Amendment to the Circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs”
IFSCA-CSD0MSC/1/2026-DCS
The record
| Reference | IFSCA-CSD0MSC/1/2026-DCS |
|---|---|
| Issued by | International Financial Services Centres Authority (IFSCA) |
| Instrument type | Circular |
| Date of issue | 10 March 2026 |
| Status | In force |
| Binds | All regulated entities in the IFSCs. Amends the 2025 Guidelines rather than standing alone: it substitutes the para 21 exemption list, inserts a second exemption tier at para 23 covering foreign universities, newly incorporated standalone REs and Credit Rating Agencies, and adds an annual cyber security audit report to the para 21 conditions. In effect immediately on issue. |
| Dates it sets |
|
What it says
- Substitutes para 21 of the 2025 Guidelines. It now covers branches of a regulated entity, Global In-House Centres serving only group companies, and regulated entities with fewer than ten employees.
- Inserts a new para 23 covering foreign universities, newly incorporated standalone regulated entities with no parent, and Credit Rating Agencies.
- Adds an annual cyber security audit report to IFSCA as a condition of the para 21 exemption — a real obligation that the 2025 text did not carry.
- Widens who is let off rather than softening what the framework asks, so it changes who is inside the regime rather than what the regime says.
- Takes effect immediately on issue.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- IFSCA Cyber Security Guidelines, 2025 IFSCA-CSD0MSC/13/2025-DCS — Any entity licensed, recognised, registered or authorised by IFSCA in GIFT City.
- IFSCA MII Cyber Security Guidelines, 2026 IFSCA-CSD/MSC/2/2026-DCS — IFSC stock exchanges, clearing corporations and depositories, on top of the 2025 baseline.
- IFSCA Frontier AI Cyber Advisory, 2026 IFSCA-CSD/MSC/3/2026-DCS — All IFSC regulated entities — an advisory whose annexure is mostly drafted with “shall”.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .