IRDAI · Guidelines

IRDAI Information and Cyber Security Guidelines, 2026

IRDAI/GA&HR/CIR/MISC/51/4/2026

In short
IRDAI/GA&HR/CIR/MISC/51/4/2026 is the covering circular for the IRDAI Information and Cyber Security Guidelines, 2026, issued on 6 April 2026. It binds all insurers, insurance intermediaries and the Insurance Information Bureau of India, and supersedes the 2023 Guidelines. Compliance is required from the financial year current at issue — FY 2026-27, which opened on 1 April 2026, five days before the circular was issued.

The record

ReferenceIRDAI/GA&HR/CIR/MISC/51/4/2026
Issued byInsurance Regulatory and Development Authority of India (IRDAI)
Instrument typeGuidelines
Date of issue6 April 2026
StatusIn force
BindsAll insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
Dates it sets
  • 1 April 2026Compliance required “from the current financial year”, which opened five days before the circular was issued.
IRDAI Guidelines, 2026 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds all insurers, insurance intermediaries and the Insurance Information Bureau of India.
  • Supersedes the IRDAI Information and Cyber Security Guidelines, 2023, issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
  • Requires compliance from the financial year current at issue, with no transition period and no phase-in.
  • Carries its control set in annexures, one of which is distributed as a compressed archive rather than as a readable document.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • CERT-In Directions, 2022 No. 20(3)/2022-CERT-InVery nearly every organisation in India, with a six-hour incident report to CERT-In.
  • DPDP Rules, 2025 G.S.R. 846(E)Data Fiduciaries, in three tranches, with the substantive duties commencing 13 May 2027.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating What the IRDAI 2026 Guidelines changed