SEBI · Circular

Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format

HO/(449)2026-ITD-5_DIV1/I/19448/2026

In short
The SEBI circular of 24 August 2026, referenced HO/(449)2026-ITD-5_DIV1/I/19448/2026, aligns SEBI’s cyber incident reporting portal with the Financial Stability Board’s Format for Incident Reporting Exchange. It moved no deadline: the six-hour email and twenty-four hour portal obligations under CSCRF Annexure-O(B) are restated unchanged. What is new is that filing becomes staged — an initial report, intermediate updates, then a final closure.

The record

ReferenceHO/(449)2026-ITD-5_DIV1/I/19448/2026
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeCircular
Date of issue24 August 2026
StatusIn force
BindsEvery SEBI regulated entity already reporting under CSCRF. Filing moves to the Financial Stability Board’s Format for Incident Reporting Exchange, staged across initial report, intermediate updates and final closure, at https://siportal.sebi.gov.in. The six-hour and twenty-four hour clocks are unchanged.
Dates it setsIn effect on issue. The instrument sets no further dates.
SEBI incident portal — FIRE format as the register holds it, read from the issuing regulator's own notification.

What it says

  • Moves SEBI incident filing to the Financial Stability Board’s Format for Incident Reporting Exchange, at the SEBI incident portal.
  • Restates the existing CSCRF Annexure-O(B) clocks unchanged: six hours by email, twenty-four hours to the portal.
  • Makes filing staged rather than single: an initial report, intermediate updates as facts emerge, and a final closure.
  • States no transition period. Entities are told to build the systems, amend their bye-laws, and read the circular alongside CSCRF.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113SEBI regulated entities, graded into five categories with obligations scaled to the category.
  • SEBI LODREvery listed entity in any sector, through three separate cyber-facing clauses.
  • CERT-In Directions, 2022 No. 20(3)/2022-CERT-InVery nearly every organisation in India, with a six-hour incident report to CERT-In.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The six-hour incident reporting clock