The Indian cyber regulation register
Every cyber and data-protection instrument binding Indian regulated entities — reference, date, status, deadlines. Read at source; downloadable as JSON and CSV.
Twenty-five instruments govern cyber security and personal data for Indian regulated entities, issued by six different authorities over four years. There is no official consolidated list of them — each regulator publishes its own, in its own format, and most secondary summaries are assembled from each other rather than from the notifications.
This is the list, kept current. Every entry carries the instrument’s own reference number, its issue date, whether it is actually in force, any deadline it sets, and the date somebody last opened the regulator’s own page to check. It is published as a page to read and as a dataset to use.
The register
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| Commercial Banks RBI/ | 31 July 2026 Directions | In force | Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters. | In effect on issue. |
| Small Finance Banks RBI/ | 31 July 2026 Directions | In force | Small Finance Banks. | In effect on issue. |
| Payments Banks RBI/ | 31 July 2026 Directions | In force | Payments Banks. | In effect on issue. |
| Urban Co-operative Banks RBI/ | 31 July 2026 Directions | In force | Primary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949, graded into Levels I to IV by the digital services they offer. | In effect on issue. |
| All India Financial Institutions RBI/ | 31 July 2026 Directions | In force | EXIM Bank, NABARD, SIDBI, NHB and NaBFID. | In effect on issue. |
| Non-Banking Financial Companies RBI/ | 31 July 2026 Directions | In force | All NBFCs registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987. Three obligation chapters, drafted as alternatives rather than as a ladder: Chapter III for Base Layer NBFCs below ₹500 crore of assets and for Core Investment Companies, Chapter IV for Base Layer NBFCs at ₹500 crore and above, and Chapter V for Middle Layer and above, excluding Core Investment Companies. | In effect on issue. |
| Credit Information Companies RBI/ | 31 July 2026 Directions | In force | Credit Information Companies as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005. | In effect on issue. |
| RBI outsourcing Directions, 2025 RBI/ | 28 November 2025 Directions | In force | Commercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered. |
|
| RBI NBFC outsourcing Directions, 2025 RBI/ | 28 November 2025 Directions | In force | NBFCs across the scale-based layers, together with HFCs, CICs, standalone primary dealers and the account aggregator and P2P categories. Existing IT outsourcing agreements to comply by 10 April 2026. |
|
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| SEBI CSCRF SEBI/ | 20 August 2024 Framework | In force | SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. |
|
| CSCRF clarifications, December 2024 SEBI/ | 31 December 2024 Circular | In force | Answered the first round of queries from regulated entities. | In effect on issue. |
| First extension, March 2025 SEBI/ | 28 March 2025 Circular | In force | Extended compliance timelines by three months, to 30 June 2025, for all REs except MIIs, KRAs and QRTAs. |
|
| CSCRF clarifications, April 2025 SEBI/ | 30 April 2025 Circular | In force | Revised the categorisation criteria and thresholds, including for Depository Participants. | In effect on issue. |
| Second extension, June 2025 SEBI/ | 30 June 2025 Circular | In force | Extended compliance timelines by a further two months, to 31 August 2025, for all REs except MIIs, KRAs and QRTAs. |
|
| Technical clarifications, August 2025 SEBI/ | 28 August 2025 Circular | In force | Technical readings of the standards, issued as the principal deadline passed. | In effect on issue. |
| SEBI incident portal — FIRE format HO/ | 24 August 2026 Circular | In force | Every SEBI regulated entity already reporting under CSCRF. Filing moves to the Financial Stability Board’s Format for Incident Reporting Exchange, staged across initial report, intermediate updates and final closure, at https://siportal.sebi.gov.in. The six-hour and twenty-four hour clocks are unchanged. | In effect on issue. |
| SEBI IT Resilience Index HO/ | 24 August 2026 Circular | In force | Market Infrastructure Institutions — stock exchanges, clearing corporations and depositories — with AMC Repo Clearing Ltd carved out by name. Half-yearly computation within 60 days of each half-year end, reported to the Standing Committee on Technology and the Governing Board. |
|
| SEBI LODR | 2 September 2015 Regulations | In force | Every listed entity, in any sector. Reg. 30(6) sets the disclosure clocks for material events; Reg. 27(2)(ba) requires cyber incidents in the quarterly corporate governance report; Reg. 21(4) requires the Risk Management Committee to cover cyber security. | In effect on issue. |
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| IRDAI Guidelines, 2026 IRDAI/ | 6 April 2026 Guidelines | In force | All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023. |
|
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| IFSCA Cyber Security Guidelines, 2025 IFSCA-CSD0MSC/ | 10 March 2025 Guidelines | In force | Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended. |
|
| IFSCA Cyber Security Guidelines Amendment, 2026 IFSCA-CSD0MSC/ | 10 March 2026 Circular | In force | All regulated entities in the IFSCs. Amends the 2025 Guidelines rather than standing alone: it substitutes the para 21 exemption list, inserts a second exemption tier at para 23 covering foreign universities, newly incorporated standalone REs and Credit Rating Agencies, and adds an annual cyber security audit report to the para 21 conditions. In effect immediately on issue. |
|
| IFSCA MII Cyber Security Guidelines, 2026 IFSCA-CSD/ | 20 April 2026 Guidelines | In force | Stock exchanges including the bullion exchange, clearing corporations and depositories in the IFSC. A prescriptive regime layered on top of the 2025 baseline Guidelines rather than replacing them, so an MII complies with both. Issued 20 April 2026 but in force from 1 April 2026. |
|
| IFSCA Frontier AI Cyber Advisory, 2026 IFSCA-CSD/ | 4 June 2026 Circular | In force | All regulated entities in the IFSCs, read alongside the 2025 Guidelines and, for an MII, the 2026 MII Guidelines — it expressly dilutes neither. Titled an advisory, but six of the eleven Annexure A items are drafted with “shall”: SBOM coverage, an API inventory with rate-limiting, frontier AI as a named board-level risk scenario, and critical-service-provider assurance among them. |
|
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| CERT-In Directions, 2022 No. 20(3)/ | 28 April 2022 Directions | In force | Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them. |
|
| Instrument | Issued | Status | Binds | Dates it sets |
|---|---|---|---|---|
| DPDP Rules, 2025 G.S.R. 846(E) | 13 November 2025 Rules | Partly in force | Data Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027. |
|
Download the dataset
The same twenty-five records, generated from the source this page renders from, so the file and the table cannot disagree. Both are free to use under CC BY 4.0 — use them, and credit bitscore.in.
- india-cyber-regulations.json — the register, one object per instrument, with deadlines nested.
- india-cyber-regulations.csv — the same rows flattened for a spreadsheet, deadlines as
kind:date:label. - schema.json — JSON Schema for a record, so you can validate against it rather than guess at the shape.
Both files are served with permissive cross-origin headers, so you can fetch them straight from a browser or a notebook without proxying them first. This register is one of two datasets published under the same terms — the other counts observed threat activity by sector. Both are listed at open data.
How this is maintained
Every entry was read from the issuing regulator’s own notification, not from secondary reporting. Where an instrument cannot be confirmed on a government source it does not go in. The verified date on each record is the day somebody last opened that source and re-read the reference, the date and the link — not the day this file was regenerated, which is a much easier thing to claim and worth nothing.
The oldest verification in the current set is 18 August 2026. Links are re-checked when the register is regenerated, and a change to any record is visible in the published dataset’s own history.
Get told when an instrument changes
Indian cyber regulation moved four times in the eighteen months to August 2026, and the changes that matter are rarely announced as changes — a categorisation threshold is revised inside a clarification circular, or a deadline moves in an extension that carves out three entity types. Leave your details and we will tell you when a record in this register moves.
Watch the register
Everything on this page stays open, including both downloads — this is not a gate. It is a note when something changes: a new instrument, a revised circular number, a deadline, or an instrument that comes into force. Nothing on a schedule.
Every instrument links to the issuing regulator’s own notification. Where a regulator serves its text through a PDF viewer or a query-string URL, the link goes to the document rather than to a landing page that may not render it.
Every instrument cited here was verified against the issuing regulator's own notification on .Questions this page answers
- What is in the India cyber regulation register?
- Twenty-five instruments binding Indian regulated entities on cyber security and data protection, issued by the RBI, SEBI, IRDAI, IFSCA, CERT-In and MeitY. Each entry carries its own reference number, issue date, status and any deadline the instrument sets — read from the issuing regulator’s own notification rather than from secondary reporting, which is where most circulating versions of these dates go wrong.
- How is the register kept current?
- Each instrument is re-read at source and carries the date it was last verified. The dataset publishes the oldest of those dates across all entries rather than the newest, so the figure describes the weakest link in the verification rather than flattering it — re-checking a handful of entries does not move the number.
- Can we use the dataset in our own systems?
- Yes. The register is published as JSON and CSV alongside a schema, openly licensed, so it can be pulled into a compliance calendar, a GRC tool or an internal wiki rather than retyped. The reference numbers are the join key worth using — they are stable, unlike instrument names, which regulators restate inconsistently across their own documents.
- How do we find out when an instrument changes?
- The register carries a watch option that notifies on material change — a new reference, a changed issue date, a change of status, a new instrument type, a moved URL or an altered deadline. Editorial changes such as a re-verification date are deliberately excluded, so a notification means the obligation moved rather than that the page was touched.