Sunday, 13 September 2026

Indian corporate news, decoded into deal flow

NSE LIVE
NIFTY 50 INDIA VIX
as of
MARKETS
DEAL FLOW
SEBI Proposes Tighter Cybersecurity Rules for… ▲ Market News / Economy India’s Next Capex Supercycle: 10 Sectors… ▲ Capex & Future Plan Flipkart Minutes Grows 4X, Reaches 1,200… ▲ Market News / Economy Tata Sons Listing Back in Focus… ▲ Market News / Economy Avantel Trading Window Closed Ahead of… ▲ Mergers & Acquisitions JSW Infrastructure Gets LOI to Set… ▲ Order Book Stock Market Next Week: Key Events,… ▲ Market News / Economy
Home / Market News / SEBI Proposes Tighter Cybersecurity Rules for MII Subsidiaries
MN · Market News

SEBI Proposes Tighter Cybersecurity Rules for MII Subsidiaries

SEBI Proposes Tighter Cybersecurity Rules for MII Subsidiaries

The Securities and Exchange Board of India (SEBI) has proposed extending the IT and Cyber Security Framework applicable to Market Infrastructure Institutions (MIIs) to certain subsidiaries of these institutions.

The proposal comes as stock exchanges, clearing corporations and other market infrastructure institutions increasingly rely on technology-driven operations and subsidiaries for critical functions.

SEBI has opened the proposal for public comments, with stakeholders required to submit their views by October 2, 2026.

Why SEBI Wants Greater Cybersecurity Oversight

India’s securities market is becoming increasingly dependent on digital infrastructure.

Trading platforms, clearing and settlement systems, market surveillance, investor data and other critical functions rely on technology operating continuously.

At the same time, cyber threats are becoming more sophisticated, with attackers using advanced technologies to exploit security vulnerabilities and gain unauthorised access to systems and data.

SEBI already has IT and Cyber Security requirements for MIIs and has introduced its Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-regulated entities.

However, the regulator says there is a gap when critical technology activities are carried out through subsidiaries.

The latest consultation paper aims to address that gap.

Which MII Subsidiaries Could Come Under the Framework?

Under SEBI’s proposal, the parent MII’s IT and Cyber Security Framework would also apply to a subsidiary if it meets any one of three conditions.

1. It Performs a Regulated MII Activity

If a subsidiary performs an activity that directly contributes to the domain or regulated function of the parent MII, it could come under the framework.

For example, a technology subsidiary that develops, operates, or maintains the trading platform of a stock exchange would be covered.

2. It Handles Critical MII Data

A subsidiary handling data that the MII itself is responsible for protecting would also be covered.

This could include subsidiaries providing:

  • Analytics
  • Market surveillance
  • AI-based services
  • Data processing

where these activities involve trading, settlement, or investor data.

3. It Shares Critical IT Infrastructure

A subsidiary that shares critical technology infrastructure with the parent MII would also fall within the proposed framework.

This could include:

  • Data centres
  • Cloud infrastructure
  • Production servers
  • Databases
  • Disaster-recovery systems
  • Network infrastructure

The objective is to ensure that a cybersecurity weakness in a subsidiary does not become a vulnerability for the parent institution or the wider securities market.

What Requirements Could Apply?

Subsidiaries covered under the framework would have to comply with requirements relating to areas such as:

  • Cybersecurity
  • System audits
  • Incident reporting
  • Business Continuity Planning
  • Disaster Recovery
  • Technology governance

This would effectively extend the cybersecurity perimeter beyond the legal entity operating the exchange or other MII.

SEBI Proposes Exemption in Some Cases

The proposal also recognises that applying the full framework to every subsidiary may not always be proportionate.

For example, a subsidiary may share IT infrastructure with an MII but not perform a regulated function or handle MII data.

In such cases, the MII could seek an exemption from SEBI.

However, the MII would need to demonstrate that appropriate compensatory controls are in place to ensure that the cybersecurity and IT resilience of the MII is not compromised.

The proposal also requires the views of the MII’s relevant technology/cybersecurity committee and Board as part of such an exemption request.

SEBI’s Examples: Which Subsidiaries Would Be Covered?

SEBI’s consultation paper gives several illustrations.

A subsidiary developing and maintaining a stock exchange’s trading engine would be covered because it directly supports a regulated function.

Similarly, a subsidiary operating a Security Operations Centre (SOC), SIEM systems, vulnerability management, or incident response for an MII would fall within the framework.

A shared data-centre or cloud subsidiary hosting production servers or disaster-recovery infrastructure would also be covered.

Other examples include subsidiaries providing:

  • Identity and access management
  • Email and network infrastructure
  • Production server administration
  • Database management
  • Storage infrastructure

The common factor is access to critical systems, infrastructure or data.

Not Every Subsidiary Would Be Covered

SEBI is not proposing a blanket extension of the framework to every company within an MII’s corporate group.

For example, a subsidiary running investor education or certification programmes without access to MII systems or data would generally not fall within the framework.

Similarly, a real-estate or facility-management subsidiary would not be covered if it does not process MII data or operate MII systems.

An HR or payroll subsidiary without access to trading, clearing, settlement, or depository systems would also generally remain outside the MII cybersecurity framework.

This indicates that SEBI is attempting to follow a risk-based approach rather than simply applying the rules based on corporate ownership.

Potential Impact on Stock Exchanges and Other MIIs

The proposal could have implications for the technology architecture and governance of India’s market infrastructure.

Market infrastructure institutions increasingly use specialised subsidiaries and group entities for technology, data, cloud infrastructure and other services.

Under the proposed approach, the regulatory responsibility would effectively follow the critical function, data, or infrastructure.

That could mean additional:

  • Cybersecurity controls
  • System audits
  • Technology governance requirements
  • Incident-reporting procedures
  • Business-continuity testing
  • Disaster-recovery requirements

for subsidiaries performing critical functions.

Why This Matters for Investors

For investors, the proposal is important because market infrastructure is the backbone of India’s financial markets.

A disruption at a critical technology provider or subsidiary could potentially affect trading, clearing, settlement or market data.

SEBI’s proposed framework attempts to reduce that risk by ensuring that subsidiaries supporting these functions are subject to appropriate cybersecurity standards.

The move also reflects a broader regulatory trend: cybersecurity is increasingly being treated as a core market-stability issue rather than simply an IT issue.

Public Comments Open Until October 2

SEBI has invited comments and suggestions on the consultation paper.

Stakeholders have until October 2, 2026, to submit their responses through SEBI’s online public-comment mechanism.

The consultation paper was issued on September 11, 2026.

The proposal is not yet a final regulation. The final framework could change after SEBI considers feedback from market participants and other stakeholders.

Bottom Line

SEBI’s latest proposal could significantly strengthen the cybersecurity perimeter around India’s market infrastructure.

The key change is simple: critical cybersecurity obligations could follow the function, data or infrastructure even when that activity is performed through a subsidiary.

This could bring technology subsidiaries, shared data-centre entities, cybersecurity units and other critical service companies under the same cybersecurity framework as their parent MIIs.

For stock-market participants, the objective is clear — a subsidiary should not become the weak link in the technology infrastructure supporting India’s securities market.

The next important milestone will be October 2, 2026, when the public-comment period closes.

Investors and market participants should then watch for SEBI’s final decision and any changes to the proposed framework.

Source

SEBI – Consultation Paper: Applicability of IT & Cyber Security Framework of MIIs to their Subsidiaries

Investor Disclaimer: This article is for informational and educational purposes only and should not be considered investment advice or a recommendation to buy or sell any security. The SEBI proposal discussed above is a consultation proposal and may be modified before final implementation.