Compliance calendar
SEBISEBI periodic filings

Cyber security incident and data loss disclosure

The quarterly Reg 27(2)(ba) disclosure that accompanies the corporate governance report inside Integrated Filing (Governance).

Next due

30 Oct 2026

Later this yearIn 49 days

For Q2 FY2026-27

Regulator
SEBI
Category
SEBI periodic filings
Form
Not specified
Last verified
2026-09-01

The cyber security incident and data loss disclosure follows the Integrated Filing (Governance) deadline. It is due within 30 days of the end of each quarter because Reg 27(2)(ba) requires it to accompany the Reg 27(2)(a) report.

What changed

This disclosure does not have a separate quarterly filing clock. It accompanies the Reg 27(2)(a) report and therefore follows the 30-day Integrated Filing (Governance) deadline.

All dates this year

Past dates are kept, so a late filing can still be dated.

30 Jul 2026Q1 FY2026-2743 days ago
30 Oct 2026Q2 FY2026-27In 49 days
30 Jan 2027Q3 FY2026-27In 141 days
30 Apr 2027Q4 FY2026-27In 231 days

The rule

Stated as the law states it, so you can work out any period yourself.

Quarterly cyber security disclosure

Within 30 days from the end of each quarter, with Integrated Filing (Governance).

Who must comply

  • Every listed entity that must submit the corporate governance report under Reg 27(2)(a)

Statutory basis

Read the provision here where we hold it, or on the regulator's site.

Before you file

  • Get the cyber security incident and data loss record for the quarter.
  • Check the record with the information technology function.

How to file

  1. 1Prepare the quarterly cyber security disclosure.
  2. 2Add it to Integrated Filing (Governance).
  3. 3Submit the integrated filing on each exchange.
  4. 4Save the acknowledgement.

Stock exchange Integrated Filing (Governance) service

Last verified 2026-09-01. Confirm against the official source before you rely on it.