SEBI · Circular

IT Resilience Index for Market Infrastructure Institutions (MIIs)

HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026

In short
The SEBI circular of 24 August 2026, referenced HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026, creates the IT Resilience Index — nine parameters with stated weightages summing to 100, computed half-yearly within 60 days of each half-year end. It binds Market Infrastructure Institutions alone, with AMC Repo Clearing Ltd carved out by name, and the first computation is for the half-year ending 31 March 2027.

The record

ReferenceHO/47/18/11(1)2026-MRD-TPD1/I/19509/2026
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeCircular
Date of issue24 August 2026
StatusIn force
BindsMarket Infrastructure Institutions — stock exchanges, clearing corporations and depositories — with AMC Repo Clearing Ltd carved out by name. Half-yearly computation within 60 days of each half-year end, reported to the Standing Committee on Technology and the Governing Board.
Dates it sets
  • 30 November 2026Industry Standards Forum finalises sub-parameters and measurement criteria.
  • 31 January 2027Standard Operating Procedures submitted to SEBI after SCOT review.
  • 28 February 2027ITRI framework operationalised, including the Early Warning System and real-time monitoring of service delivery.
  • 31 March 2027First ITRI computation submitted, for the half-year ending on this date.
SEBI IT Resilience Index as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds Market Infrastructure Institutions only — stock exchanges, clearing corporations and depositories — with AMC Repo Clearing Ltd excluded by name.
  • Sets nine parameters with stated weightages summing to 100: Availability 20, Security 20, Integrity 10, Governance 10, Reliability and Monitoring 10, Business Continuity 10, Modularity and Flexibility 10, Scalability 5, and a residual 5.
  • Requires the computation to be system-driven and non-discretionary, with manual retrieval permitted only where the exception is discussed with the MII’s Standing Committee on Technology in advance.
  • Requires an Early Warning System that detects deterioration in any parameter before it becomes a performance issue.
  • Reports to the Standing Committee on Technology and the Governing Board, half-yearly within 60 days of each half-year end.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113SEBI regulated entities, graded into five categories with obligations scaled to the category.
  • SEBI incident portal — FIRE format HO/(449)2026-ITD-5_DIV1/I/19448/2026Moved SEBI incident filing to the FIRE format and staged it, without moving either clock.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating What the IT Resilience Index asks of an MII