Work out your SEBI CSCRF Cyber Capability Index
Score all 23 Annexure-K parameters against their targets and weightages, see the rating band it lands in, and find which parameters are costing you the most marks.
Work out your index
Enter the percentage your own figures produce against each formula. The calculator opens on a worked assessment for a mid-maturity entity, so the tables below are readable as a reference even without entering anything.
A score is not a pass. SEBI awards Fail at 50 or below or where the “RE has scored below the cut-off in at least one domain/ sub-domain”. That second limb is a floor test rather than a total, so an RE scoring well above 50 still fails on one weak domain. SEBI does not publish what the cut-off is — it appears nowhere in the framework — so neither this tool nor any other can compute it.
| Rating | Index score |
|---|---|
| Exceptional Cybersecurity Maturity | 91–100 |
| Optimal Cybersecurity Maturity | 81–90 |
| Manageable Cybersecurity MaturityYour band | 71–80 |
| Developing Cybersecurity Maturity | 61–70 |
| Bare Minimum Cybersecurity Maturity | 51–60 |
| Fail | 50 and belowor one domain below cut-off |
Where the marks are going
- Security Budget — 3.20 of 8 marks lost. 6% against a target of 10%.
- Automated compliance with CSCRF — 3.00 of 5 marks lost. 40% against a target of 100%.
- Vulnerability — 2.70 of 18 marks lost. 85% against a target of 100%.
- Critical Assets Identified — 1.80 of 9 marks lost. 40% against a target of 50%.
- Contingency Plan Testing — 1.60 of 4 marks lost. 60% against a target of 100%.
Ordered by marks lost rather than by percentage, because the weightings are lopsided: Vulnerability alone carries 18 marks and Physical Security Incidents carries 1, so a poor showing on the second costs almost nothing and a middling one on the first costs more than most parameters are worth in total.
Indicative, and not a submission. Parameters, targets and weightages are from Annexure-K Table 27 of the CSCRF; the bands are Table 24. Your reporting authority and, for an MII, your third-party assessor determine the score that counts.
Take this away as a CCI working paper
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
The 23 parameters and what each is worth
The weightings are lopsided, and that is the first thing worth knowing. Vulnerability alone carries 18 of the 100 marks and Critical Assets Identified another 9, so those two are more than a quarter of the index between them. Physical Security Incidents, Planning, Personnel Security Screening and System and Communication Protection carry one mark each. An improvement plan that works through the parameters in order will spend most of its effort at the wrong end.
| # | Parameter | Formula | Target | Weight |
|---|---|---|---|---|
| 1 | Security Budget | (Information security budget / total organisation’s information technology budget) × 100 | 10% | 8 |
| 2 | Vulnerability | (Number of vulnerabilities mitigated / Number of vulnerabilities identified) × 100 | 100% | 18 |
| 3 | Security Training | (Number of information system security personnel that have completed security training within the past year / total number of information system security personnel) × 100 | 100% | 5 |
| 4 | Remote Access Control | (Number of remote users logging through MFA / total number of remote users) × 100 | 100% | 2 |
| 5 | Audit Record Review | (Number of critical systems integrated with SIEM tool / total number of critical systems) × 100 | 100% | 2 |
| 6 | Configuration Changes | (Number of approved and implemented configuration changes identified in the latest automated baseline configuration / total number of configuration changes identified through automated or manual scan) × 100 | 100% | 2 |
| 7 | Contingency Plan Testing | (Number of information systems that have conducted contingency plans testing at least once in a year / number of information systems in the system inventory) × 100 | 100% | 4 |
| 8 | User Accounts | (Number of systems accessed through PIM / total number of systems) × 100 | 100% | 3 |
| 9 | Incident Response | (Number of incidents reported on time / total number of reported incidents) × 100 | 100% | 2 |
| 10 | Maintenance | (Number of system components that undergo maintenance according to planned maintenance schedules / total number of system components) × 100 | 100% | 5 |
| 11 | Media Sanitization | (Number of media that passes sanitization procedures testing / total number of media disposed or released for reuse) × 100 | 100% | 2 |
| 12 | Physical Security Incidents | (Number of physical security incidents allowing unauthorized entry into facilities containing information systems / total number of physical security incidents) × 100 | 0% | 1 |
| 13 | Planning | (Number of users who are granted system access after signing confidentiality and integrity agreement / total number of users who are granted system access) × 100 | 100% | 1 |
| 14 | Personnel Security Screening | (Number of individuals screened / total number of individuals having access to organisation’s information and information systems) × 100 | 100% | 1 |
| 15 | Risk Assessment | (Number of organisation’s information systems and assets covered under risk assessment / total number of organisation information systems and assets) × 100 | 100% | 5 |
| 16 | Service Acquisition Contract | (Number of system and service acquisition contracts that include security requirements specifications / total number of system and service acquisition contracts) × 100 | 100% | 3 |
| 17 | System and Communication Protection | (Number of mobile computers and devices that perform all cryptographic operations / total number of mobile computers and devices) × 100 | 100% | 1 |
| 18 | Risk Management | (Number of organisation information systems and assets covered under risk management / total number of organisation information systems and assets) × 100 | 100% | 8 |
| 19 | Critical Assets Identified | (Number of critical systems identified / total IT systems integrated with SOC) × 100 | 50% | 9 |
| 20 | CSK Events | (Total number of CSK reported events closed in 15 days / total number of CSK reported events to the organisation) × 100 | 100% | 4 |
| 21 | Cybersecurity Policy Document | Non-quantifiable measure — Table 27 gives no formula and no target. | 100% | 4 |
| 22 | SOC efficacy | As specified in the SOC efficacy score at Annexure-N. | 100% | 5 |
| 23 | Automated compliance with CSCRF | (Number of standards for which compliance has been automated / total number of CSCRF standards) × 100 | 100% | 5 |
Three of the 23 are not ordinary ratios, and together they carry 10 marks. Parameter 12 is inverse — it counts physical security incidents that allowed unauthorised entry, so its target is 0% and a lower number is better. Parameter 21 is expressly a non-quantifiable measure: Table 27 gives it no formula and no target at all, only implementation evidence about the policy document, its revision frequency and its approval. Parameter 22 defers to the SOC efficacy score defined at Annexure-N, so it is not computed here at all — you enter the score you already hold.
Two of the targets are not 100% either. Security Budget targets 10% of the IT budget, and Critical Assets Identified targets 50% of the systems integrated with your SOC. Reaching a target earns the full weightage; exceeding it earns nothing further.
How SEBI says to score it
The scoring rules are not in the framework. They are in SEBI’s CSCRF FAQ, which is a separate document, and they are specific enough that a calculator built without them will be wrong in ways nobody notices.
- Partial scoring is pro rata. SEBI’s own worked example: an entity reaching 30% against a target of 50%, on a parameter carrying 5 marks, is awarded 3.
- Scores may carry two decimal places, and the highest score for any category is capped at that category’s weightage — there is no credit above target.
- An undefined value resolves per parameter, not uniformly. Where a formula divides zero by zero, the framework does not fall back to a single convention. On parameter 2, no vulnerabilities identified and none mitigated takes the maximum marks. On parameter 14, nobody with access and nobody screened takes zero. A calculator applying one rule to both is wrong in one direction or the other.
- Everything runs on the financial year, and compliance is submitted along with the cyber audit report to the relevant reporting authority.
What the score gets you
| Rating | Index score |
|---|---|
| Exceptional Cybersecurity Maturity | 91–100 |
| Optimal Cybersecurity Maturity | 81–90 |
| Manageable Cybersecurity Maturity | 71–80 |
| Developing Cybersecurity Maturity | 61–70 |
| Bare Minimum Cybersecurity Maturity | 51–60 |
| Fail | 50 and below |
A high score is not a pass. The Fail row carries a second limb — it applies at 50 or below, or where the “RE has scored below the cut-off in at least one domain/ sub-domain”. That makes Fail a floor test as well as a total, so an entity scoring in the eighties still fails on one weak domain. SEBI does not publish what the cut-off is; it appears nowhere in the framework. No calculator can determine that limb, this one included, and one that reports a clean pass on the aggregate alone is answering a question SEBI did not ask.
The bands are printed as whole numbers while the score itself may carry two decimals, so a figure such as 90.5 sits between two printed ranges. This tool reads such a score downward, into the band its integer part falls in.
| Entity | Assessment | Frequency |
|---|---|---|
| Market Infrastructure Institutions | Third-party assessment of cyber resilience using the CCI | Half-yearly |
| Qualified REs | Self-assessment of cyber resilience using the CCI | Annually |
Mid-size, Small-size and Self-certification REs have no CCI obligation at all. If you are not sure which category you are in, that is a different question and the CSCRF category finder answers it — and it is worth answering first, because the category is fixed at the start of the financial year and holds all year.
What the index cannot tell you
- Whether you pass. The domain cut-off limb sits outside the arithmetic and outside the published framework.
- Whether the numbers are evidenced. Implementation evidence goes to SEBI only on demand, but it has to exist. For an MII every item is verified by the auditor conducting the third-party assessment, so an unevidenced figure is a finding rather than a score.
- Anything an outsider can see. Every parameter here is measured from inside. Expired certificates, exposed services and leaked credentials — the things a counterparty or a regulator can observe without asking — sit outside the index entirely.
- What your assessor will conclude. This is a working figure for a conversation, not a submission.
For the framework as a whole, category by category, see the CSCRF compliance guide, or work out your incident-reporting deadlines with the incident reporting clock.
This tool is indicative and is not a submission. Parameters, formulas, targets and weightages are from Annexure-K, Table 27 of the CSCRF, and the rating bands from Table 24 — both read from SEBI’s own framework document, which carries the annexures the circular’s landing page does not. The scoring rules are from SEBI’s CSCRF FAQ. Your reporting authority determines the score that counts. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- What is the Cyber Capability Index under SEBI CSCRF?
- An index-framework that rates the preparedness and resilience of a regulated entity’s cybersecurity, calculated on 23 parameters carrying different weightages and expressed out of 100. It applies to Market Infrastructure Institutions and Qualified REs only — Mid-size, Small-size and Self-certification REs have no CCI obligation. The parameters, their formulas, targets and weightages are set out in Annexure-K, Table 27 of the framework, and the rating bands in Table 24.
- Who has to calculate a CCI score, and how often?
- Market Infrastructure Institutions commission a third-party assessment of their cyber resilience using the CCI on a half-yearly basis. Qualified REs conduct a self-assessment annually. All periodicities under the framework run on the financial year, and compliance is submitted alongside the cyber audit report to the relevant reporting authority. A third-party assessment and a self-report do not carry the same evidential weight in a supervisory conversation.
- How is the CCI score calculated?
- Each of the 23 parameters is measured by its own formula, compared against its target, and awarded marks pro rata up to its weightage. SEBI’s FAQ gives the worked example: an entity reaching 30% against a target of 50% on a parameter carrying 5 marks is awarded 3. Scores may carry two decimal places, and the highest score for any category is capped at that category’s weightage. The weightages sum to 100.
- What is a good CCI score?
- The framework sets six bands: 91 and above is Exceptional Cybersecurity Maturity, 81 to 90 Optimal, 71 to 80 Manageable, 61 to 70 Developing, 51 to 60 Bare Minimum, and 50 or below is a Fail. The bands are printed as whole numbers while the score itself may carry two decimals, so a figure such as 90.5 sits between two printed ranges; read downward, it is Optimal.
- Can an entity fail the CCI despite a high score?
- Yes. The Fail row in Table 24 carries a second limb: it applies at 50 or below, or where the entity has scored below the cut-off in at least one domain or sub-domain. That makes Fail a floor test as well as a total, so a strong aggregate does not by itself demonstrate a pass. SEBI does not publish the cut-off value anywhere in the framework, so no calculator can determine that limb — it is a matter for the assessor and the reporting authority.
- Are all 23 CCI parameters scored the same way?
- No, and three of them are not ordinary ratios. Parameter 12, Physical Security Incidents, is inverse and carries a target of 0% — fewer is better — so the pro-rata rule of dividing by the target cannot be applied to it at all. Parameter 21, Cybersecurity Policy Document, is expressly a non-quantifiable measure with no formula and no target in Table 27. Parameter 22 defers to the SOC efficacy score defined at Annexure-N. Together they carry 10 of the 100 marks.