सनद — हर अनुपालन का प्रमाणिक रिकॉर्ड।
Sanad is the only India-built compliance platform with a hardware-attested endpoint agent, dual-audit verification, and a tamper-evident chain that maps directly to all four parts of SEBI's Cyber Security & Cyber Resilience Framework — for stock brokers, AMCs, custodians, and KRAs.
No obligation. Scored against all 4 CSCRF parts. Report delivered to your inbox.
CSCRF Coverage
Sanad maps every CSCRF control to a deterministic Boolean check — auto-monitored where possible, attested where required. Evidence is signed at the endpoint with TPM-rooted cryptography and chained in a tamper-evident ledger that any external auditor can independently re-verify.
Cyber security policy, board-approved framework, designated CISO, periodic risk assessments. Sanad ships a CISO-ready policy template and tracks board approval cycles automatically.
Asset inventory, access control, endpoint protection, network segmentation, vulnerability scanning, security event logging with 180-day retention. Sanad's Sentinel agent monitors all endpoints continuously and ships HMAC-signed logs to your nominated storage.
Incident response procedures with 6-hour reporting to CERT-In and SEBI, business continuity testing, periodic recovery drills. Sanad routes incidents to both CERT-In and SEBI SCORES portals from a single console.
Annual third-party VAPT, half-yearly cyber audit by SEBI-empanelled auditor, hardware-rooted evidence chain. Sanad generates a SEBI-format compliance report and an auditor-ready evidence pack with one click.
See Sanad In Action
Live control status across all four CSCRF parts. Continuously-updated evidence chain. One-click auditor pack. Your Risk Committee reviews posture in minutes, not weeks.
Live preview from our test tenant. Your tenant will look like this on Day 1.
Deployment in 30 Days
You sign Monday. Your auditor has evidence by end of month. Here's how.
License key emailed. Sanad portal provisioned. CISO + IT admin user setup. 45-minute kickoff call with our engineering team.
Sentinel.exe pushed to all endpoints via your MDM (Intune, GPO, JAMF). No manual install. First heartbeats within hours of deployment.
Dashboard surfaces every gap mapped to CSCRF sub-clauses. Work with our team to remediate. Self-attest controls where auto-monitoring isn't applicable.
Generate auditor-pack PDF. Share read-only audit view link with your SEBI-empanelled auditor. Present board-level dashboard to Risk Committee.
Pricing
Pricing scales with regulatory tier, not user count. All tiers include the Sentinel endpoint agent for unlimited endpoints within your registered legal entity, the full CSCRF Part I-IV control set, and an auditor-ready evidence pack.
Tier-3 brokers · < ₹500 cr daily turnover
per year · annual upfront · + GST
Tier-2 brokers · ₹500-5,000 cr daily turnover
per year · annual upfront · + GST
KRAs, mid-size AMCs, depository participants
per year · annual upfront · + GST
How Sanad Compares
CSCRF compliance is usually built one of four ways. Here's where each approach wins and where it falls short.
| Approach | Annual Cost | Time to Ready | Evidence Depth | CSCRF-specific |
|---|---|---|---|---|
Sanad CSCRF Purpose-built, India-made | ₹2.4-12 L | 30 days | Hardware-attested | 100% |
Enterprise SOC Vendor Sequretek, SecureLayer7, K7 | ₹15-40 L | 60-90 days | Log-based | Partial · generic SOC |
Big 4 Consulting PwC, KPMG, Deloitte, EY | ₹30-80 L | 90-180 days | Manual documentation | 100% · human-led |
In-house Build Internal IT + SIEM setup | ₹20-60 L | 6-12 months | Varies wildly | DIY mapping burden |
Where Sanad loses: very large entities (>1,000 endpoints) may prefer a full-service SOC. Where Sanad wins: purpose-built CSCRF mapping + hardware attestation + 5-10x lower price. We'll tell you honestly if Sanad isn't the right fit.
Three Ways to Procure
Email sanad@cognoshift.in. Signed MSA + PO within 7 days. GST invoice from COGNOSHIFT PRIVATE LIMITED (CIN, GSTIN verified). Annual upfront payment via Razorpay or NEFT.
Most CERT-In empanelled cyber audit firms can bundle Sanad into their annual CSCRF audit engagement. We pay referral, you get single invoice. Contact us for auditor firm list.
GeM listing coming Q3 2026 for PSU brokers, public-sector AMCs, and government-held institutions requiring GeM procurement. Join waitlist for GeM availability.
Frequently Asked Questions
Next Step
Answer 10 questions. Get a readiness score across all 4 CSCRF parts. Receive a prioritized gap report in your inbox. No sales call, no obligation.
Start the Self-Check →Direct call with our engineering team. We'll review your current CSCRF posture, map gaps to specific SEBI sub-clauses, and walk through deployment. Signed MSA possible same week.
Email sanad@cognoshift.in →What happens after you email us