SEBI CSCRF · ISO/IEC 27001:2022
Compliance work for brokers, AMCs, RTAs, depository participants and other SEBI-regulated entities divides into two halves that should not sit with the same firm. One half is assurance: an independent audit against SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF), issued in August 2024 and clarified through subsequent circulars. The other is implementation — designing the controls, running them, and producing evidence that they actually operated. We do the second.
Gap assessment · control implementation · security operations · evidence
The division
Where we fit
The separation is the point, not a limitation.
| The work | Who should do it | What we provide |
|---|---|---|
| Independent audit or assurance | An independent auditor | Nothing — engaging your implementer as your auditor defeats the purpose of both |
| Gap assessment | Either | A control-by-control read of where you stand |
| Control implementation | Us with your team | Network, identity, endpoint, logging and recovery controls |
| Security operations | Us or in-house | SOC and NOC capability, and the records they generate |
| Evidence | Us with your team | Repeatable proof that a control operated, not just that it exists |
Scroll the table sideways on a narrow screen.
If a provider offers to both implement your controls and audit them, that is the first thing to question.
Control domains
The controls we actually implement
Regulatory frameworks differ in wording and overlap almost entirely in substance. The control domains below are what the work reduces to in practice.
Identity and access
Joiner-mover-leaver process, privileged access separation, multi-factor authentication on administrative paths, and access reviews that produce a dated record with a named approver rather than an assertion.
Network segmentation
Separating what must not reach what, and being able to demonstrate the separation from the running configuration rather than from a diagram. See firewall audit.
Logging and retention
Logs that leave the device, are retained where they can be queried, and cover the systems the policy claims they cover. See SIEM services.
Monitoring and response
Somebody watching, with a defined escalation path and a record of what was seen and what was done about it.
Backup and recovery
Tested recovery with a documented result. An untested backup is a claim, and auditors have become good at asking when it was last proven. See backup and DR.
Third-party risk
Knowing which suppliers reach your data and what they are contractually obliged to do about it — increasingly the domain where findings are raised.
The real difficulty
Why evidence is the hard part
Regulated entities rarely fail on the absence of controls. They struggle to demonstrate that a control operated consistently over the period under review — that access was reviewed and by whom, that changes went through approval, that monitoring actually covered the systems it claimed to, that recovery was tested rather than assumed.
That is an operations problem rather than a documentation problem, which is why organisations running a real SOC and NOC find audits substantially less painful: the evidence is a by-product of the operation rather than something assembled retrospectively each year.
On regulatory specifics — deadlines, thresholds, submission windows — we do not restate them on this page. They are amended, and a confidently wrong figure on a vendor’s website is worse than no figure. We will check the current text with you against your own category.
Related
Related work
These sit alongside this engagement more often than not:
Managed security services
Day-to-day security operations run on your behalf, which is what leadership and compliance work both depend on.
Questions
SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs, answered
What is the CSCRF?
SEBI’s Cybersecurity and Cyber Resilience Framework, issued in August 2024 for SEBI-regulated entities, consolidating earlier cybersecurity circulars into a single framework covering governance, security operations, incident response and resilience testing.
What are the current deadlines?
SEBI has issued several clarifications and extensions since the original circular, and dates differ by entity category. We deliberately do not publish a date here, because a stale compliance deadline on a vendor page is worse than none — check the current position on SEBI’s own site or ask us and we will look it up with you.
The framework expects a SOC. Does that have to be our own?
The framework contemplates access to security operations capability and measuring its effectiveness. Whether that is built in-house, shared, or taken as a service is an operational choice. See SOC as a Service and managed SOC services.
Are you CERT-In empanelled?
No, and we will not imply otherwise. Where an engagement requires an empanelled auditor, that work goes to an empanelled firm and we support the implementation and remediation around it.
Do you hold a security certification yourselves?
P J Networks holds ISO/IEC 27001:2022. We have been operating since 2002 and run our own NOC and SOC from New Delhi.
Can you help if we have already failed an audit?
Yes, and it is a common starting point. A findings list is in practice a well-specified scope of work — we take the observations, agree remediation with owners and dates, implement, and produce the evidence for the follow-up review.
Next step
Talk to someone who has done this before
Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.



