SEBI’s Cybersecurity and Cyber Resilience Framework establishes cyber-governance, vendor-risk and continuity expectations across market infrastructure institutions and regulated entities.
SEBI's CSCRF sets cybersecurity and cyber-resilience expectations for regulated entities in capital markets, including third-party / vendor risk and recovery capability. For a CIO, CISO or compliance officer, the practical issue is whether a critical third-party application can remain available when the provider fails, exits, is acquired or can no longer support the product.
Software escrow addresses custody: who holds the source code, build materials and documentation. Software Recoverability addresses the next question: whether those materials have been independently rebuilt, deployed and tested. The distinction matters because an agreement and a deposit do not prove that recovery can be completed within the institution’s operational tolerance.
Castler therefore treats the requirement as part of vendor onboarding. The agreement and first deposit are established when the relationship begins, every release is captured, and the verification evidence is renewed before an auditor, insurer or supervisor asks for it.