Skip to main content
Gated download · Monitoring evidence, not compliance advice · Reviewed August 2026

Eight frameworks ask you to show something. This says what shows it.

A control-by-control evidence matrix across RBI, SEBI CSCRF, IRDAI, DPDP, DORA, NIS2, ISO 27001:2022 and SOC 2 — what a review asks you to produce, what evidence answers it, and which artefact of a continuous external-monitoring programme actually generates that evidence. With a gap worksheet, an evidence-retention table and an audit-response template.

Said here rather than in a footer: it maps evidence to artefacts. It does not interpret an obligation, state which framework binds you, or tell you whether you are compliant. That assessment work belongs to your compliance function and to Security Brigade. Built for the GRC lead, the compliance manager, internal audit, and the CISO with an examination already on the calendar.

What is inside

Specific enough to be worth an email address

The matrix is a working document, not a brochure with a framework list on the cover. It is meant to be filtered to the frameworks that bind you, filled in against what you actually run today, and handed to somebody who will check it.

  • One row per evidence expectation, for each of the eight frameworks: what a review asks you to show, what satisfies it, and the artefact that produces it.
  • A boundary column on every row — what that artefact does not cover, stated beside the claim rather than in a footnote at the end.
  • A gap worksheet: the same rows again, with five states to mark each against, plus columns for the owner and the date.
  • An evidence-retention table you fill in against your own obligations, because retention differs by framework and by jurisdiction.
  • An audit-response template: the wording for a row that is evidenced, for one that is only partial, and for a risk that was accepted deliberately.
  • The SEBI rows written against the 28 August 2025 clarifications, which made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory rather than mandatory.

What is deliberately not in it: clause and control identifiers, tier or applicability tables, and any reading of what a framework requires of your entity. Those belong to an adviser working against the instruments that bind you — not to a matrix that has never seen your control set.

External Monitoring Evidence Matrix

The evidence matrix across RBI, SEBI CSCRF, IRDAI, DPDP, DORA, NIS2, ISO 27001:2022 and SOC 2 — with the gap worksheet, the retention table and the audit-response template.

By downloading, you agree to receive relevant communications. We respect your privacy.

Prefer not to fill anything in? Six of the eight frameworks have a free companion page on this site, ungated and linked further down. The matrix is the version you can put your own company name on.

Contents

Which rows you get, framework by framework

One block per framework. The note beneath each is the boundary for that block — including the two frameworks where the honest answer is that the matrix carries no companion page and no clause identifiers at all.

What the External Monitoring Evidence Matrix carries for each framework
FrameworkThe evidence rows the matrix carries for itFree companion page
RBI cyber security framework The external asset inventory, the continuous-monitoring record, per-finding remediation timestamps measured against your own window, third-party exposure, and the action log showing who changed what. RBI evidence guide
Applicability is not stated, and no supervisory reading of any obligation is offered. The rows map evidence to artefacts; whether that evidence answers a supervisor is assessment work, and it sits with Security Brigade.
SEBI CSCRF The same evidence rows, plus a validation row marked in the cell as evidence the framework does not ask for. Tier and classification are absent by design — they are not ours to state. SEBI CSCRF evidence guide
Written against the technical clarifications of 28 August 2025, which made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory rather than mandatory. Any matrix still presenting Continuous Automated Red-Teaming as a CSCRF requirement is out of date — the band below sets out what changed.
IRDAI cyber-security guidelines Rows for the estate an insurer answers for but does not operate: intermediary and distribution properties, policyholder credential exposure, and look-alike quote and payment pages. IRDAI monitoring guide
These rows carry the longest boundary column in the matrix. An intermediary property is somebody else’s asset and your exposure at the same time, and an outside-in method reaches only what is reachable from outside it.
DPDP Act What external monitoring can establish about personal data already outside your control — where it was observed, when it was first seen, and what it is attributable to. DPDP exposure guide
Nothing in these rows determines whether a personal data breach has occurred, or what follows from one if it has. That determination is legal, and it is not a monitoring vendor’s to make.
DORA Outside-in monitoring evidence on the ICT third-party providers you nominate, with the boundary column stating plainly what that evidence never reaches. DORA exposure guide
Provider-side findings are an input to a third-party risk assessment. They are not the assessment, they designate nothing, and no outside-in method sees anything behind a provider’s perimeter. The rows cite no article number.
NIS2 Supplier-side external findings scored with the same categories, the same arithmetic and the same bands used on your own estate, so an internal target and a supplier threshold are directly comparable. NIS2 supply-chain guide
The NIS2 rows describe what the monitoring record holds, not what the directive obliges — no article, no scope threshold, no entity classification. Which entities are in scope, and under whose national law, is a question for your own counsel.
ISO 27001:2022 The monitoring, logging and supplier rows an ISMS audit expects to see operating rather than documented: dated, scoped, and attributable to a named person and a specific asset. Covered in the matrix only
No control identifiers. A published Annex A mapping is a claim about what the standard requires of your ISMS, it depends on your own scope and control set, and it is certification work rather than product documentation.
SOC 2 The artefacts a service auditor asks for on monitoring, change and vendor oversight, expressed as dated records covering a period rather than a state on the day someone looked. Covered in the matrix only
A SOC 2 report is an opinion issued by a licensed service auditor about your controls over a period. Nothing in the matrix is that opinion, and no artefact in it substitutes for the examination that produces one.

What the External Monitoring Evidence Matrix carries for each framework

RBI cyber security framework

The evidence rows the matrix carries for it
The external asset inventory, the continuous-monitoring record, per-finding remediation timestamps measured against your own window, third-party exposure, and the action log showing who changed what.
Free companion page
RBI evidence guide

Applicability is not stated, and no supervisory reading of any obligation is offered. The rows map evidence to artefacts; whether that evidence answers a supervisor is assessment work, and it sits with Security Brigade.

SEBI CSCRF

The evidence rows the matrix carries for it
The same evidence rows, plus a validation row marked in the cell as evidence the framework does not ask for. Tier and classification are absent by design — they are not ours to state.
Free companion page
SEBI CSCRF evidence guide

Written against the technical clarifications of 28 August 2025, which made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory rather than mandatory. Any matrix still presenting Continuous Automated Red-Teaming as a CSCRF requirement is out of date — the band below sets out what changed.

IRDAI cyber-security guidelines

The evidence rows the matrix carries for it
Rows for the estate an insurer answers for but does not operate: intermediary and distribution properties, policyholder credential exposure, and look-alike quote and payment pages.
Free companion page
IRDAI monitoring guide

These rows carry the longest boundary column in the matrix. An intermediary property is somebody else’s asset and your exposure at the same time, and an outside-in method reaches only what is reachable from outside it.

DPDP Act

The evidence rows the matrix carries for it
What external monitoring can establish about personal data already outside your control — where it was observed, when it was first seen, and what it is attributable to.
Free companion page
DPDP exposure guide

Nothing in these rows determines whether a personal data breach has occurred, or what follows from one if it has. That determination is legal, and it is not a monitoring vendor’s to make.

DORA

The evidence rows the matrix carries for it
Outside-in monitoring evidence on the ICT third-party providers you nominate, with the boundary column stating plainly what that evidence never reaches.
Free companion page
DORA exposure guide

Provider-side findings are an input to a third-party risk assessment. They are not the assessment, they designate nothing, and no outside-in method sees anything behind a provider’s perimeter. The rows cite no article number.

NIS2

The evidence rows the matrix carries for it
Supplier-side external findings scored with the same categories, the same arithmetic and the same bands used on your own estate, so an internal target and a supplier threshold are directly comparable.
Free companion page
NIS2 supply-chain guide

The NIS2 rows describe what the monitoring record holds, not what the directive obliges — no article, no scope threshold, no entity classification. Which entities are in scope, and under whose national law, is a question for your own counsel.

ISO 27001:2022

The evidence rows the matrix carries for it
The monitoring, logging and supplier rows an ISMS audit expects to see operating rather than documented: dated, scoped, and attributable to a named person and a specific asset.
Free companion page
Covered in the matrix only

No control identifiers. A published Annex A mapping is a claim about what the standard requires of your ISMS, it depends on your own scope and control set, and it is certification work rather than product documentation.

SOC 2

The evidence rows the matrix carries for it
The artefacts a service auditor asks for on monitoring, change and vendor oversight, expressed as dated records covering a period rather than a state on the day someone looked.
Free companion page
Covered in the matrix only

A SOC 2 report is an opinion issued by a licensed service auditor about your controls over a period. Nothing in the matrix is that opinion, and no artefact in it substitutes for the examination that produces one.

The gap worksheet

Five states, and only one of them is a blank

Most control worksheets offer two options — done, or not done — so everything awkward becomes an empty cell. These are the five the matrix uses, and the two that usually go missing are the two that make a programme look like a programme.

The five states a row in the gap worksheet can carry
StateWhat it meansWhat you write in the row
Evidenced An artefact exists, carries a date, and covers the period under review. Cite the artefact and the period it covers. Nothing further is owed on that row.
Partial An artefact exists but reaches less than the row asks — a shorter period, a narrower scope, or part of the estate rather than all of it. Write the limit into the row. A partial answer stated is defensible; a partial answer presented as a whole one is the finding.
Accepted The exposure is known, has not been remediated, and somebody with the authority to carry it has said so in writing. Record the approver, the rationale and the review date, and keep the finding in the queue rather than out of it.
Gap Nothing you run today produces this evidence. Goes on the plan with an owner and a date. A gap you have written down is one you control.
Out of scope Terminal The row does not apply to your estate, your registration or your jurisdiction. State why, in the row. An unexplained blank is read as a gap, and reasonably so.
Key
  • Evidence exists and covers the period
  • Evidence exists but is narrower than the row
  • Carried deliberately, with an approver
  • No artefact produces this today
  • Does not apply to this estate
  • TerminalNo state follows this one

How to use it

The order matters more than the rows do

Each step decides what the next one is allowed to contain. Scope it wrongly and every row after that is noise; skip the gap column and the audit-response template has nothing to respond with.

The one row people get wrong

CSCRF does not mandate Continuous Automated Red-Teaming

It read that way once. It has not since August 2025 — and a control mapping that still carries it as a requirement is telling you to buy something on a basis that has been withdrawn.

Aug 2024 → Aug 2025

Breach and Attack Simulation and Continuous Automated Red-Teaming under CSCRF

What the master circular read as
The Cyber Security and Cyber Resilience Framework issued in August 2024 used mandatory language for Breach and Attack Simulation and for Continuous Automated Red-Teaming. That is why the claim persists, and why several published control mappings still carry it.
What the 28 August 2025 technical clarifications changed
SEBI replaced that with a recommendation, taken in consultation with the IT Committee. It is a real change to what the framework asks of you, and it means a vendor still selling Continuous Automated Red-Teaming as a CSCRF requirement is selling a requirement that no longer exists.
How the matrix handles it
The SEBI validation row says in the cell that the framework does not ask for this, rather than burying it in a note. Continuous Automated Red-Teaming is worth deploying if your IT Committee decides it is, because it keeps the estate tested between the scoped manual engagements — and that is the case the matrix makes for it, on its merits rather than on a circular.

Sourcing

What the matrix was built against, and what it leaves out

An undated compliance document is a liability. This one carries its review date on the cover, and the exclusions below are printed inside it rather than kept for a landing page.

How the matrix is built, and what it deliberately does not doCaution As of August 2026
  • Eight frameworks: RBI, SEBI CSCRF, IRDAI, DPDP, DORA, NIS2, ISO 27001:2022 and SOC 2. Each row states what a review asks you to show, what evidence answers it, and which monitoring artefact produces that evidence.
  • Rows carry no clause or control identifiers. A published mapping to identifiers is a claim about what a regulator requires of you, it goes stale on the next amendment, and it is advisory work rather than product documentation.
  • The SEBI rows are written against the framework as it stands after the technical clarifications of 28 August 2025, which made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory rather than mandatory.
  • The retention table ships as a worksheet with the periods blank. Retention differs by framework and by jurisdiction, and a table publishing our numbers would be wrong for most of the people reading it.
  • Every artefact named in the matrix is one a continuous external-monitoring programme produces in the ordinary course. Nothing in it is assembled specially for a review, which is the property that makes it worth reading.

Deliberately excluded

  • Applicability. Whether a framework binds your entity, and which tier, category or classification you fall into, is assessment work — Security Brigade publishes the tools for it and runs the engagements.
  • Clause and control identifiers, for every framework in the matrix without exception.
  • Retention periods. The table is a worksheet; the periods are yours to set against the obligations that actually bind you.
  • Everything internal. Each artefact is produced from outside your perimeter, so no internal control, nothing your security operations centre is obliged to produce, and no policy or governance artefact is covered.
  • Legal reading and audit sign-off. Nothing here interprets an instrument for your entity, and no artefact substitutes for the opinion an auditor issues.

Questions this page gets asked

Before any of this goes into a compliance file

Does the matrix tell us whether we are compliant?

No, and an asset that claimed to would be claiming something it cannot deliver. Compliance is a determination made about your organisation by your auditor, and ultimately by your regulator. What the matrix does is narrower and more useful: it says which artefact of a continuous external-monitoring programme produces which piece of evidence, so you can see what you already have and what you do not. What that evidence is worth against a particular obligation is assessment work, and assessment is a Security Brigade engagement rather than a product feature.

Does it map to clause or control identifiers?

No, and the omission is deliberate rather than an economy. A published clause mapping is a claim about what a regulator requires of you. It goes stale on the next amendment — SEBI alone has amended its framework repeatedly since the master circular, several times changing whether a control is mandatory at all — and it is advisory work rather than product documentation. In an engagement an adviser does that mapping against the instruments that actually bind you and against your own control set, which is the only version of it worth having.

Does SEBI CSCRF require Continuous Automated Red-Teaming?

No. SEBI made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory on 28 August 2025, to be taken in consultation with the IT Committee. The master circular did read as mandatory, which is why the claim is still circulating and why several published mappings still carry it. The matrix marks the row accordingly. Continuous Automated Red-Teaming is worth deploying because it keeps the estate tested between the scoped manual engagements — not because a circular compels you.

We are only in scope for two of these. Is it still worth the download?

That is the ordinary case, and the matrix is built for it. The rows are grouped by framework precisely so you can delete the ones that do not apply before you start, and the evidence categories underneath them repeat across frameworks — which is the actual finding most readers take away. An estate that produces a dated inventory, a change record, per-finding remediation timestamps and an accepted-risk register is answering most of what all eight ask for, in different words.

Who does the assessment and the audit?

Security Brigade — the same company, CERT-In empanelled since 2008. Classification, applicability, clause interpretation, the gap assessment itself and audit sign-off are all engagements there, and this page routes every one of those questions across rather than answering them. Keeping the two apart is deliberate: taking your classification from a monitoring vendor’s marketing page is the wrong way round.

What actually arrives when we submit the form?

An email with a confirmation link. Click it and the matrix downloads — the file is released only after the address has been shown to work, which is why the button says what it says rather than promising an instant download. The link expires in 48 hours, and nothing is gated behind a call.

Ungated companions

Six of the eight have a free page here already

One per regulator, no form, no download. They set out what a monitoring record contains for that framework. The matrix is the version with the worksheet, the retention table and the response template — the one you would put your own company name on.

The dated log of advisories and directives behind all of them is Regulatory Intelligence — 31 supervisory, national and standards authorities, each published item structured into binding-or-advisory with the deadline the document itself states, and routed to the part of the platform that holds the matching evidence. It is programme context, not a scan of your estate and not a reading of the instrument. The evidence itself comes from Attack Surface Management, Data Exposure Monitoring and Third-Party Risk Management, with the workflow and audit log on the platform.

For the assessment side

Classification, gap assessment and audit sign-off sit with Security Brigade

Same company, CERT-In empanelled since 2008. Every question this matrix deliberately does not answer — whether a framework binds you, which tier or category you fall into, what a clause means for your control set, and whether your evidence satisfies an examiner — is an engagement there rather than a feature here. Duplicating that work on this side would produce two pages that disagree the next time a regulator amends anything, and the reader would have no way to tell which one was current.

Start with the framework you are actually being examined against:

See what your evidence file is missing from outside

One apex domain, two business days, a written snapshot of what is already reachable — assets, credentials, leaked code and impersonating domains. No call required, and the snapshot is yours either way.