SEBI · Regulations

Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015

In short
The SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 reach a cyber incident through three separate clauses. Regulation 30(6) sets the disclosure clock, and for a cyber incident that clock is twelve hours rather than the twenty-four usually quoted, because the event emanates from within the listed entity. Regulation 27(2)(ba) puts cyber incidents in the quarterly corporate governance report with no materiality test at all, and Regulation 21(4) requires the Risk Management Committee to cover cyber security.

The record

ReferenceNone — the instrument carries no circular number.
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeRegulations
Date of issue2 September 2015
StatusIn force
BindsEvery listed entity, in any sector. Reg. 30(6) sets the disclosure clocks for material events; Reg. 27(2)(ba) requires cyber incidents in the quarterly corporate governance report; Reg. 21(4) requires the Risk Management Committee to cover cyber security.
Dates it setsIn effect on issue. The instrument sets no further dates.
SEBI LODR as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds every listed entity in any sector, including listed entities with no financial-sector regulator at all.
  • Regulation 30(6) sets three disclosure limbs. A cyber incident falls in limb (ii) — twelve hours — because it emanates from within the listed entity.
  • Regulation 27(2)(ba) requires cyber incidents, breaches and loss of data in the quarterly corporate governance report, with no materiality test.
  • Regulation 21(4) requires the Risk Management Committee’s remit to cover cyber security.
  • Applies in addition to any sectoral cyber instrument: a listed broker owes CSCRF and these, and a listed bank owes the RBI Directions and these.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113SEBI regulated entities, graded into five categories with obligations scaled to the category.
  • SEBI incident portal — FIRE format HO/(449)2026-ITD-5_DIV1/I/19448/2026Moved SEBI incident filing to the FIRE format and staged it, without moving either clock.
  • CERT-In Directions, 2022 No. 20(3)/2022-CERT-InVery nearly every organisation in India, with a six-hour incident report to CERT-In.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The six-hour incident reporting clock