SEBI Proposes Extending Cybersecurity and IT Framework to Subsidiaries of Market Infrastructure Institutions — September 11, 2026
Published: 2026-09-11 20:04 IST | Category: Markets | Author: Abhi AI
The Securities and Exchange Board of India (SEBI) has moved to tighten digital resilience across the country's capital markets by proposing to extend its comprehensive Information Technology and Cyber Security Framework to the subsidiaries of Market Infrastructure Institutions (MIIs).
MIIs comprise key institutions such as stock exchanges, clearing corporations, and depositories. Under current regulations, parent MIIs are held to rigorous cybersecurity standards, but regulatory oversight over their subsidiaries has remained ambiguously defined, creating potential operational vulnerabilities.
In a consultation paper released on September 11, 2026, the market regulator highlighted that MIIs are increasingly diversifying their business models and engaging subsidiaries to deliver technology-driven solutions, handle market data, and support operational workflows. Because these arms frequently interface with parent systems or share critical IT assets, any security breach at the subsidiary level could pose systemic risks to India’s securities market.
Three Criteria for Inclusion
SEBI proposed that an MII's IT and cybersecurity framework will apply directly to a subsidiary if it satisfies any of the following three conditions:
- The subsidiary executes an activity that directly contributes to the domain or statutory function of the parent MII.
- The subsidiary processes or stores market data that the parent MII is tasked with handling.
- The subsidiary shares IT infrastructure, applications, or network systems with the parent MII.
Subsidiaries that do not meet any of these three thresholds will remain outside the scope of the framework.
Compliance Requirements and Exemptions
Entities brought under the extended rules will need to adhere to the full range of MII compliance mandates. These include periodic system audits, real-time incident reporting, rigorous technology governance, and institutionalised Business Continuity Planning and Disaster Recovery (BCP-DR) mechanisms.
Recognising operational nuances, the regulator has introduced an exemption window based on proportionality. If a subsidiary only meets the infrastructure-sharing criterion and does not perform domain functions or handle sensitive market data, the parent MII may apply to SEBI for an exemption.
To qualify for relief, the parent entity must submit detailed compensatory IT controls designed to guarantee that the MII’s operational resilience remains completely uncompromised. Such exemption requests must also be vetted and backed by the views of the MII's Standing Committee on Technology (SCOT) alongside formal approval from its board of directors.
Strengthening the Securities Ecosystem
With rising geopolitical cyber risks and automated threats targeting digital financial systems, closing perimeter gaps between parent market institutions and their affiliated corporate structures has emerged as a high priority for SEBI.
The public and market stakeholders have been invited to submit comments and feedback on the consultation paper by October 2, 2026. Once implemented, the norms are expected to enhance data protection and ensure uninterrupted continuity across India’s trading, settlement, and depository infrastructure.
Tags: SEBI NSE BSE CDSL NSDL Cybersecurity