IFSCA circular IFSCA-CSD/MSC/2/2026-DCS · 20 Apr 2026
Official title
Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC
Summary
Check the official recordThe International Financial Services Centres Authority (IFSCA) has issued comprehensive guidelines to strengthen the cyber security and resilience of Market Infrastructure Institutions (MIIs), including stock exchanges, clearing corporations, depositories, and the bullion exchange. These guidelines mandate a robust governance framework, including the appointment of a Chief Information Security Officer (CISO) and the formulation of a Board-approved Cyber Security and Cyber Resilience Policy. MIIs must implement stringent access controls, network security, data protection, and vulnerability management, including regular VAPT and 24/7 Cyber Security Operation Center (C-SOC) monitoring. The framework requires mandatory incident reporting to IFSCA and CERT-In within 6 hours of detection, annual audits by CERT-In empanelled auditors, and ISO 27001 certification within two years.
What you must do
Key dates
Who is affected
i
CIRCULAR
IFSCA-CSD/MSC/2/2026-DCS
April 20, 2026
To,
All the Stock Exchanges, including Bullion Exchange, in the International Financial Services Centres (IFSC)
All the Clearing Corporations in the International Financial Services Centres (IFSC)
All the Depositories in the International Financial Services Centres (IFSC)
Dear Madam/Sir,
Sub: Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC
IFSCA vide circular dated March 10, 2025 had issued the ‘Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs’, prescribing a minimum baseline framework for cyber security applicable to all Regulated Entities (REs) operating within GIFT IFSC. The said framework adopts a principles-based approach to ensure proportional applicability, taking into account the heterogeneity of REs in terms of size, structure, complexity and risk profile.
The Market Infrastructure Institutions (MIIs) comprising Stock Exchanges, Clearing Corporations, Depository and the Bullion Exchange are systemically critical to the stability, integrity and continuity of the capital market in IFSC. In view of their central role and heightened risk exposure, a more robust, granular and prescriptive cyber security framework is warranted.
Accordingly, with a view to enhancing cyber resilience, mitigating systemic cyber risks and ensuring preparedness against evolving threat vectors, IFSCA has formulated the “Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC” as set out in Annexure A.
The key objective of these Guidelines is to establish a comprehensive cyber security and cyber resilience framework for the MIIs operating in IFSC. The Guidelines seek to:
ii
a. strengthen governance and reinforce accountability for cyber security at the Board and Senior Management level b. address evolving cyber threat landscape, including emerging risks such as those arising from developments in quantum computing c. align MII cyber security practices with national and international standards and d. ensure robust incident detection, response, reporting and recovery mechanisms.
a. Govern b. Identify c. Protect d. Detect e. Respond f. Recover g. Resilience.
These Guidelines shall come into effect from April 01, 2026. The MIIs shall ensure full compliance within the timelines specified in the respective provisions of these Guidelines.
This Circular is issued in exercise of powers conferred by Sections 12 and 13 of the International Financial Services Centres Authority Act, 2019, to develop and regulate the financial services market in the International Financial Services Centre.
A copy of this circular is available on the website at www.ifsca.gov.in
Yours Faithfully,
Praveen Kamat General Manager & Chief Information Security Officer Division of Cyber Security Email: praveen.kamat@ifsca.gov.in Tel : +91- 079 - 61809820
1
Annexure A
Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC
Financial institutions today face a constant barrage of threats that attempt to compromise the Confidentiality, Integrity and Availability (CIA) of their computer systems, networks and databases. To counter this, it is imperative that a financial institution have a robust Cyber security framework in place that includes measures, tools and processes that are intended to prevent cyber-attacks and improve cyber resilience i.e. the capacity to maintain operations during a cyberattack and recover swiftly after a breach.
I. Govern
The Market Infrastructure Institutions (MIIs), as part of their operational risk management framework, shall formulate a comprehensive Cyber Security and Cyber Resilience Policy (“Policy”) to manage risks to their systems, networks, and databases posed by cyber-attacks and threats. This Policy document shall encompass the guidelines specified within this framework.
The Policy document must be approved by the Governing Board (Board) of the MIIs. The said policy shall also cover the mechanism for handling exceptions to the proposed framework. Furthermore, the Board shall periodically review the Policy document to ensure that the framework remains adaptive to emerging threats, in order to strengthen and improve the MII's cyber security and cyber resilience posture.
The MIIs shall prepare a risk appetite and risk tolerance statement as part of the Policy that articulates the nature and extent of cyber security risks that the MIIs are willing and able to assume. The Board and Senior Management shall ensure that key IT decisions are made in accordance with the MII’s risk appetite and risk tolerance statement.
The Policy shall establish a structured framework to identify, assess, and manage cyber security risks associated with the organization’s processes, information, networks, and systems. This framework shall comprise the following key processes:
i. 'Identify' critical IT assets and risks associated with such assets.
2
ii. 'Protect' assets by deploying suitable controls, tools, and measures.
iii. ‘Detect’ incidents, anomalies, and attacks through appropriate monitoring tools/processes.
iv. 'Respond' by taking immediate steps after identification of the incident, anomaly, or attack.
v. ‘Recover’ from incident through incident management, disaster recovery, and business continuity framework.
The Standing Committee on Technology (SCOT) of the MIIs shall review the implementation of the Policy on a bi-annual basis.
For MIIs that have been identified as Critical Information Infrastructure (CII) by the National Critical Information Infrastructure Protection Centre (NCIIPC), the policy shall encompass the principles prescribed by NCIIPC of the National Technical Research Organisation (NTRO), Government of India, in the report titled 'Guidelines for Protection of National Critical Information Infrastructure' and subsequent revisions, if any, from time to time.
The MIIs shall appoint a dedicated Chief Information Security Officer (CISO) who will be responsible for:
i. Assessing, identifying, and mitigating cyber security risks; ii. Responding to cyber security incidents; iii. Establishing cyber security standards and controls; iv. Implementing the necessary processes as per the Board-approved cyber security and resilience policy.
The CISO shall report directly to the Managing Director (MD)/Chief Executive Officer (CEO).
For the MIIs designated as CII by NCIIPC, the roles and responsibilities of the CISO shall also adhere to the aforesaid NCIIPC guidelines.
The Board and the Senior Management shall have members with the requisite knowledge to understand and manage risks posed by cyber threats.
3
The MIIs shall establish a reporting procedure to facilitate communication of unusual activities and events to the CISO or to the Senior Management in a timely manner.
The MIIs shall formally define and document the cyber security obligations for all individuals, who possess authorized access to the systems or networks of the MII, inter alia, including its:
a. internal employees, b. outsourced personnel, c. third-party vendors, d. market participants.
II. Identify
a. digital assets (such as URLs, domain names, applications, APIs, etc.), b. shared resources (including cloud assets), c. interfacing systems (internal and external), d. details of its network resources, e. connections to its network and data flows.
Any additions/ deletions or changes in existing assets shall be reflected in the asset inventory in a timely manner.
The MIIs shall identify and classify critical assets based on their sensitivity and criticality for business operations, services and data management. The critical assets shall, inter alia, include:
a. business-critical systems, b. internet-facing applications /systems, c. systems that contain sensitive data, d. sensitive personal data, e. sensitive financial data, f. Personally Identifiable Information (PII)