Resources · Guides

ISO 27001 to CSCRF: how much you've already done

The crosswalk between Annex A and CSCRF, where the real gaps concentrate, and how to quantify coverage before planning anything.

CSCRF was not written in a vacuum. Its protection and detection controls overlap heavily with ISO 27001:2022 Annex A, access control, logging, network security, vulnerability management. An organisation with a running ISMS is not starting CSCRF from zero.

The genuine gaps concentrate in three places: SEBI-specific governance artefacts, the 6-hour incident reporting requirement with its particular content, and audit cadence obligations that differ from your certification cycle. These are the project; everything else is mapping.

Quantify before planning. A crosswalk with reviewable mappings turns 'how much is already done' from a consultant's estimate into a percentage with sources. In a representative demonstration environment the figure was 61%. Yours is computed from your control state.

Reviewed September 2026.

See it working on your data

Everything in this article runs live in a proof of concept: your frameworks, your evidence, your vendors.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.