For vendors to SEBI-regulated entities

Your client answers to SEBI for your security.

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) keeps brokers, depositories, mutual funds and other regulated entities accountable for the services they outsource. ProvenClosed watches what you expose to the internet, re-checks every fix, and gives you dated, signed evidence — mapped to the CSCRF identifiers their security team works from.

What CSCRF says about you

Outsourcing the work does not outsource the accountability.

CSCRF's supply-chain category, GV.SC, is written for the regulated entity — and most of it is about its vendors.

Held to similar standards

Third-party service providers are to be mandated to follow similar standards of information security, and contracts with them are to carry measures that serve the regulated entity's own cybersecurity programme.

Reviewed on a schedule

A regulated entity is to monitor and review, periodically, the service providers that perform critical activities for it — not once at onboarding.

Still their name on it

Responsibility for outsourced activities stays with the regulated entity, and its periodic reports to SEBI name the critical activities third parties handle. What it needs from you is evidence it can keep on file.

Paraphrased from SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024), GV.SC. Which parts apply depends on the category of regulated entity — read the circular for the exact wording.

Where the evidence fits

Each check names the CSCRF identifiers it is evidence for.

On every finding, in exports and on signed certificates — beside the SOC 2 and ISO 27001 controls the same check is evidence for.

What ProvenClosed checksCSCRF
Exposed services — databases, remote access, admin portsPR.AAPR.IPDE.CM.S5
AI model servers and consoles answering without authenticationProPR.AAPR.IPDE.CM.S5
Known vulnerabilities, from 100 reviewed templatesPR.IPDE.CM.S5
Dangling DNS — a name pointing at something nobody owns any moreID.AMDE.CM.S5
TLS — expired, expiring, untrusted or mismatched certificates, old protocolsPR.DS
Missing browser security headersPR.IPDE.CM
AWS — public bucketsBusiness & ProPR.AAPR.DS
AWS — world-open security groups, public databasesBusiness & ProPR.AAPR.IP
AWS — IAM users without MFA, stale access keysBusiness & ProPR.AA

What each identifier is about

ID.AM
Asset management: an inventory of what is run — domains, URLs and cloud assets included — kept current as they change.
PR.AA
Access control: multi-factor authentication for anything reachable from the internet, and network access limited to allowed ports and sources.
PR.DS
Data security: data protected in transit and at rest, and digital certificates renewed before they lapse.
PR.IP
Hardening: only the ports and services that are needed, secure configuration, and known vulnerabilities closed within set timelines.
DE.CM
Continuous monitoring: unauthorised change and access affecting internet-facing systems is noticed.
DE.CM.S5
Vulnerability assessment and penetration testing, public-IP systems included, and revalidation once findings are closed.

In our words, not the circular's.

Why mostly categories

CSCRF often attaches one block of guidance to several standards at once — the MFA and network-access guidance sits under five PR.AA standards together. Picking one of those numbers for an observation would be a guess that looks like a citation, so the category is named instead.

DE.CM.S5 is the exception because the circular makes it one: it is where VAPT, and the revalidation of findings once they are closed, are defined.

No "x of y standards" figure is given. Which CSCRF standards apply depends on your client's category of regulated entity, so there is no single total to count against.

Between the VAPT and its revalidation

Months pass between a VAPT and its revalidation. They can be observed.

If your client's VAPT covers systems you run for them, CSCRF sets the clock. ProvenClosed re-checks each externally visible fix as it is made — only a later scan can mark a finding fixed — and then keeps watching for it to come back.

The VAPT and its revalidation are the auditor's work, done by a CERT-In empanelled organisation. ProvenClosed's re-check is evidence beside them, for what it can see from outside and in your AWS account — it does not replace either.

VAPT

The test — by a CERT-In empanelled IS auditing organisation.

3 MONTHS

Findings closed within three months of the report, in an order graded by how critical each is.

5 MONTHS

Revalidation completed within five months of the VAPT — confirming the closures held.

Handing it over

Your client checks it without an account, and without trusting you — or us.

A certificate per fix

What was exposed, when it was last seen, when it was seen gone and what the scan covered, in one readable page. The signed data inside it also names the CSCRF, SOC 2 and ISO 27001 identifiers.

Checked on their machine

Their team runs one open script, verify.py, against the key set published on this site. It prints every claim from the signed data, the identifiers included, and fails if one byte was changed. How it works.

Honest about its limits

It lists what it could not establish, and the verifier prints the mapping's caveat directly under the identifiers — so it survives being pasted into a questionnaire.

What this is not

  • Not an assessment against CSCRF. A check observes one resource at one moment. A CSCRF standard is an organisational requirement no scanner can decide, so ProvenClosed never says one is met.
  • Not a VAPT, not its revalidation, and not a cyber audit. ProvenClosed is not a CERT-In empanelled IS auditing organisation, and its certificates are not VAPT certificates.
  • Not SEBI's view. The mapping is ProvenClosed's judgement about where a check's evidence is relevant. On a signed certificate it says so, and that the signature does not cover it.
  • Not all of CSCRF. It covers what can be observed from the internet and read from an AWS account — not policies, people, logging, backups or anything inside your network.

Have the evidence ready
before they ask.

Monitor one domain free. Signed certificates and evidence packs come with Business & Pro, in early access.