63 of 244 CSCRF guidelines mapped, from 88 mapping points, with 37 of the 63 in access and authentication alone.
The Cyber Security and Cyber Resilience Framework runs across six functions: governance, identify, protect, detect, respond and evolve. Akku maps to 63 of its 244 guidelines, and 37 of those 63 sit in access and authentication, which is the single largest concentration in the framework. CSCRF also requires that logs of user access to critical systems be uniquely identified and retained for at least two years.

From 88 overlapping mapping points across the platform.
Market infrastructure institutions, credit rating agencies, asset management companies, custodians and stock brokers. CSCRF grades obligations by entity category, which changes reporting frequency and audit depth rather than which controls have to be in place.
| Module | Guidelines | Mapping points |
|---|---|---|
| UEM | ID.AM.S1-S4 (G2, G3, G4), PR.AA.S1-S9 (G2b), PR.AA.S15 (G1c, G4a, G4b, G4d, G4e, G4f), PR.IP.S1 (G2, G3), PR.IP.S2 (G1a, G1b, G1e, G1f), PR.IP.S15 (G1a, G1e), PR.MA.S2 (G2), PR.MA.S3 (G1-2) | 20 |
| PAM | PR.AA.S1-S9 (G1b, G1c, G3a, G3d, G4f), PR.AA.S4-S5 (G1), PR.AA.S10-S12 (G2a, G2b, G2c), PR.AA.S15 (G1c, G4c), PR.IP.S2 (G1a), PR.MA.S2 (G2, G3, G4), RS.AN.S1-S3 (G1-4) | 18 |
| Workforce IAM | ID.RA.S4 (G2), PR.AA.S1-S9 (G1e, G1f, G1i, G1j, G3b, G4h), PR.AA.S4-S5 (G1), PR.AA.S6 (G1, G3, G4), PR.AA.S8 (G3), PR.AA.S10-S12 (G2b), PR.IP.S2 (G1a), PR.IP.S16-S17 (G1b), PR.MA.S2 (G2) | 17 |
| CIAM | ID.RA.S4 (G2), PR.AA.S1-S9 (G1e, G1i, G1j, G4h), PR.AA.S16-S17 (G1b, G2i), PR.AT.S3 (G2, G3) | 9 |
| IGA | PR.AA.S1-S9 (G1a, G1b, G1c, G1g, G1h, G2a), PR.AA.S4-S5 (G2), PR.AA.S6 (G2), PR.AA.S15 (G4c) | 9 |
| DLP | PR.AA.S1-S9 (G1d, G3c), PR.AA.S8 (G3), PR.AA.S15 (G3a), PR.DS.S1-S3 (G1b, G1c, G1e, G4b), RS.AN.S1-S3 (G1-4) | 9 |
| MDM | ID.AM.S1-S4 (G2, G3), PR.AA.S1-S9 (G2b, G4j), PR.AA.S16-S17 (G2o), PR.MA.S2 (G2) | 6 |
CSCRF mandates a 24x7 security operations centre. Akku feeds logs into a SOC and does not staff or operate one. The rest of what sits outside is network hardware, offensive testing, business continuity, and the governance the framework requires of the board.