Tool 12

Work out your SEBI CSCRF Cyber Capability Index

Score all 23 Annexure-K parameters against their targets and weightages, see the rating band it lands in, and find which parameters are costing you the most marks.

In short
The Cyber Capability Index scores a SEBI regulated entity on 23 weighted parameters from Annexure-K of the CSCRF, out of 100. Market Infrastructure Institutions commission a third-party assessment half-yearly; Qualified REs self-assess annually. A score of 50 or below is a Fail — and so is scoring below the cut-off in any single domain, whatever the total.

Work out your index

Enter the percentage your own figures produce against each formula. The calculator opens on a worked assessment for a mid-maturity entity, so the tables below are readable as a reference even without entering anything.

Your measurements

Enter the percentage your own figures produce for each formula. Every parameter is scored against its target and capped at its weightage, so there is no credit for exceeding a target.

#ParameterTargetWeightYour %Marks
1Security Budget10%84.80
2Vulnerability100%1815.30
3Security Training100%54.50
4Remote Access Control100%22.00
5Audit Record Review100%21.60
6Configuration Changes100%21.50
7Contingency Plan Testing100%42.40
8User Accounts100%32.10
9Incident Response100%21.80
10Maintenance100%54.25
11Media Sanitization100%21.00
12Physical Security Incidentslower is better0%11.00
13Planning100%10.95
14Personnel Security Screening100%10.80
15Risk Assessment100%54.50
16Service Acquisition Contract100%31.80
17System and Communication Protection100%10.70
18Risk Management100%86.80
19Critical Assets Identified50%97.20
20CSK Events100%43.00
21Cybersecurity Policy Documentno formula100%44.00
22SOC efficacyAnnexure-N100%53.50
23Automated compliance with CSCRF100%52.00
77.50Manageable Cybersecurity Maturity

A score is not a pass. SEBI awards Fail at 50 or below or where the “RE has scored below the cut-off in at least one domain/ sub-domain”. That second limb is a floor test rather than a total, so an RE scoring well above 50 still fails on one weak domain. SEBI does not publish what the cut-off is — it appears nowhere in the framework — so neither this tool nor any other can compute it.

Table 24 — rating categories based on CCI
RatingIndex score
Exceptional Cybersecurity Maturity91–100
Optimal Cybersecurity Maturity81–90
Manageable Cybersecurity MaturityYour band71–80
Developing Cybersecurity Maturity61–70
Bare Minimum Cybersecurity Maturity51–60
Fail50 and belowor one domain below cut-off

Where the marks are going

  • Security Budget3.20 of 8 marks lost. 6% against a target of 10%.
  • Automated compliance with CSCRF3.00 of 5 marks lost. 40% against a target of 100%.
  • Vulnerability2.70 of 18 marks lost. 85% against a target of 100%.
  • Critical Assets Identified1.80 of 9 marks lost. 40% against a target of 50%.
  • Contingency Plan Testing1.60 of 4 marks lost. 60% against a target of 100%.

Ordered by marks lost rather than by percentage, because the weightings are lopsided: Vulnerability alone carries 18 marks and Physical Security Incidents carries 1, so a poor showing on the second costs almost nothing and a middling one on the first costs more than most parameters are worth in total.

Indicative, and not a submission. Parameters, targets and weightages are from Annexure-K Table 27 of the CSCRF; the bands are Table 24. Your reporting authority and, for an MII, your third-party assessor determine the score that counts.

Take this away as a CCI working paper

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

The 23 parameters and what each is worth

The weightings are lopsided, and that is the first thing worth knowing. Vulnerability alone carries 18 of the 100 marks and Critical Assets Identified another 9, so those two are more than a quarter of the index between them. Physical Security Incidents, Planning, Personnel Security Screening and System and Communication Protection carry one mark each. An improvement plan that works through the parameters in order will spend most of its effort at the wrong end.

#ParameterFormulaTargetWeight
1Security Budget(Information security budget / total organisation’s information technology budget) × 10010%8
2Vulnerability(Number of vulnerabilities mitigated / Number of vulnerabilities identified) × 100100%18
3Security Training(Number of information system security personnel that have completed security training within the past year / total number of information system security personnel) × 100100%5
4Remote Access Control(Number of remote users logging through MFA / total number of remote users) × 100100%2
5Audit Record Review(Number of critical systems integrated with SIEM tool / total number of critical systems) × 100100%2
6Configuration Changes(Number of approved and implemented configuration changes identified in the latest automated baseline configuration / total number of configuration changes identified through automated or manual scan) × 100100%2
7Contingency Plan Testing(Number of information systems that have conducted contingency plans testing at least once in a year / number of information systems in the system inventory) × 100100%4
8User Accounts(Number of systems accessed through PIM / total number of systems) × 100100%3
9Incident Response(Number of incidents reported on time / total number of reported incidents) × 100100%2
10Maintenance(Number of system components that undergo maintenance according to planned maintenance schedules / total number of system components) × 100100%5
11Media Sanitization(Number of media that passes sanitization procedures testing / total number of media disposed or released for reuse) × 100100%2
12Physical Security Incidents(Number of physical security incidents allowing unauthorized entry into facilities containing information systems / total number of physical security incidents) × 1000%1
13Planning(Number of users who are granted system access after signing confidentiality and integrity agreement / total number of users who are granted system access) × 100100%1
14Personnel Security Screening(Number of individuals screened / total number of individuals having access to organisation’s information and information systems) × 100100%1
15Risk Assessment(Number of organisation’s information systems and assets covered under risk assessment / total number of organisation information systems and assets) × 100100%5
16Service Acquisition Contract(Number of system and service acquisition contracts that include security requirements specifications / total number of system and service acquisition contracts) × 100100%3
17System and Communication Protection(Number of mobile computers and devices that perform all cryptographic operations / total number of mobile computers and devices) × 100100%1
18Risk Management(Number of organisation information systems and assets covered under risk management / total number of organisation information systems and assets) × 100100%8
19Critical Assets Identified(Number of critical systems identified / total IT systems integrated with SOC) × 10050%9
20CSK Events(Total number of CSK reported events closed in 15 days / total number of CSK reported events to the organisation) × 100100%4
21Cybersecurity Policy DocumentNon-quantifiable measure — Table 27 gives no formula and no target.100%4
22SOC efficacyAs specified in the SOC efficacy score at Annexure-N.100%5
23Automated compliance with CSCRF(Number of standards for which compliance has been automated / total number of CSCRF standards) × 100100%5
Annexure-K, Table 27. Weightages sum to 100.

Three of the 23 are not ordinary ratios, and together they carry 10 marks. Parameter 12 is inverse — it counts physical security incidents that allowed unauthorised entry, so its target is 0% and a lower number is better. Parameter 21 is expressly a non-quantifiable measure: Table 27 gives it no formula and no target at all, only implementation evidence about the policy document, its revision frequency and its approval. Parameter 22 defers to the SOC efficacy score defined at Annexure-N, so it is not computed here at all — you enter the score you already hold.

Two of the targets are not 100% either. Security Budget targets 10% of the IT budget, and Critical Assets Identified targets 50% of the systems integrated with your SOC. Reaching a target earns the full weightage; exceeding it earns nothing further.

How SEBI says to score it

The scoring rules are not in the framework. They are in SEBI’s CSCRF FAQ, which is a separate document, and they are specific enough that a calculator built without them will be wrong in ways nobody notices.

  • Partial scoring is pro rata. SEBI’s own worked example: an entity reaching 30% against a target of 50%, on a parameter carrying 5 marks, is awarded 3.
  • Scores may carry two decimal places, and the highest score for any category is capped at that category’s weightage — there is no credit above target.
  • An undefined value resolves per parameter, not uniformly. Where a formula divides zero by zero, the framework does not fall back to a single convention. On parameter 2, no vulnerabilities identified and none mitigated takes the maximum marks. On parameter 14, nobody with access and nobody screened takes zero. A calculator applying one rule to both is wrong in one direction or the other.
  • Everything runs on the financial year, and compliance is submitted along with the cyber audit report to the relevant reporting authority.

What the score gets you

RatingIndex score
Exceptional Cybersecurity Maturity91–100
Optimal Cybersecurity Maturity81–90
Manageable Cybersecurity Maturity71–80
Developing Cybersecurity Maturity61–70
Bare Minimum Cybersecurity Maturity51–60
Fail50 and below
Table 24 — rating categories of REs based on CCI.

A high score is not a pass. The Fail row carries a second limb — it applies at 50 or below, or where the “RE has scored below the cut-off in at least one domain/ sub-domain”. That makes Fail a floor test as well as a total, so an entity scoring in the eighties still fails on one weak domain. SEBI does not publish what the cut-off is; it appears nowhere in the framework. No calculator can determine that limb, this one included, and one that reports a clean pass on the aggregate alone is answering a question SEBI did not ask.

The bands are printed as whole numbers while the score itself may carry two decimals, so a figure such as 90.5 sits between two printed ranges. This tool reads such a score downward, into the band its integer part falls in.

EntityAssessmentFrequency
Market Infrastructure InstitutionsThird-party assessment of cyber resilience using the CCIHalf-yearly
Qualified REsSelf-assessment of cyber resilience using the CCIAnnually
Who computes the index, and how often.

Mid-size, Small-size and Self-certification REs have no CCI obligation at all. If you are not sure which category you are in, that is a different question and the CSCRF category finder answers it — and it is worth answering first, because the category is fixed at the start of the financial year and holds all year.

What the index cannot tell you

  • Whether you pass. The domain cut-off limb sits outside the arithmetic and outside the published framework.
  • Whether the numbers are evidenced. Implementation evidence goes to SEBI only on demand, but it has to exist. For an MII every item is verified by the auditor conducting the third-party assessment, so an unevidenced figure is a finding rather than a score.
  • Anything an outsider can see. Every parameter here is measured from inside. Expired certificates, exposed services and leaked credentials — the things a counterparty or a regulator can observe without asking — sit outside the index entirely.
  • What your assessor will conclude. This is a working figure for a conversation, not a submission.

For the framework as a whole, category by category, see the CSCRF compliance guide, or work out your incident-reporting deadlines with the incident reporting clock.

This tool is indicative and is not a submission. Parameters, formulas, targets and weightages are from Annexure-K, Table 27 of the CSCRF, and the rating bands from Table 24 — both read from SEBI’s own framework document, which carries the annexures the circular’s landing page does not. The scoring rules are from SEBI’s CSCRF FAQ. Your reporting authority determines the score that counts. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

What is the Cyber Capability Index under SEBI CSCRF?
An index-framework that rates the preparedness and resilience of a regulated entity’s cybersecurity, calculated on 23 parameters carrying different weightages and expressed out of 100. It applies to Market Infrastructure Institutions and Qualified REs only — Mid-size, Small-size and Self-certification REs have no CCI obligation. The parameters, their formulas, targets and weightages are set out in Annexure-K, Table 27 of the framework, and the rating bands in Table 24.
Who has to calculate a CCI score, and how often?
Market Infrastructure Institutions commission a third-party assessment of their cyber resilience using the CCI on a half-yearly basis. Qualified REs conduct a self-assessment annually. All periodicities under the framework run on the financial year, and compliance is submitted alongside the cyber audit report to the relevant reporting authority. A third-party assessment and a self-report do not carry the same evidential weight in a supervisory conversation.
How is the CCI score calculated?
Each of the 23 parameters is measured by its own formula, compared against its target, and awarded marks pro rata up to its weightage. SEBI’s FAQ gives the worked example: an entity reaching 30% against a target of 50% on a parameter carrying 5 marks is awarded 3. Scores may carry two decimal places, and the highest score for any category is capped at that category’s weightage. The weightages sum to 100.
What is a good CCI score?
The framework sets six bands: 91 and above is Exceptional Cybersecurity Maturity, 81 to 90 Optimal, 71 to 80 Manageable, 61 to 70 Developing, 51 to 60 Bare Minimum, and 50 or below is a Fail. The bands are printed as whole numbers while the score itself may carry two decimals, so a figure such as 90.5 sits between two printed ranges; read downward, it is Optimal.
Can an entity fail the CCI despite a high score?
Yes. The Fail row in Table 24 carries a second limb: it applies at 50 or below, or where the entity has scored below the cut-off in at least one domain or sub-domain. That makes Fail a floor test as well as a total, so a strong aggregate does not by itself demonstrate a pass. SEBI does not publish the cut-off value anywhere in the framework, so no calculator can determine that limb — it is a matter for the assessor and the reporting authority.
Are all 23 CCI parameters scored the same way?
No, and three of them are not ordinary ratios. Parameter 12, Physical Security Incidents, is inverse and carries a target of 0% — fewer is better — so the pro-rata rule of dividing by the target cannot be applied to it at all. Parameter 21, Cybersecurity Policy Document, is expressly a non-quantifiable measure with no formula and no target in Table 27. Parameter 22 defers to the SOC efficacy score defined at Annexure-N. Together they carry 10 of the 100 marks.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools