| A current inventory of assets | A dated external asset inventory — domains, subdomains, reachable services, exposed panels — with the attribution evidence that ties each entry to your organisation rather than to a similar name. | Attack Surface Management |
| CSCRF asset inventory covers the whole estate, including internal systems. Outside-in discovery covers the internet-facing part of it and nothing else — the internal register stays yours to maintain. |
| Monitoring that is continuous rather than point-in-time | A change record rather than a report: what appeared, what changed, when it was first observed, and when it stopped being observed. The record is the evidence, not a PDF generated from it. | Attack Surface Management |
| This is a record of external exposure. It is not a SOC, and it does not discharge whatever SOC or M-SOC obligation attaches to your tier. Which one attaches, and on what terms, is a classification question this page does not answer — Security Brigade publishes the tier cards that do. |
| Closure of findings inside a defined remediation timeline | Per-finding timestamps — first observed, acknowledged, owner assigned, closed — measured against the remediation window your own policy sets, so adherence is a query rather than a reconstruction. | The platform |
| The window is yours, not ours. CSCRF does not publish one universal remediation SLA, so the trail records adherence to whatever timeline your policy and IT Committee have defined. |
| Risks knowingly carried rather than remediated | An accepted-risk record holding the finding, the approver, the rationale and the review date — kept alongside the open queue rather than deleted out of it, so an accepted risk resurfaces when its review date arrives. | The platform |
| Acceptance is a decision your IT Committee or its delegate makes. The platform records the decision and keeps the finding visible; it does not make the decision, approve it, or judge whether it was reasonable. |
| Third-party and supply-chain exposure | Vendor-side external findings scored with the identical categories, the same maths and the same bands used on your own estate — so an internal target and a vendor threshold are directly comparable. | Third-Party Risk Management |
| The August 2025 clarifications place supply-chain risk assessment in consultation with the IT Committee. Outside-in vendor findings are an input to that assessment. They are not the assessment, and they do not see anything inside a vendor perimeter. |
| Exposure that has been tested, not only observed — which CSCRF does not ask for | Where it is safe and authorised, a validation record naming what was tested, the scope it was bounded to, the time it ran and the audit identifier for the run. | Continuous Automated Red-Teaming |
| CSCRF does not require this. SEBI made BAS and Continuous Automated Red-Teaming recommendatory on 28 August 2025 — see the section below before treating it as an obligation. Validation is also never universal: what was not tested says so. |
| Awareness of directives issued against you | A dated log of advisories and directives from the regulators in scope for you, matched against the technology actually discovered on your estate — so the question becomes whether a directive applies to you rather than whether it exists. | Regulatory Intelligence |
| Programme context, never legal advice. Tracking covers 31 regulators across 12 jurisdictions, which is useful precisely because SEBI amends this framework often — but a feed cannot tell you whether an amendment binds you. |
| An audit trail of who did what | An action log per finding: who changed its state, what they changed it to, and when. Nothing is deleted from the queue, so a closed or accepted finding is still there to be produced. | The platform |
| This is the platform’s own log and covers activity inside ShadowMap. It is one source among the several a CSCRF review will ask for, not the whole audit trail. |