Resources · Guides
ISO 27001 to CSCRF: how much you've already done
The crosswalk between Annex A and CSCRF, where the real gaps concentrate, and how to quantify coverage before planning anything.
CSCRF was not written in a vacuum. Its protection and detection controls overlap heavily with ISO 27001:2022 Annex A, access control, logging, network security, vulnerability management. An organisation with a running ISMS is not starting CSCRF from zero.
The genuine gaps concentrate in three places: SEBI-specific governance artefacts, the 6-hour incident reporting requirement with its particular content, and audit cadence obligations that differ from your certification cycle. These are the project; everything else is mapping.
Quantify before planning. A crosswalk with reviewable mappings turns 'how much is already done' from a consultant's estimate into a percentage with sources. In a representative demonstration environment the figure was 61%. Yours is computed from your control state.
Reviewed September 2026.
See it working on your data
Everything in this article runs live in a proof of concept: your frameworks, your evidence, your vendors.
