NSE circular NSE/INSP/75970 · 25 Aug 2026
Official title
Alignment of SEBI's Cyber Incident Reporting Portal with FIRE Format
Official record
Open source pageSummary
Check the official recordSEBI updates its Cyber Incident Reporting Portal to align with the Format for Incident Reporting Exchange (FIRE) framework. This framework standardizes incident reporting through common information fields and consistent definitions. Regulated entities must report cyber incidents through the portal at https://siportal.sebi.gov.in. The portal now supports multi-stage reporting to track the incident life cycle from initial detection to final closure. Entities must implement necessary systems and amend relevant bye-laws, rules, or regulations to comply with these requirements. This circular applies to all SEBI regulated entities and must be read with existing cybersecurity and resilience frameworks.
What you must do
Who is affected
[Image omitted. See the official document.]
| Download Ref No: NSE/INSP/75970 | Date: August 25, 2026 |
|---|---|
| Circular Ref. No: 43/2026 |
To All Trading Members,
Sub: Alignment of SEBI's Cyber Incident Reporting Portal with FIRE Format.
This is with reference to SEBI circular no. SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024, and Exchange circular no. NSE/INSP/63502 dated August 21, 2024, on Cyber Security & Cyber Resilience framework for SEBI Regulated Entities (REs).
In this regard, SEBI has issued Circular no. HO/(449)2026-ITD-5_DIV1/I/19448/2026 dated August 24, 2026, on the subject Alignment of SEBI's Cyber Incident Reporting Portal with FIRE Format. A copy of the said SEBI circular is enclosed as Annexure-A for reference.
All Trading Members are advised to take note of the contents of this circular and comply.
For and on behalf of
National Stock Exchange of India Limited
Prashant Aier
Chief Manager – Inspection
[Image omitted. See the official document.]
Continuation Sheet
In case of any clarifications, Members may contact our below offices:
| Regional Office | Email Address | Contact No. |
|---|---|---|
| Ahmedabad (ARO) | inspectionahm@nse.co.in | 079- 49008632 |
| Chennai (CRO) | inspection_cro@nse.co.in | 044- 66309915 / 17 |
| Delhi (DRO) | delhi_inspection@nse.co.in | 011- 23459127 / 38 / 46 |
| Kolkata (KRO) | inspection_kolkata@nse.co.in | 033- 40400412 / 459 |
| Mumbai (WRO) | compliance_wro@nse.co.in | 022-26598200 / 022-61928200 |
| Central Help Desk | compliance_assistance@nse.co.in |
ANNEXURE - A
[Image omitted. See the official document.]
HO/(449)2026-ITD-5_DIV1/I/19448/2026 24.08.2026
| प्रति, | To, |
|---|---|
| सभी ऑलटरनेटिव इनवेस्टमेंट फंड (एआईफ़) | All Alternative Investment Funds (AIFs) |
| सभी बैंकर टू इश्यू और सेल्फ-सर्टिफाइड सिंडीकेट बैंक (एससीएसबी) | All Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs) |
| सभी क्लीयरिंग कारपोरेशन | All Clearing Corporations |
| सभी कलेक्टिव इनवेस्टमेंट स्कीमें (सीआईएस) | All Collective Investment Schemes (CIS) |
| सभी क्रेडिट रेटिंग एजेंसियाँ (सीआरए) | All Credit Rating Agencies (CRAs) |
| सभी कस्टोडियन | All Custodians |
| सभी डिबेंचर ट्रस्टी (डीटी) | All Debenture Trustees (DTs) |
| सभी डिपाँज़िटरी | All Depositories |
| सभी डेसिग्नेटेड डिपाँज़िटरी पार्टिसिपेंट (डीडीपी) | All Designated Depository Participants (DDPs) |
| सभी डिपाँज़िटरी पार्टिसिपेंट (डिपाँज़िटरीज़ के जरिए) | All Depository Participants through Depositories |
| सभी निवेश सलाहकार (आईए) / अनुसंधान विश्लेषक (आरए) | All Investment Advisors (IAs) / Research Analysts (RAs) |
| सभी केवाईसी रजिस्ट्रेशन एजेंसियाँ (केआरए) | All KYC Registration Agencies (KRAs) |
| सभी मर्चेंट बैंकर (एमबी) | All Merchant Bankers (MBs) |
| सभी म्यूचुअल फंड (एमएफ) / असेट मैनेजमेंट कंपनियाँ (एएमसी) | All Mutual Funds (MFs)/ Asset Management Companies (AMCs) |
| सभी पोर्टफोलियो प्रबंधक | All Portfolio Managers |
| सभी रजिस्ट्रार टू इश्यू और शेयर ट्रांसफर एजेंट (आरटीए) | All Registrar to an Issue and Share Transfer Agents (RTAs) |
| सभी स्टॉक ब्रोकर (एक्सचोंजों के जरिए) | All Stock Brokers through Exchanges |
| सभी स्टॉक एक्सचेंज | All Stock Exchanges |
| सभी वेंचर कैपिटल फंड (वीसीएफ) | All Venture Capital Funds (VCFs) |
| BSE लिमिटेड (इन्वेस्टमेंट एडवाइज़र एडमिनिस्ट्रेशन और सुपरवाइज़री बॉडी) | BSE Limited (Investment Adviser Administration and supervisory body IAASB) |
| BSE लिमिटेड (रिसर्च एनालिस्ट्स एडमिनिस्ट्रेशन और सुपरवाइज़री बॉडी) | BSE Limited (Research Analysts Administration and supervisory body-RAASB) |
पृष्ठ सं. 1 (कुल पृष्ठ 4)
Page 1 of 4
[Image omitted. See the official document.]
| महोदय/महोदया, | Sir/ Madam, |
| विषय: साइबर हमलों की घटनाओं की जानकारी देने के लिए बनाए गए एक ही पोर्टल (साइबर इंसिडेंट रिपोर्टिंग पोर्टल) के तहत फायर फॉर्मेट के अनुसार जानकारी देने की व्यवस्था करना | Subject: Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format |
| 1. शेयर बाजार (सिक्यूरिटीज़ मार्केट) में तकनीक जिस तरह तेजी से अपने पैर पसार रही है, उसके साथ-साथ साइबर हमलों की घटनाओं की तादाद भी बढ़ती जा रही है और अलग-अलग पैंतरे अपनाकर इन घटनाओं को अंजाम भी दिया जाने लगा है । इस तरह पैदा हो रहे खतरों से समय रहते निपटने और शेयर बाजार की समूची व्यवस्था में सुरक्षा को और पुख्ता करने के उद्देश्य से यह जरूरी है कि इस तरह की घटनाओं की भनक लगते ही इनकी जानकारी दे दी जाए, ताकि इनकी वजह से हो सकने वाले नुकसान को कम किया जा सके और साथ ही सुरक्षा के लिहाज से और पुख्ता इंतजाम किए जा सकें । | 1. With the rapid pace of technological developments in securities market, the frequency and sophistication of cyber incidents are also on the rise. To proactively address these evolving threats and ensure the security of securities market ecosystem, prompt reporting of these incidents are crucial to contain the attack, implement mitigation measures and strengthen defences. |
| 2. सेबी ने पहले से ही सी.एस.सी.आर.एफ. के ढाँचे के Annexure-O (B: Guidelines on Handling Cybersecurity Incidents) में साइबर हमलों की घटनाओं की जानकारी देने के संबंध में दिशानिर्देश जारी किए हुए हैं, जिनके अनुसार सेबी के विनियामक (रेग्यूलेटरी) दायरे में आने वाली सभी एंटिटियों के लिए यह अनिवार्य किया हुआ है कि वे साइबर हमलों की घटनाओं की जानकारी 6 घंटों के भीतर इस ईमेल पर दें: mkt_incidents@sebi.gov.in और साथ ही 24 घंटों के भीतर सेबी के "इंसिडेंट रिपोर्टिंग पोर्टल" पर दें । | 2. SEBI has already prescribed guidelines for reporting of cyber incidents under Annexure-O (B: Guidelines on Handling Cybersecurity Incidents) of CSCRF framework, mandating that all regulated entities report cyber incident through mkt_incidents@sebi.gov.in within 6 hours and SEBI Incident Reporting Portal within 24 hours. |
पृष्ठ सं. 2 (कुल पृष्ठ 4)
Page 2 of 4
[Image omitted. See the official document.]