For SEBI-regulated entities

CSCRF compliance, with the evidence to show for it.

SEBI’s Cybersecurity & Cyber Resilience Framework asks regulated entities to demonstrate their controls — in recurring audits, not once. Sanad is the evidence layer: it collects, signs and preserves the proof your auditor asks for, continuously.

The framework

CSCRF (SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113) consolidates SEBI’s cybersecurity expectations for stockbrokers, investment advisers and other intermediaries, graded by entity category.

What it demands

Not just controls, but demonstrable ones: asset inventories, incident-response records, policies, log trails and audit reports — maintained and producible on request.

What stacks on top

The same entities also carry CERT-In’s 6-hour incident reporting and 180-day log mandates, and DPDP Act duties for client personal data. Sanad covers all three from one deployment.

What lands in your evidence locker

Six categories of proof, produced and signed as a by-product of normal operation.

ICT asset inventory, from the machines themselves

The Sentinel agent reports installed software, patch status, disk encryption and endpoint posture from every Windows machine — an inventory your auditor can trace to hardware-attested telemetry, not a spreadsheet.

Incident reporting with a defensible timeline

From detection to CERT-In dispatch, every step is timestamped and signed. The 6-hour clock is tracked for you, and the record of when you knew and when you reported is tamper-evident.

CSCRF policy artifacts, signed and versioned

Pre-configured templates for the cybersecurity policy, incident-response SOP, data-encryption and vendor-security policies CSCRF expects — each version signed on creation and verifiable by number.

180-day log retention, evidenced

Windows event logs are collected, minimised for privacy, HMAC-signed in batches and retained on Indian storage — with a coverage ledger showing exactly which windows were captured.

Training records that stand up

Security-awareness sessions — including CSCRF-specific modules for trading-desk and vendor-governance staff — recorded as signed artifacts with attendance and content.

Vendor & third-party register

Your vendor lifecycle — registration, risk classification, DPA status, review dates — kept as chained records, ready for the supply-chain questions every CSCRF review asks.

Verifiable, independently

Every artifact carries an Ed25519 signature and a position in a hash-chained ledger. Your auditor — or SEBI — can verify a record without trusting our word for it.

console.cognoshift.in — Chain integrity
Sanad console re-verifying all evidence chains for a tenant

A straight answer on scope

Sanad does not replace your CSCRF auditor, your VAPT provider or your SOC. It makes their job — and yours — dramatically easier by ensuring that when evidence is requested, it exists, it is signed, and it has not been altered. That is the part audits actually fail on.

Book a CSCRF demo