Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs
IFSCA-CSD0MSC/13/2025-DCS
The record
| Reference | IFSCA-CSD0MSC/13/2025-DCS |
|---|---|
| Issued by | International Financial Services Centres Authority (IFSCA) |
| Instrument type | Guidelines |
| Date of issue | 10 March 2025 |
| Status | In force |
| Binds | Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended. |
| Dates it sets |
|
What it says
- Binds any entity licensed, recognised, registered or authorised by IFSCA, displacing the mainland regulator rather than adding to it.
- Runs a six-hour incident clock from detection, followed by an interim report at three days, mitigation measures at seven days and a root cause analysis at thirty.
- Applies on a principle of proportionality, sized to the fact that an IFSC regulated entity may be a two-person branch.
- Carries express exemptions that the March 2026 amendment restructured into two tiers with different conditions.
- Leaves CERT-In in place: an IFSC entity still owes the six-hour report under the CERT-In Directions.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- IFSCA Cyber Security Guidelines Amendment, 2026 IFSCA-CSD0MSC/1/2026-DCS — Restructured the IFSCA exemptions into two tiers with different conditions.
- IFSCA MII Cyber Security Guidelines, 2026 IFSCA-CSD/MSC/2/2026-DCS — IFSC stock exchanges, clearing corporations and depositories, on top of the 2025 baseline.
- IFSCA Frontier AI Cyber Advisory, 2026 IFSCA-CSD/MSC/3/2026-DCS — All IFSC regulated entities — an advisory whose annexure is mostly drafted with “shall”.
- CERT-In Directions, 2022 No. 20(3)/2022-CERT-In — Very nearly every organisation in India, with a six-hour incident report to CERT-In.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .