IFSCA · Guidelines

Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC

IFSCA-CSD/MSC/2/2026-DCS

In short
IFSCA-CSD/MSC/2/2026-DCS is the Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions in IFSC, issued on 20 April 2026 and in force from 1 April 2026 — twenty days before they were published. They bind the IFSC stock exchanges including the bullion exchange, the clearing corporations and the depositories, and they sit on top of the 2025 baseline Guidelines rather than replacing them, so an MII reads two instruments.

The record

ReferenceIFSCA-CSD/MSC/2/2026-DCS
Issued byInternational Financial Services Centres Authority (IFSCA)
Instrument typeGuidelines
Date of issue20 April 2026
StatusIn force
BindsStock exchanges including the bullion exchange, clearing corporations and depositories in the IFSC. A prescriptive regime layered on top of the 2025 baseline Guidelines rather than replacing them, so an MII complies with both. Issued 20 April 2026 but in force from 1 April 2026.
Dates it sets
  • 1 April 2026In force — twenty days before the Guidelines were issued.
  • 20 April 2028ISO 27001 certification, measured two years from issuance.
IFSCA MII Cyber Security Guidelines, 2026 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds IFSC stock exchanges including the bullion exchange, clearing corporations and depositories.
  • Layers a prescriptive regime on top of the principles-based 2025 baseline Guidelines rather than replacing them — an MII complies with both.
  • Runs a six-hour notification to IFSCA and CERT-In, triggered by noticing, detecting, or being brought to notice of an incident, then an interim report at three days, mitigation at seven and a root cause analysis at thirty.
  • Requires ISO 27001 certification within two years of issuance, so by 20 April 2028.
  • Requires annual audit at minimum, bi-annual VAPT for NCIIPC-designated systems, and an annual Cryptographic Risk Assessment with an express expectation of readiness to move to post-quantum standards.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating Every Indian cyber instrument, and who each one binds