For vendors to SEBI-regulated entities
Your client answers to SEBI for your security.
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) keeps brokers, depositories, mutual funds and other regulated entities accountable for the services they outsource. ProvenClosed watches what you expose to the internet, re-checks every fix, and gives you dated, signed evidence — mapped to the CSCRF identifiers their security team works from.
What CSCRF says about you
Outsourcing the work does not outsource the accountability.
CSCRF's supply-chain category, GV.SC, is written for the regulated entity — and most of it is about its vendors.
Held to similar standards
Third-party service providers are to be mandated to follow similar standards of information security, and contracts with them are to carry measures that serve the regulated entity's own cybersecurity programme.
Reviewed on a schedule
A regulated entity is to monitor and review, periodically, the service providers that perform critical activities for it — not once at onboarding.
Still their name on it
Responsibility for outsourced activities stays with the regulated entity, and its periodic reports to SEBI name the critical activities third parties handle. What it needs from you is evidence it can keep on file.
Paraphrased from SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024), GV.SC. Which parts apply depends on the category of regulated entity — read the circular for the exact wording.
Where the evidence fits
Each check names the CSCRF identifiers it is evidence for.
On every finding, in exports and on signed certificates — beside the SOC 2 and ISO 27001 controls the same check is evidence for.
What each identifier is about
ID.AM- Asset management: an inventory of what is run — domains, URLs and cloud assets included — kept current as they change.
PR.AA- Access control: multi-factor authentication for anything reachable from the internet, and network access limited to allowed ports and sources.
PR.DS- Data security: data protected in transit and at rest, and digital certificates renewed before they lapse.
PR.IP- Hardening: only the ports and services that are needed, secure configuration, and known vulnerabilities closed within set timelines.
DE.CM- Continuous monitoring: unauthorised change and access affecting internet-facing systems is noticed.
DE.CM.S5- Vulnerability assessment and penetration testing, public-IP systems included, and revalidation once findings are closed.
In our words, not the circular's.
Why mostly categories
CSCRF often attaches one block of guidance to several standards at once — the MFA and network-access guidance sits under five PR.AA standards together. Picking one of those numbers for an observation would be a guess that looks like a citation, so the category is named instead.
DE.CM.S5 is the exception because the circular makes it one: it is where VAPT, and the revalidation of findings once they are closed, are defined.
No "x of y standards" figure is given. Which CSCRF standards apply depends on your client's category of regulated entity, so there is no single total to count against.
Between the VAPT and its revalidation
Months pass between a VAPT and its revalidation. They can be observed.
If your client's VAPT covers systems you run for them, CSCRF sets the clock. ProvenClosed re-checks each externally visible fix as it is made — only a later scan can mark a finding fixed — and then keeps watching for it to come back.
The VAPT and its revalidation are the auditor's work, done by a CERT-In empanelled organisation. ProvenClosed's re-check is evidence beside them, for what it can see from outside and in your AWS account — it does not replace either.
The test — by a CERT-In empanelled IS auditing organisation.
Findings closed within three months of the report, in an order graded by how critical each is.
Revalidation completed within five months of the VAPT — confirming the closures held.
Handing it over
Your client checks it without an account, and without trusting you — or us.
A certificate per fix
What was exposed, when it was last seen, when it was seen gone and what the scan covered, in one readable page. The signed data inside it also names the CSCRF, SOC 2 and ISO 27001 identifiers.
Checked on their machine
Their team runs one open script, verify.py, against the key set published on this site. It prints every claim from the signed data, the identifiers included, and fails if one byte was changed. How it works.
Honest about its limits
It lists what it could not establish, and the verifier prints the mapping's caveat directly under the identifiers — so it survives being pasted into a questionnaire.
What this is not
- Not an assessment against CSCRF. A check observes one resource at one moment. A CSCRF standard is an organisational requirement no scanner can decide, so ProvenClosed never says one is met.
- Not a VAPT, not its revalidation, and not a cyber audit. ProvenClosed is not a CERT-In empanelled IS auditing organisation, and its certificates are not VAPT certificates.
- Not SEBI's view. The mapping is ProvenClosed's judgement about where a check's evidence is relevant. On a signed certificate it says so, and that the signature does not cover it.
- Not all of CSCRF. It covers what can be observed from the internet and read from an AWS account — not policies, people, logging, backups or anything inside your network.
Have the evidence ready
before they ask.
Monitor one domain free. Signed certificates and evidence packs come with Business & Pro, in early access.