Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format
HO/(449)2026-ITD-5_DIV1/I/19448/2026
The record
| Reference | HO/(449)2026-ITD-5_DIV1/I/19448/2026 |
|---|---|
| Issued by | Securities and Exchange Board of India (SEBI) |
| Instrument type | Circular |
| Date of issue | 24 August 2026 |
| Status | In force |
| Binds | Every SEBI regulated entity already reporting under CSCRF. Filing moves to the Financial Stability Board’s Format for Incident Reporting Exchange, staged across initial report, intermediate updates and final closure, at https://siportal.sebi.gov.in. The six-hour and twenty-four hour clocks are unchanged. |
| Dates it sets | In effect on issue. The instrument sets no further dates. |
What it says
- Moves SEBI incident filing to the Financial Stability Board’s Format for Incident Reporting Exchange, at the SEBI incident portal.
- Restates the existing CSCRF Annexure-O(B) clocks unchanged: six hours by email, twenty-four hours to the portal.
- Makes filing staged rather than single: an initial report, intermediate updates as facts emerge, and a final closure.
- States no transition period. Entities are told to build the systems, amend their bye-laws, and read the circular alongside CSCRF.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 — SEBI regulated entities, graded into five categories with obligations scaled to the category.
- SEBI LODR — Every listed entity in any sector, through three separate cyber-facing clauses.
- CERT-In Directions, 2022 No. 20(3)/2022-CERT-In — Very nearly every organisation in India, with a six-hour incident report to CERT-In.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .