SecurityBoat

Compliance · Indian Regulatory

SEBI CSCRF reports, generated — not assembled.

TriNetra ships SEBI CSCRF VAPT report formats natively, in both full and attestation versions. Findings, severity matrix, scope tables, and testing checklist auto-assemble from your real assessments. Your team reviews and approves; the platform does the paperwork.

Compliance Reports
  • RBI Cyber Security FrameworkAnnual Assessment 2026
    PENDING REVIEWReviewView
  • ISO/IEC 27001:2022Annual Assessment 2026
    PENDING REVIEWReviewView
  • SOC 2 Type IIAnnual Assessment 2026
    PENDING REVIEWReviewView
  • IRDAI Information & Cyber SecurityAnnual Assessment 2026
    PENDING REVIEWReviewView
  • SEBI Cyber Security & Cyber ResilienceAnnual Assessment 2026
    PENDING REVIEWReviewView
  • ISO/IEC 27001:2022 Cloud AddendumAnnual Assessment 2026
    PENDING REVIEWReviewView

The regulation

What SEBI CSCRF expects of you.

SEBI's Cybersecurity and Cyber Resilience Framework doesn't apply uniformly — it sets tiered obligations across a wide taxonomy of regulated entities: stock brokers, Market Infrastructure Institutions (exchanges, depositories, clearing corporations), Registrars and Transfer Agents, Know Your Customer Registration Agencies, Asset Management Companies, and credit rating agencies, among others. Obligations scale with an entity's systemic importance — an MII carries heavier requirements than a small broker — but every tier shares the same backbone: periodic VAPT, a documented cyber-resilience framework, and incident reporting to SEBI within a 6-hour window, mirroring the CERT-In timeline it's built on top of. SEBI's enforcement options run from monetary penalties through trading restrictions to, in the most serious cases, cancellation of registration — meaning the entity can't legally operate in the market it's registered for. For a broker or RTA, that's an existential outcome, which is why CSCRF evidence quality gets scrutinized closely during SEBI inspections.

How TriNetra maps to it

Native CSCRF, end to end.

TriNetra moduleEvidence produced
PTaaSEngagements scoped against the specific CSCRF tier an entity falls into — broker, MII, RTA, KRA, AMC, credit rating agency — with the Coverage tab's methodology checklist reflecting the control categories relevant to that tier rather than a one-size-fits-all checklist.
Attack Surface ManagementThe continuous attack-surface visibility CSCRF's resilience language implies but doesn't fully spell out — brokers and RTAs run public-facing trading and account-servicing portals that need monitoring between audit cycles, not just at renewal time.
Continuous Controls ValidationCSCRF controls mapped alongside any other framework the same entity is pursuing, so control evidence isn't duplicated per framework — and incident-reporting readiness kept current against SEBI's 6-hour window.
Continuous Controls ValidationOne of two frameworks the compliance-reporting pipeline generates end-to-end today: SEBI CSCRF VAPT reports, both full and short-form attestation variants, with findings, severity matrices, and methodology checklists auto-aggregated from real engagement data, per-client white-labelled templates, approval gating, and a change-request workflow for disputed findings.

Keep evidence current between audits with Continuous Controls Validation.

The raw material

Every CSCRF report starts from validated findings.

Severity, CVSS scoring, and status on every finding — auto-aggregated into full and attestation CSCRF formats when the cycle comes around.

Findings

116 total12 critical26 high85 open31 resolved
Insecure deserialization in job queueLOW 1.0ResolvedPTaaS
SQL injection in legacy reporting exportLOW 1.9Accepted riskPTaaS
Outdated TLS configuration (TLS 1.0/1.1)MEDIUM 4.5Fix in progressPTaaS
Verbose error messages leak stack tracesMEDIUM 5.6Fix in progressPTaaS
Race condition in wallet balance updateMEDIUM 6.5VerifiedPTaaS
Missing rate limiting on OTP verificationHIGH 7.7ResolvedPTaaS
Privilege escalation through mass assignmentMEDIUM 5.5Ready for retestPTaaS

Why SecurityBoat

The deadline is fixed. The scramble is optional.

Most regulated entities rebuild their CSCRF evidence from scratch each cycle — chasing vendor PDFs, reconciling findings lists, reformatting to the prescribed template. On TriNetra, the report is a generated artifact of testing you already ran. When the cycle comes around, you review, approve, and submit.

Ready when you are

See a CSCRF report build itself.

Bring your scope. We'll walk you through a live CSCRF reporting flow — from finding to approved, submission-ready document.