Cyber security incident and data loss disclosure
The quarterly Reg 27(2)(ba) disclosure that accompanies the corporate governance report inside Integrated Filing (Governance).
30 Oct 2026
- SEBI
- SEBI periodic filings
- Not specified
- 2026-09-01
The cyber security incident and data loss disclosure follows the Integrated Filing (Governance) deadline. It is due within 30 days of the end of each quarter because Reg 27(2)(ba) requires it to accompany the Reg 27(2)(a) report.
This disclosure does not have a separate quarterly filing clock. It accompanies the Reg 27(2)(a) report and therefore follows the 30-day Integrated Filing (Governance) deadline.
All dates this year
30 Jul 2026Q1 FY2026-27
30 Oct 2026Q2 FY2026-27
30 Jan 2027Q3 FY2026-27
30 Apr 2027Q4 FY2026-27
The rule
Within 30 days from the end of each quarter, with Integrated Filing (Governance).
Who must comply
- Every listed entity that must submit the corporate governance report under Reg 27(2)(a)
Statutory basis
Before you file
- Get the cyber security incident and data loss record for the quarter.
- Check the record with the information technology function.
How to file
- Prepare the quarterly cyber security disclosure.
- Add it to Integrated Filing (Governance).
- Submit the integrated filing on each exchange.
- Save the acknowledgement.
Stock exchange Integrated Filing (Governance) service