Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC
IFSCA-CSD/MSC/2/2026-DCS
The record
| Reference | IFSCA-CSD/MSC/2/2026-DCS |
|---|---|
| Issued by | International Financial Services Centres Authority (IFSCA) |
| Instrument type | Guidelines |
| Date of issue | 20 April 2026 |
| Status | In force |
| Binds | Stock exchanges including the bullion exchange, clearing corporations and depositories in the IFSC. A prescriptive regime layered on top of the 2025 baseline Guidelines rather than replacing them, so an MII complies with both. Issued 20 April 2026 but in force from 1 April 2026. |
| Dates it sets |
|
What it says
- Binds IFSC stock exchanges including the bullion exchange, clearing corporations and depositories.
- Layers a prescriptive regime on top of the principles-based 2025 baseline Guidelines rather than replacing them — an MII complies with both.
- Runs a six-hour notification to IFSCA and CERT-In, triggered by noticing, detecting, or being brought to notice of an incident, then an interim report at three days, mitigation at seven and a root cause analysis at thirty.
- Requires ISO 27001 certification within two years of issuance, so by 20 April 2028.
- Requires annual audit at minimum, bi-annual VAPT for NCIIPC-designated systems, and an annual Cryptographic Risk Assessment with an express expectation of readiness to move to post-quantum standards.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- IFSCA Cyber Security Guidelines, 2025 IFSCA-CSD0MSC/13/2025-DCS — Any entity licensed, recognised, registered or authorised by IFSCA in GIFT City.
- IFSCA Cyber Security Guidelines Amendment, 2026 IFSCA-CSD0MSC/1/2026-DCS — Restructured the IFSCA exemptions into two tiers with different conditions.
- IFSCA Frontier AI Cyber Advisory, 2026 IFSCA-CSD/MSC/3/2026-DCS — All IFSC regulated entities — an advisory whose annexure is mostly drafted with “shall”.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .