SEBI proposes extending IT, cybersecurity framework to market infastructure companies' arms
This story was originally published at 17:51 IST on 11 September 2026
Register to read our real-time news.Informist, Friday, Sept. 11, 2026
--SEBI issues consultation paper on IT, cybersec framework for mkt infra cos
--SEBI proposes extending IT, cybersec framework to mkt infra cos' arms
MUMBAI – The Securities and Exchange Board of India has proposed to extend the information technology and cybersecurity framework of market infrastructure institutions to their subsidiaries. This would ensure that the regulatory framework remains aligned with the evolving market structure even as market infrastructure institutions diversify their business models, SEBI said in a consultation paper issued Friday. The regulator has invited comments from market participants on the proposal by Oct. 2.
The IT and cybersecurity framework applicable to the parent institution shall also apply to the subsidiary where it is involved in activities that directly contribute to the domain pertaining to that of its parent, according to the proposal. This will be applicable where a subsidiary is carrying out an activity which the parent institution is supposed to do, or is handling data that the parent is supposed to handle, or is sharing infrastructure with the parent institution, the market regulator said.
If a parent institution believes the framework need not be extended to subsidiaries that meet only one of the conditions, SEBI has proposed that it may seek an exemption from the market regulator in such cases. "Such proposal shall include details of compensatory controls put in place/proposed to be put in place by MIIs (market infrastructure institutions) to ensure cyber and IT resilience of MIIs is not affected by such proposal along with views of SCOT (standing committee on technology) and Board of the MII," SEBI said.
Currently, the IT and cybersecurity framework applicable to market infrastructure institutions is not explicitly defined to cover their subsidiaries. As these institutions grow, the complexity of their operations increases, and they undertake technology-driven activities, there may be a case for them to use the services of their subsidiaries to carry out these activities, the market regulator said.
Moreover, with rising reliance on a digital ecosystem, the threat of cyber-attacks has increased. Attackers are using advanced technologies to exploit security gaps and gain unauthorised access to organisational data. "In order to strengthen the cybersecurity posture of SEBI-regulated entities, ensuring they can anticipate, withstand, contain, and recover from cyber incidents, SEBI has also prescribed Cybersecurity and Cyber Resilience Framework," it said. End
Reported by Ashutosh Pati
Edited by Rajeev Pai
For users of real-time market data terminals, Informist news is available exclusively on the NSE Cogencis WorkStation.
Cogencis news is now Informist news. This follows the acquisition of Cogencis Information Services Ltd. by NSE Data & Analytics Ltd., a 100% subsidiary of the National Stock Exchange of India Ltd. As a part of the transaction, the news department of Cogencis has been sold to Informist Media Pvt. Ltd.
Informist Media Tel +91 (22) 6985-4000
Send comments to feedback@informistmedia.com
© Informist Media Pvt. Ltd. 2026. All rights reserved.
To read more please subscribe


