Page 1 of 3 5th Floor, Tower E, World Trade Center, Nauroji Nagar, New Delhi – 110 029 Phone: 011 - 26517501, 26517503. website: www.pfrda.org.in परिपत्र परिपत्र संख्या :- पीएफआरडीए/2026/05/एसयूपी-पीओपी/01 दिनांक : 15 जनविी 2026 प्रति, राष्ट्रीय पेंशन प्रणाली (एनपीएस), एनपीएस-लाईट एवं एपीवाई के अंिर्गि सभी पीओपी सभी र्…
Page 1 of 3 5th Floor, Tower E, World Trade Center, Nauroji Nagar, New Delhi – 110 029 Phone: 011 - 26517501, 26517503. website: www.pfrda.org.in परिपत्र परिपत्र संख्या :- पीएफआरडीए/2026/05/एसयूपी-पीओपी/01 दिनांक : 15 जनविी 2026 प्रति, राष्ट्रीय पेंशन प्रणाली (एनपीएस), एनपीएस-लाईट एवं एपीवाई के अंिर्गि सभी पीओपी सभी र्ैर-वैयक्तिक सेवातनवृति सलाहकार दवषय : पीएफआिडीए द्वािा जािी सूचना एवं साइबि सुिक्षा नीदि दिशादनिेशों के अंिर्गि रिपोदटिंर् आवश्यकिाएँ यह पीएफआरडीए द्वारा जारी पररपत्र संख्या पीएफआरडीए/2024/14/आईसीएस/01 तिनांक 01 अर्स्त 2024, को जारी “मध्यवतिगयों/तवतनयतमि संस्थाओं (आरई) के तलए सूचना एवं साइबर सुरक्षा नीति तिशातनिेश–2024” के संिभग में है। उि तिशातनिेशों के प्रयोजन हेिु, मध्यवतिगयों/तवतनयतमि संस्थाओं (आरई) को तनम्नतलक्तिि िो श्रेतणयों में वर्ीकृि तकया र्या है : (i) श्रेणी–I– पेंशन फंड जो पीओपी के रूप में पंजीकृि हैं; िथा (ii) श्रेणी–II – पीओपी तजनमें एपीवाई-एसपी िथा र्ैर-वैयक्तिक सेवातनवृति सलाहकार सक्तितलि हैं। 2. उि तिशातनिेशों के अनुपालन में, मध्यविी / तवतनयतमि संस्थाएँ (पीओपी एवं र्ैर-वैयक्तिक आरए) संबंतिि तविीय वर्ग के तलए अनुलग्नक–I एवं अनुलग्नक–II में संलग्न प्रारूप के अनुसार अनुपालन प्रमाणपत्र, उि तविीय वर्ग की समाक्ति से 30 तिनों के भीिर प्रस्तुि करेंर्ी। 3. इसके अतिररि, CERT-In को ररपोतटिंर् (तकसी भी साइबर िुर्गटना की क्तस्थति में) के अलावा, सभी पीओपी (एपीवाई-एसपी सतहि) एवं र्ैर-वैयक्तिक आरए, तिनांक 01 अर्स्त 2024 के तिशातनिेशों में उक्तिक्तिि साइबर िुर्गटनाओं को अतनवायग रूप से पीएफआरडीए को ई-मेल आईडी reports-pop-@pfrda.org.in पर तवर्य पंक्ति “ साइबर िुर्गटना की रिपोदटिंर्” के साथ, उि तिशातनिेशों में तनिागररि समयसीमा एवं प्रारूप के अनुसार ररपोटग करेंर्े। इसके अतिररि, श्रेणी–I पीओपी को साइबर र्टनाओं पर त्रैमातसक आिार पर, उठाए र्ए सुिारात्मक उपायों के तववरण सतहि, पीएफआरडीए को ररपोटग प्रस्तुि करना अतनवायग होर्ा। 4. श्रेणी–I पीओपी को अपने साइबर सुरक्षा नीति िस्तावेज़, तजसे बोडग द्वारा समीक्षा एवं अनुमोिन प्राि हो, ऐसे अनुमोिन की तितथ से 30 तिनों के भीिर प्रातिकरण को प्रस्तुि करना होर्ा। 5. संशोतिि ररपोतटिंर् प्रारूप तविीय वर्ग 2025-26 से लार्ू होर्ा िथा यह पररपत्र संख्या पीएफआरडीए/2020/13/SUP-POP/2 तिनांक 21 अप्रैल 2020 का स्थान लेर्ा। ििनुसार, 1 अप्रैल 2026 या उसके पश्चाि प्रस्तुि की जाने वाली सभी ररपोटें संशोतिि प्रारूप में ही प्रस्तुि की जाएँर्ी। -Sd/- (आशीष कुमाि) मुख्य महाप्रबंिक संलग्नक : अनुलग्नक–I एवं अनुलग्नक–II Page 2 of 3 अनुलग्नक – I दवत्तीय वषग ________ हेिु श्रेणी–I PoPs के दलए साइबि सुिक्षा अनुपालन प्रमाणपत्र (प्रातिकरण द्वारा समय-समय पर तनतिगष्ट् माध्यमों से, तविीय वर्ग की समाक्ति से 30 कैलेंडर तिनों के भीिर पीओपी द्वारा प्रस्तुि तकया जाना है) यह प्रमातणि तकया जािा है तक _________________________________(पीओपी का नाम), जो पेंशन तनति तवतनयामक और तवकास प्रातिकरण (पीएफआरडीए) के साथ पंजीकरण संख्या __________________ के अंिर्गि पंजीकृि है, ने बोडग द्वारा अनुमोतिि सूचना एवं साइबर सुरक्षा नीति को अपनाया र्या है िथा पीएफआरडीए द्वारा जारी सूचना एवं साइबर सुरक्षा नीति तिशातनिेशों को डेटा, सूचना एवं आईटी प्रणातलयों की सुरक्षा हेिु अनुपातलि तकया र्या है। इसके अतिररि, पीएफआरडीए द्वारा जारी तिशातनिेशों के अनुसार साइबर सुरक्षा ऑतडट कराया र्या है िथा ऑतडट ररपोटग में अनुशंतसि सभी सुिारात्मक उपाय तवतिवि रूप से लार्ू तकए र्ए हैं। यति कोई साइबर र्टना हुई है, िो उसे पीएफआरडीए की सूचना एवं साइबर सुरक्षा नीति के अनुसार, CERT-In एवं पीएफआरडीए को ररपोटग तकया र्या है। पीओपी द्वारा साइबर र्टनाओं पर त्रैमातसक आिार पर, उठाए र्ए सुिारात्मक उपायों के तववरण सतहि, पीएफआरडीए को ररपोटग भी प्रस्तुि की र्ई है। यह भी प्रस्तुि तकया जािा है तक सूचना एवं साइबर सुरक्षा नीति को बोडग द्वारा तिनांक ____________ को अनुमोतिि तकया र्या था िथा इसकी अंतिम समीक्षा तिनांक _______________ को की र्ई थी। समीक्षित एवं अनुमोतिि साइबर सुरक्षा नीति को तवतनयतमि संस्था (आरई) के बोडग द्वारा अनुमोिन के 30 तिनों के भीिर पीएफआरडीए को प्रस्तुि तकया र्या है। इसके अतिररि, सूचना एवं साइबर सुरक्षा जोक्तिम प्रबंिन सतमति (ICSRM) के सिस्ों का तववरण तनम्नानुसार है : क्रम सं. सिस्य का नाम पिनाम 1 2 3 4 CISO/अनुपालन अदिकािी का नाम : पिनाम : मोबाइल नंबि : ई-मेल आईडी : दिनांक : स्थान : CISO/अनुपालन अदिकािी के हस्ताक्षि Page 3 of 3 अनुलग्नक – II दवत्तीय वषग ________ हेिु श्रेणी–II पीओपी के दलए साइबि सुिक्षा अनुपालन प्रमाणपत्र (प्रातिकरण द्वारा समय-समय पर तनतिगष्ट् माध्यमों से, तविीय वर्ग की समाक्ति से 30 कैलेंडर तिनों के भीिर पीओपी द्वारा प्रस्तुि तकया जाना है) यह प्रमातणि तकया जािा है तक _________________________________(पीओपी तजनमें एपीवाई-एसपी / र्ैर-वैयक्तिक आरए सक्तितलि हैं), जो पेंशन तनति तवतनयामक और तवकास प्रातिकरण (पीएफआरडीए) के साथ पंजीकरण संख्या __________________ के अंिर्गि पंजीकृि है, ने: बोर्ड द्वारा अनुमोक्षित सूचना एवं साइबर सुरिा नीक्षत को अपनाया एवं उसका पालन क्षकया है िथा पीएफआरडीए अथवा संबंतिि प्रिान तविीय क्षेत्र तवतनयामक (आरबीआई / सेबी / इरडाई / एनएचबी) ,जैसा भी लार्ू हो, द्वारा जारी सूचना एवं साइबर सुरक्षा नीति तिशातनिेशों को डेटा, सूचना एवं आईटी प्रणातलयों की सुरक्षा हेिु अनुपातलि तकया र्या है। इसके अतिररि , संबंतिि प्रिान तविीय क्षेत्र तवतनयामक द्वारा जारी तिशातनिेशों क अनुसार, साइबर सुरक्षा ऑतडट कराया र्या है िथा ऑतडट ररपोटग में अनुशंतसि सभी सुिारात्मक उपाय तवतिवि रूप से लार्ू तकए र्ए हैं। यति कोई साइबर िुर्गटना हुई है, िो उसे CERT-In िथा पीएफआरडीए, और संबंतिि प्रिान तविीय क्षेत्र तवतनयामक, जहाँ भी लार्ू हो, को उनकी सूचना एवं साइबर सुरक्षा नीति के अनुसार, ररपोटग तकया र्या है। CISO/अनुपालन अदिकािी का नाम : पिनाम : मोबाइल नंबि : ई-मेल आईडी : दिनांक : स्थान : CISO/अनुपालन अदिकािी के हस्ताक्षि Page 1 of 3 5th Floor, Tower E, World Trade Center, Nauroji Nagar, New Delhi – 110 029 Phone: 011 - 26517501, 26517503. website: www.pfrda.org.in Circular Circular No.: PFRDA/2026/05/SUP-PoP/01 Date:15 January, 2026 To, All Point of Presence (PoPs) under NPS, NPS-Lite and APY All Non-Individual Retirement Advisers (RAs) Subject: Reporting requirement under Information and Cyber Security Policy Guidelines issued by PFRDA This has reference to Circular no. PFRDA/2024/14/ICS/01 dated 1st August 2024 on the subject “Information & Cyber Security Policy Guidelines-2024 for intermediaries/Regulated Entities (REs)” issued by the PFRDA. For the purpose of these guidelines, the intermediaries/Regulated Entities (REs) are classified into two categories as (i) Category I - consisting of Pension Funds that are registered as Point of Presence (PoPs) (ii) Category II - consisting of Point of Presence (PoPs) including APY-SPs, Retirement Advisors excluding individuals. 2. In compliance with the said Guidelines, intermediaries/REs (PoPs and Non-Individual RAs) shall submit the certificate of compliance as per the format enclosed as Annexure I & II, for the respective Financial Year (FY), within 30 days from the end of the said FY. 3. Further, in addition to reporting to CERT-IN (in-case of any Cyber-incident), all PoPs including APY-SPs and Non-Individual RAs shall mandatorily report cyber incidents mentioned in the Guidelines dated 1st August 2024 to the PFRDA at reports-pop-@pfrda.org.in with the subject ‘Reporting of Cyber Incident’ in accordance with the reporting timeline and format outlined in the said Guidelines. Additionally, category I PoPs shall also required to submit the report on the cyber incidents to PFRDA on quarterly basis, along with the details of remedial actions taken. 4. Category I PoPs shall be required to submit their Cyber Security Policy which has been reviewed and approved by the Board to the Authority within 30 days of such approval by the Board of the regulated entity (RE). 5. The revised reporting format shall come into effect from the report applicable for the FY 2025- 26 and will supersede Circular No. PFRDA/2020/13/SUP-POP/2 dated 21st April 2020. Accordingly, all reports submitted on or after 1st April 2026 shall be required to be furnished in the revised format. (Ashish Kumar) Chief General Manager Encl: Annexure I & II ASHISH KUMAR Digitally signed by ASHISH KUMAR Date: 2026.01.15 16:42:16 +05'30' Page 2 of 3 Annexure I Cyber Security Compliance certificate for Category I PoPs the FY _________ (To be submitted by PoP through modes as specified by the Authority from time to time within 30 calendar days from the end of the FY) This is to certify that _________________________________ (Name of PoP) registered vide Reg. No. __________________ with Pension Fund Regulatory and Development Authority (PFRDA) has: Adopted and complied with the Information and Cybersecurity Policy approved by the Board and has adhered to the Information and Cybersecurity Policy Guidelines issued by PFRDA, for the protection of data, information, and IT systems. Further, a Cyber Security Audit was conducted in accordance with the guidelines issued by PFRDA and all remedial actions recommended in the audit report have been duly implemented. Cyber incidents, if any, were reported to CERT-In and PFRDA, in terms of the Information and Cybersecurity Policy of PFRDA. The PoP has also submitted the report on the cyber incidents to PFRDA on quarterly basis, along with the details of remedial actions taken. It is further submitted that the Information and Cybersecurity Policy was approved by the board on _____________ and the same was last reviewed on _______________. The reviewed and approved Cyber Security Policy has been submitted to PFRDA within 30 days of such approval by the Board of the regulated entity (RE). Additionally, the details of the members of Information and Cyber Security Risk Management Committee (ICSRM) is as mentioned below: S.No Name of the Member Designation 1 2 3 4 The changes in the constitution of the member of ICSRM committee, if any has duly been reported to the PFRDA. Name of CISO/Compliance Officer: Designation: Signature of CISO/Compliance officer Mobile No.: Email ID: Date: Place Page 3 of 3 Annexure II Cyber Security Compliance certificate for category II PoPs for the FY ________ (To be submitted by PoP through modes as specified by the Authority from time to time within 30 calendar days from the end of the FY) This is to certify that _________________________________ (Name of PoPs including APY-SPs /non-individual RAs) registered vide Reg. No. __________________ with Pension Fund Regulatory and Development Authority (PFRDA) has: Adopted and complied with the Information and Cybersecurity Policy approved by the Board and has adhered to the Information and Cybersecurity Policy Guidelines issued by PFRDA or the respective Principal Financial Sector Regulator (RBI / SEBI / IRDAI / NHB), as applicable, for the protection of data, information, and IT systems. Further, a Cyber Security Audit was conducted in accordance with the guidelines issued by the respective Principal Financial Sector Regulator, and all remedial actions recommended in the audit report have been duly implemented. Cyber incidents, if any, were reported to CERT-In and PFRDA, and were also reported to the respective Principal Financial Sector Regulator, wherever applicable, in terms of the Information and Cybersecurity Policy of such Principal Financial Sector Regulator. Name of CISO/Compliance Officer: Designation: Signature of CISO/Compliance officer Mobile No.: Email ID: Date: Place
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws