Tool 6

What a Mid-size RE board has to approve under CSCRF

The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.

In short
A board under the RBI Directions of 31 July 2026 approves the strategies and policies for five named frameworks, an Information Security Policy and a separate Cybersecurity Policy. Under SEBI CSCRF it approves a Cybersecurity and Cyber Resilience policy document that must record every deviation from the framework and the reason for it. The lists differ by NBFC chapter, by urban co-operative bank level and by CSCRF category.

Your board document register

Mid-size is the category where CSCRF starts disapplying standards below it and stops requiring a CISO above it. It carries almost the whole governance set, with a Designated Officer in place of the Chief Information Security Officer that binds MIIs and Qualified REs.

The instrument is Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. It binds: SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.

The entity you are asking about

An NBFC and an urban co-operative bank each appear more than once, because their instruments assign obligations by layer and by level rather than by entity type. Pick the line that describes you, not the licence.

9 artefactsMid-size RE

A Mid-size regulated entity under CSCRF — a Designated Officer rather than a CISO, but otherwise most of the governance set.

7 documents the board approves, plus 2 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.

Board artefacts for Mid-size RE, each cited to its paragraph or standard
ArtefactApproved byBack before themClause
Cybersecurity and Cyber Resilience policy document
Document
The Board, Partners or ProprietorPeriodicallyGV.PO.S1, GV.PO.S2 and GV.PO.S5 — all REs, mandatory
The supporting policy set
Document
The Board, Partners or ProprietorPeriodicallyGV.PO.S1, GV.PO.S2 and GV.PO.S5 — all REs, mandatory
Policy for mobile and web applications
Document
The Board, Partners or ProprietorPeriodicallyGV.PO — all REs, mandatory
The Identify–Protect–Detect–Respond–Recover process, inside the policy
Document
The Board, Partners or ProprietorPeriodicallyGV.PO — all REs
Documented information under Plan-Do-Check-Act
Document
The Board, Partners or ProprietorPeriodicallyGV.PO — all REs except small-size and self-certification REs
Compliance policies and procedures
Document
The Board, Partners or ProprietorPeriodicallyGV.PO — all REs except small-size and self-certification REs
A separate budgetary head for cybersecurity
Document
The Board, Partners or ProprietorPeriodicallyGV.RR.S4 — all REs except small-size and self-certification REs
IT Committee of experts proficient in technology
Committee
The IT Committee, with its review placed before the BoardPeriodicallyGV.PO — all REs except small-size and self-certification REs, mandatory
Designated Officer
Named role
The Board, Partners or ProprietorPeriodicallyGV.RR — mid-size, small-size and self-certification REs, mandatory

What each one has to contain

  • Cybersecurity and Cyber Resilience policy document. A comprehensive policy document encompassing CSCRF, formed as part of the operational risk management framework. Where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the document itself. The deviations clause is the part that is routinely missed. CSCRF does not require an entity to implement every standard regardless; it requires the policy document to say where it has not, and why. A policy that silently omits a standard has not deviated properly — it has failed to record a deviation.
  • The supporting policy set. Policies for asset management, patch management, vulnerability management, VAPT, audit, monitoring of networks and endpoints, configuration management, change management, secure software development, authentication, authorisation, network segmentation and isolation, commissioning internet-facing assets, encryption, personal information and privacy, cybersecurity control management and asset ownership documentation — plus the chain of command for any cybersecurity approval, and the do’s and don’ts for using information assets including desktops, laptops, BYOD, networks, internet and data. These may form part of the cybersecurity policy or stand alone — CSCRF says so expressly. The list is drafted as “including but not limited to”, so it is a floor rather than a scope.
  • Policy for mobile and web applications. The parameters of any new product, including its alignment with business strategy, the product’s inherent risk, risk mitigation, regulatory compliance and customer experience — and, explicitly, the security requirements from Functionality, Security and Performance angles.
  • The Identify–Protect–Detect–Respond–Recover process, inside the policy. The cybersecurity policy must itself set out the process to identify critical IT assets and their risks, protect them with suitable controls, detect incidents and anomalies through monitoring, respond immediately on identification, and recover through incident management and other recovery mechanisms.
  • Documented information under Plan-Do-Check-Act. Policies guide the Plan phase, procedures and standard operating procedures the Do phase, and both are referred back to in the Check and Act phases.
  • Compliance policies and procedures. Assessing compliance with the guidelines, policies, laws, circulars and regulations issued by SEBI or the Government; developing compliance policies and procedures; implementing controls; training employees; monitoring and reviewing the compliance process; and regular audits and reporting.
  • A separate budgetary head for cybersecurity. An adequate percentage of the total IT budget allocated to cybersecurity, shown under a separate budgetary head so that the board can monitor it, with resources defined in budget, people and material and revisited as implementation progresses or falls short. This is a board-visible line in the budget rather than a policy. It is the standard most likely to be satisfied on paper and not in the accounts, because it asks for a separate head rather than a stated intention.
  • IT Committee of experts proficient in technology. Constituted by the Board, Partners or Proprietor, meeting periodically to review implementation of the approved cybersecurity and cyber resilience policy. The review must set a goal for a target level of cyber resilience and establish a plan to reach it, and must then be placed before the Board, Partners or Proprietor for action. The committee reviews; it does not replace the board. CSCRF requires the review to go back up, with goal setting and an improvement plan attached, so a committee that meets and minutes nothing upward has met half the standard.
  • Designated Officer. A senior official or member of management designated to assess, identify and reduce cybersecurity risks, respond to incidents, establish standards and controls, and direct implementation as per the approved policy — with a reporting procedure that gets incidents and unusual activity to them in a time-bound manner. CSCRF does not ask a mid-size or smaller entity for a CISO. It asks for a Designated Officer with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.

Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.

Take this away as a print-ready board document register

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Why the cybersecurity policy is its own document

Both the RBI Directions and SEBI CSCRF require a cybersecurity policy that is distinct from the IT and information security policies, so that cyber risk is visible on its own rather than as a chapter inside something longer. That is the requirement most often satisfied on paper and not in fact, and it is the one an inspection can test by asking for the document by name.

RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice.

Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What documents must a bank board approve under the RBI 2026 Directions?
Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
Does the cybersecurity policy have to be separate from the IT policy?
Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
What policy does SEBI CSCRF require a board to approve?
A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
Does a small urban co-operative bank need an IT Strategy Committee?
No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
Does every SEBI regulated entity need a CISO?
No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools