Reference

The Indian cyber regulation register

Every cyber and data-protection instrument binding Indian regulated entities — reference, date, status, deadlines. Read at source; downloadable as JSON and CSV.

In short
Twenty-five instruments bind Indian regulated entities on cyber security and data protection, issued by the RBI, SEBI, IRDAI, IFSCA, CERT-In and MeitY. Each entry here carries its own reference number, issue date, status and any deadline the instrument sets, read from the issuing regulator’s notification rather than from secondary reporting.

Twenty-five instruments govern cyber security and personal data for Indian regulated entities, issued by six different authorities over four years. There is no official consolidated list of them — each regulator publishes its own, in its own format, and most secondary summaries are assembled from each other rather than from the notifications.

This is the list, kept current. Every entry carries the instrument’s own reference number, its issue date, whether it is actually in force, any deadline it sets, and the date somebody last opened the regulator’s own page to check. It is published as a page to read and as a dataset to use.

The register

InstrumentIssuedStatusBindsDates it sets
Commercial Banks
RBI/DoS/2026-27/410
31 July 2026
Directions
In forceBanking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.In effect on issue.
Small Finance Banks
RBI/DoS/2026-27/419
31 July 2026
Directions
In forceSmall Finance Banks.In effect on issue.
Payments Banks
RBI/DoS/2026-27/428
31 July 2026
Directions
In forcePayments Banks.In effect on issue.
Urban Co-operative Banks
RBI/DoS/2026-27/437
31 July 2026
Directions
In forcePrimary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949, graded into Levels I to IV by the digital services they offer.In effect on issue.
All India Financial Institutions
RBI/DoS/2026-27/456
31 July 2026
Directions
In forceEXIM Bank, NABARD, SIDBI, NHB and NaBFID.In effect on issue.
Non-Banking Financial Companies
RBI/DoS/2026-27/461
31 July 2026
Directions
In forceAll NBFCs registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987. Three obligation chapters, drafted as alternatives rather than as a ladder: Chapter III for Base Layer NBFCs below ₹500 crore of assets and for Core Investment Companies, Chapter IV for Base Layer NBFCs at ₹500 crore and above, and Chapter V for Middle Layer and above, excluding Core Investment Companies.In effect on issue.
Credit Information Companies
RBI/DoS/2026-27/470
31 July 2026
Directions
In forceCredit Information Companies as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005.In effect on issue.
RBI outsourcing Directions, 2025
RBI/DOR/2025-26/171
28 November 2025
Directions
In forceCommercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered.
  • 10 April 2026Existing IT outsourcing agreements to comply.
RBI NBFC outsourcing Directions, 2025
RBI/DOR/2025-26/363
28 November 2025
Directions
In forceNBFCs across the scale-based layers, together with HFCs, CICs, standalone primary dealers and the account aggregator and P2P categories. Existing IT outsourcing agreements to comply by 10 April 2026.
  • 10 April 2026Existing IT outsourcing agreements to comply.
Reserve Bank of India — 9 instruments
InstrumentIssuedStatusBindsDates it sets
SEBI CSCRF
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
20 August 2024
Framework
In forceSEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.
  • 31 August 2025Compliance deadline as twice extended, for every RE except MIIs, KRAs and QRTAs.
CSCRF clarifications, December 2024
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184
31 December 2024
Circular
In forceAnswered the first round of queries from regulated entities.In effect on issue.
First extension, March 2025
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45
28 March 2025
Circular
In forceExtended compliance timelines by three months, to 30 June 2025, for all REs except MIIs, KRAs and QRTAs.
  • 30 June 2025Extended compliance deadline for every RE except MIIs, KRAs and QRTAs.
CSCRF clarifications, April 2025
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60
30 April 2025
Circular
In forceRevised the categorisation criteria and thresholds, including for Depository Participants.In effect on issue.
Second extension, June 2025
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96
30 June 2025
Circular
In forceExtended compliance timelines by a further two months, to 31 August 2025, for all REs except MIIs, KRAs and QRTAs.
  • 31 August 2025Compliance deadline extended a second time, again excluding MIIs, KRAs and QRTAs.
Technical clarifications, August 2025
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119
28 August 2025
Circular
In forceTechnical readings of the standards, issued as the principal deadline passed.In effect on issue.
SEBI incident portal — FIRE format
HO/(449)2026-ITD-5_DIV1/I/19448/2026
24 August 2026
Circular
In forceEvery SEBI regulated entity already reporting under CSCRF. Filing moves to the Financial Stability Board’s Format for Incident Reporting Exchange, staged across initial report, intermediate updates and final closure, at https://siportal.sebi.gov.in. The six-hour and twenty-four hour clocks are unchanged.In effect on issue.
SEBI IT Resilience Index
HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026
24 August 2026
Circular
In forceMarket Infrastructure Institutions — stock exchanges, clearing corporations and depositories — with AMC Repo Clearing Ltd carved out by name. Half-yearly computation within 60 days of each half-year end, reported to the Standing Committee on Technology and the Governing Board.
  • 30 November 2026Industry Standards Forum finalises sub-parameters and measurement criteria.
  • 31 January 2027Standard Operating Procedures submitted to SEBI after SCOT review.
  • 28 February 2027ITRI framework operationalised, including the Early Warning System and real-time monitoring of service delivery.
  • 31 March 2027First ITRI computation submitted, for the half-year ending on this date.
SEBI LODR2 September 2015
Regulations
In forceEvery listed entity, in any sector. Reg. 30(6) sets the disclosure clocks for material events; Reg. 27(2)(ba) requires cyber incidents in the quarterly corporate governance report; Reg. 21(4) requires the Risk Management Committee to cover cyber security.In effect on issue.
Securities and Exchange Board of India — 9 instruments
InstrumentIssuedStatusBindsDates it sets
IRDAI Guidelines, 2026
IRDAI/GA&HR/CIR/MISC/51/4/2026
6 April 2026
Guidelines
In forceAll insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
  • 1 April 2026Compliance required “from the current financial year”, which opened five days before the circular was issued.
Insurance Regulatory and Development Authority of India — 1 instrument
InstrumentIssuedStatusBindsDates it sets
IFSCA Cyber Security Guidelines, 2025
IFSCA-CSD0MSC/13/2025-DCS
10 March 2025
Guidelines
In forceAny entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended.
  • 1 April 2025In force.
  • 10 March 2028The para 21 and para 23 exemptions lapse unless extended.
IFSCA Cyber Security Guidelines Amendment, 2026
IFSCA-CSD0MSC/1/2026-DCS
10 March 2026
Circular
In forceAll regulated entities in the IFSCs. Amends the 2025 Guidelines rather than standing alone: it substitutes the para 21 exemption list, inserts a second exemption tier at para 23 covering foreign universities, newly incorporated standalone REs and Credit Rating Agencies, and adds an annual cyber security audit report to the para 21 conditions. In effect immediately on issue.
  • 10 March 2026In effect immediately on issue.
IFSCA MII Cyber Security Guidelines, 2026
IFSCA-CSD/MSC/2/2026-DCS
20 April 2026
Guidelines
In forceStock exchanges including the bullion exchange, clearing corporations and depositories in the IFSC. A prescriptive regime layered on top of the 2025 baseline Guidelines rather than replacing them, so an MII complies with both. Issued 20 April 2026 but in force from 1 April 2026.
  • 1 April 2026In force — twenty days before the Guidelines were issued.
  • 20 April 2028ISO 27001 certification, measured two years from issuance.
IFSCA Frontier AI Cyber Advisory, 2026
IFSCA-CSD/MSC/3/2026-DCS
4 June 2026
Circular
In forceAll regulated entities in the IFSCs, read alongside the 2025 Guidelines and, for an MII, the 2026 MII Guidelines — it expressly dilutes neither. Titled an advisory, but six of the eleven Annexure A items are drafted with “shall”: SBOM coverage, an API inventory with rate-limiting, frontier AI as a named board-level risk scenario, and critical-service-provider assurance among them.
  • 4 June 2026In force with immediate effect.
International Financial Services Centres Authority — 4 instruments
InstrumentIssuedStatusBindsDates it sets
CERT-In Directions, 2022
No. 20(3)/2022-CERT-In
28 April 2022
Directions
In forceService providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them.
  • 27 June 2022In force, sixty days after issue.
Indian Computer Emergency Response Team — 1 instrument
InstrumentIssuedStatusBindsDates it sets
DPDP Rules, 2025
G.S.R. 846(E)
13 November 2025
Rules
Partly in forceData Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027.
  • 13 May 2027Full compliance with the Rules.
Ministry of Electronics and Information Technology — 1 instrument

Download the dataset

The same twenty-five records, generated from the source this page renders from, so the file and the table cannot disagree. Both are free to use under CC BY 4.0 — use them, and credit bitscore.in.

Both files are served with permissive cross-origin headers, so you can fetch them straight from a browser or a notebook without proxying them first. This register is one of two datasets published under the same terms — the other counts observed threat activity by sector. Both are listed at open data.

How this is maintained

Every entry was read from the issuing regulator’s own notification, not from secondary reporting. Where an instrument cannot be confirmed on a government source it does not go in. The verified date on each record is the day somebody last opened that source and re-read the reference, the date and the link — not the day this file was regenerated, which is a much easier thing to claim and worth nothing.

The oldest verification in the current set is 18 August 2026. Links are re-checked when the register is regenerated, and a change to any record is visible in the published dataset’s own history.

Get told when an instrument changes

Indian cyber regulation moved four times in the eighteen months to August 2026, and the changes that matter are rarely announced as changes — a categorisation threshold is revised inside a clarification circular, or a deadline moves in an extension that carves out three entity types. Leave your details and we will tell you when a record in this register moves.

Watch the register

Everything on this page stays open, including both downloads — this is not a gate. It is a note when something changes: a new instrument, a revised circular number, a deadline, or an instrument that comes into force. Nothing on a schedule.

Every instrument links to the issuing regulator’s own notification. Where a regulator serves its text through a PDF viewer or a query-string URL, the link goes to the document rather than to a landing page that may not render it.

Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

What is in the India cyber regulation register?
Twenty-five instruments binding Indian regulated entities on cyber security and data protection, issued by the RBI, SEBI, IRDAI, IFSCA, CERT-In and MeitY. Each entry carries its own reference number, issue date, status and any deadline the instrument sets — read from the issuing regulator’s own notification rather than from secondary reporting, which is where most circulating versions of these dates go wrong.
How is the register kept current?
Each instrument is re-read at source and carries the date it was last verified. The dataset publishes the oldest of those dates across all entries rather than the newest, so the figure describes the weakest link in the verification rather than flattering it — re-checking a handful of entries does not move the number.
Can we use the dataset in our own systems?
Yes. The register is published as JSON and CSV alongside a schema, openly licensed, so it can be pulled into a compliance calendar, a GRC tool or an internal wiki rather than retyped. The reference numbers are the join key worth using — they are stable, unlike instrument names, which regulators restate inconsistently across their own documents.
How do we find out when an instrument changes?
The register carries a watch option that notifies on material change — a new reference, a changed issue date, a change of status, a new instrument type, a moved URL or an altered deadline. Editorial changes such as a re-verification date are deliberately excluded, so a notification means the obligation moved rather than that the page was touched.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Work out which instruments bind you