IFSCA · Circular

Amendment to the Circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs”

IFSCA-CSD0MSC/1/2026-DCS

In short
The IFSCA circular of 10 March 2026, printed as IFSCA-CSD0MSC/1/2026-DCS, amends the 2025 Cyber Security Guidelines by restructuring their exemptions into two tiers. Para 21 was substituted and now covers branches, group-only Global In-House Centres and regulated entities with fewer than ten employees; a new para 23 was inserted covering foreign universities, newly incorporated standalone entities with no parent, and Credit Rating Agencies. The two tiers carry different conditions, and para 21 gained an annual cyber security audit report obligation that did not exist before.

The record

ReferenceIFSCA-CSD0MSC/1/2026-DCS
Issued byInternational Financial Services Centres Authority (IFSCA)
Instrument typeCircular
Date of issue10 March 2026
StatusIn force
BindsAll regulated entities in the IFSCs. Amends the 2025 Guidelines rather than standing alone: it substitutes the para 21 exemption list, inserts a second exemption tier at para 23 covering foreign universities, newly incorporated standalone REs and Credit Rating Agencies, and adds an annual cyber security audit report to the para 21 conditions. In effect immediately on issue.
Dates it sets
  • 10 March 2026In effect immediately on issue.
IFSCA Cyber Security Guidelines Amendment, 2026 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Substitutes para 21 of the 2025 Guidelines. It now covers branches of a regulated entity, Global In-House Centres serving only group companies, and regulated entities with fewer than ten employees.
  • Inserts a new para 23 covering foreign universities, newly incorporated standalone regulated entities with no parent, and Credit Rating Agencies.
  • Adds an annual cyber security audit report to IFSCA as a condition of the para 21 exemption — a real obligation that the 2025 text did not carry.
  • Widens who is let off rather than softening what the framework asks, so it changes who is inside the regime rather than what the regime says.
  • Takes effect immediately on issue.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating Every Indian cyber instrument, and who each one binds