The Cybersecurity and Cyber Resilience Framework (CSCRF) is a standards-driven framework based on the Cyber Crisis Management Plan (CCMP) established by the Indian Computer Emergency Response Team (CERT-In). It focuses on five key cyber resilience goals — Anticipate, Withstand, Contain, Recover, and Evolve — which are aligned with six essential cybersecurity functions: Governance, Identify, Protect, Detect, Respond, and Recover.
The CSCRF is structured into four comprehensive parts:
- Part I: Objectives and Standards – Outlines the foundational principles of the framework.
- Part II: Guidelines – Provides detailed implementation guidance.
- Part III: Compliance Formats – Contains structured formats to facilitate compliance.
- Part IV: Annexures and References – Offers additional context and supporting information.
The framework applies to the following Registered Entities (REs) and further classifies them into different categories based on factors such as operational scale, client base, trade volume, and assets under management. It also outlines specific compliance requirements tailored to each category.