IFSCA · Guidelines

Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs

IFSCA-CSD0MSC/13/2025-DCS

In short
IFSCA-CSD0MSC/13/2025-DCS is the Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs, issued 10 March 2025 and in force from 1 April 2025. It binds any entity licensed, recognised, registered or authorised by IFSCA in GIFT City — which is why a GIFT City banking unit does not file under the RBI Directions and a GIFT City fund does not take a CSCRF category. Its incident clock runs six hours from detection, followed by an interim report at three days, mitigation at seven and a root cause analysis at thirty.

The record

ReferenceIFSCA-CSD0MSC/13/2025-DCS
Issued byInternational Financial Services Centres Authority (IFSCA)
Instrument typeGuidelines
Date of issue10 March 2025
StatusIn force
BindsAny entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended.
Dates it sets
  • 1 April 2025In force.
  • 10 March 2028The para 21 and para 23 exemptions lapse unless extended.
IFSCA Cyber Security Guidelines, 2025 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds any entity licensed, recognised, registered or authorised by IFSCA, displacing the mainland regulator rather than adding to it.
  • Runs a six-hour incident clock from detection, followed by an interim report at three days, mitigation measures at seven days and a root cause analysis at thirty.
  • Applies on a principle of proportionality, sized to the fact that an IFSC regulated entity may be a two-person branch.
  • Carries express exemptions that the March 2026 amendment restructured into two tiers with different conditions.
  • Leaves CERT-In in place: an IFSC entity still owes the six-hour report under the CERT-In Directions.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating Every Indian cyber instrument, and who each one binds