Compliance · India

AI that meets SEBI’s cyber-resilience framework.

CSCRF controls are binding for SEBI-regulated entities. Its data-localisation control is in abeyance, not repealed, so an on-prem deployment in India keeps you ready either way.

Framework
CSCRF, issued August 2024
Status
Binding for regulated entities
Data localisation
In abeyance since 31 Dec 2024
Our approach
Controls on infrastructure you operate

In short

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) sets binding cyber-security controls for regulated entities. Its data-localisation control (PR.DS.S2) has been held in abeyance since 31 December 2024 but can be reinstated by circular. AI that runs on infrastructure you operate in India meets the controls and stays ready if localisation returns.

What it asks

Requirements, and how we meet them.

RequirementHow DeepVox addresses it
Governance and identificationAI components and data flows documented in your asset inventory.
ProtectionRole-based access, encryption options and hardening on your infrastructure.
Detection and responseLogs and monitoring feed your SOC and incident process.
Data localisation (in abeyance)Deployed in India regardless, so reinstatement needs no change.

FAQ

Questions, answered.

Is SEBI data localisation required right now?

The CSCRF data-localisation control has been in abeyance since 31 December 2024. It was not repealed and can return by circular.

Does the rest of CSCRF apply?

Yes. All other controls remain binding.

Related

General information, not legal advice. Have your counsel confirm how each rule applies to you. Sources: SEBI CSCRF data localisation status. Updated October 2026.

Start with two weeks of evidence, not a sales call.

A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.

Book a discovery sprint