IRDAI Information and Cyber Security Guidelines, 2026
IRDAI/GA&HR/CIR/MISC/51/4/2026
The record
| Reference | IRDAI/GA&HR/CIR/MISC/51/4/2026 |
|---|---|
| Issued by | Insurance Regulatory and Development Authority of India (IRDAI) |
| Instrument type | Guidelines |
| Date of issue | 6 April 2026 |
| Status | In force |
| Binds | All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023. |
| Dates it sets |
|
What it says
- Binds all insurers, insurance intermediaries and the Insurance Information Bureau of India.
- Supersedes the IRDAI Information and Cyber Security Guidelines, 2023, issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
- Requires compliance from the financial year current at issue, with no transition period and no phase-in.
- Carries its control set in annexures, one of which is distributed as a compressed archive rather than as a readable document.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- CERT-In Directions, 2022 No. 20(3)/2022-CERT-In — Very nearly every organisation in India, with a six-hour incident report to CERT-In.
- DPDP Rules, 2025 G.S.R. 846(E) — Data Fiduciaries, in three tranches, with the substantive duties commencing 13 May 2027.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .