NSE circular NSE/INSP/76673 · 01 Oct 2026
Official title
Quarterly Cyber Incident Reporting under Cyber Security & Cyber Resilience Framework for Regulated Entities (REs)
Official record
Open source pageSummary
Check the official recordThe National Stock Exchange requires all trading members to submit a Quarterly Cyber Incident Report for the quarter ending September 30, 2026. Members must submit this report through the ENIT member portal by October 15, 2026. The submission process involves assigning the ENIT New Trade role to a designated officer, entering incident details, and uploading the generated report. Digital signatures are not required for this submission. Failure to submit the report by the due date results in daily financial charges and potential disciplinary actions, including the prohibition of new client registrations and the disablement of trading facilities in all segments. Repeat violations incur an additional 50 percent penalty escalation.
What you must do
Who is affected
| Download Ref No: NSE/INSP/76673 | Date: October 01, 2026 |
|---|---|
| Circular Ref. No: 45/2026 |
To All Trading Members,
Sub: Quarterly Cyber Incident reporting under Cyber Security & Cyber Resilience Framework for Regulated Entities (REs)
This is with reference to SEBI circular no. SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024 and Exchange circular no. NSE/INSP/63502 dated August 21, 2024 on Cyber Security & Cyber Resilience framework for SEBI Regulated Entities (REs).
In view of the above, REs/trading members are required to report Cyber Incident(s) for the quarter ending September 30, 2026, through member portal on or before October 15, 2026. The path for online submission of the Quarterly Cyber Incident Report is given below.
ENIT > ENIT-NEW-TRADE > Trade > Incident Report > Quarterly Report Submission.
In addition to the above for reporting of Immediate Cyber Incident, REs/trading members are requested to refer to Exchange circular no. NSE/INSP/66040 dated January 08, 2025, on Standard Operating Procedure (SOP) for handling Cyber Security Incidents.
The guidelines for submitting the Quarterly Cyber Incident Report is given in Annexure 1.
Trading Members are requested to refer Annexure - 1.2 of Exchange Circular Ref No. NSE/INSP/73792 dated April 17, 2026, on actions for non-compliances observed in periodic submissions by trading members related to the Quarterly Cyber Incident Reporting. The details of financial disincentive(s)/ Penalties/ disciplinary action(s) have been provided in Annexure 2.
All Trading Members are advised to take note of the above and comply.
In case of any query or support for cyber incident reporting, please reach us on email address: DL-SYSCYB@nse.co.in
For and on behalf of
National Stock Exchange of India Limited
Prashant Aier
Chief Manager – Inspection
In case of any clarifications, Members may contact our below offices:
| Regional Office | CONTACT NO. | E MAIL ID |
|---|---|---|
| Ahmedabad (ARO) | 079-65278024/55 | inspectionahm@nse.co.in |
| Chennai (CRO) | 044- 66309915/17 | inspection_cro@nse.co.in |
| Delhi (DRO) | 011-23459146/127/144/147 | delhi_inspection@nse.co.in |
| Kolkata (KRO) | 033- 40400404/06 | inspection_kolkata@nse.co.in |
| Mumbai (WRO) | 022-61928200 | compliance_wro@nse.co.in |
| Central Help Desk | compliance_assistance@nse.co.in |
[Image omitted. See the official document.]
[Image omitted. See the official document.]
[Image omitted. See the official document.]
| S.No | Year | Quarter | Submission Start Date | Due Date | Submission |
|---|---|---|---|---|---|
| 1 | 2026-27 | Q2 | October 01, 2026 | October 15, 2026 | Submit Details |
[Image omitted. See the official document.]
[Image omitted. See the official document.]
[Image omitted. See the official document.]
[Image omitted. See the official document.]
[Image omitted. See the official document.]
[Image omitted. See the official document.]
User can see the status of the report on the below path:
ENIT-NEW-TRADE >Trade > Incident Report > Quarterly View Report
The following penalty/ disciplinary actions would be initiated against the Trading Member for late/non-submission in this regard:
| Details of Violation/contravention | Action in case of first instance | Action in case of repeat instance |
|---|---|---|
| Delay/Non-submission of Cyber Incident reporting (Quarterly Submission) within the due date | 1.Charges Rs. 1,500/- per day for Non QRE & Rs. 3,000/- per day for QRE from the due date till first 7 calendar days or submission of report, whichever is earlier. |
2.Charges of Rs. 2,500/- per day for Non QRE & Rs. 5,000/- per day for QRE from 8th calendar day after the due date to 21st calendar day or submission of report, whichever is earlier.
3.In case of non-submission of report till 21st calendar days, new client registration shall be prohibited and notice of 7 calendar days for disablement of trading facility till submission of report, shall be issued.
4.The disablement notice issued to the member will be shared with all the Exchanges for information.
5.In case of non-submission of report by 28th calendar day, Member shall be disabled in all segments till submission of report. | 2nd Time & Onwards -Levy of applicable monetary penalty along with an escalation of 50%.
In case of non-submission of report till 21st calendar days, new client registration shall be prohibited and notice of 7 calendar days for disablement of trading facility till submission of report, shall be issued. The disablement notice issued to the member will be shared with all the Exchanges for information. In case of non-submission of report by 28th calendar day, Member shall be disabled in all segments till submission of report. |
Exceptions
If you do not comply