Regulation

SEBI’s IT Resilience Index has to compute itself

SEBI’s IT Resilience Index binds MIIs alone: nine weighted parameters, a half-yearly score that may not be produced by hand, and four dates to March 2027.

In short
SEBI’s IT Resilience Index of 24 August 2026 binds Market Infrastructure Institutions alone — stock exchanges, clearing corporations and depositories, with AMC Repo Clearing Ltd carved out by name. It scores nine weighted parameters totalling 100, computed half-yearly for the Standing Committee on Technology and the Governing Board. The computation must be system-driven, with manual retrieval only by exception agreed with that committee in advance.

Who it binds, and who it does not

The IT Resilience Index binds Market Infrastructure Institutions and nobody else. Stock exchanges, clearing corporations and depositories owe it; brokers, portfolio managers, merchant bankers, AIFs and every other SEBI regulated entity owe nothing under it. That is worth settling first, because SEBI issued a second cyber circular on the same day — HO/(449)2026-ITD-5_DIV1/I/19448/2026, realigning the incident reporting portal — and that one reaches every entity already reporting under CSCRF. Same date, same subject area, entirely different populations.

The addressee list carries one carve-out, stated by name: AMC Repo Clearing Ltd. An exclusion written into the addressees rather than into the operative text is easy to lose when the circular is summarised, and it is the kind of detail worth reading off the notification rather than off a summary of it.

The nine parameters

The index scores the robustness of an institution’s critical systems — a term the circular does not redefine, pointing instead at the clauses of three existing master circulars that already do. Its scope reaches beyond those systems to the other systems feeding into or related to them, which is a wider boundary than it first appears.

ParameterWeightage
Availability20
Security20
Integrity10
Governance10
Reliability and Monitoring10
Business Continuity10
Modularity and Flexibility10
Scalability5
Others, such as incident handling5
The nine parameters of the IT Resilience Index and their stated weightages, which total 100.

Availability and Security carry forty of the hundred between them. Everything beneath that is unwritten: the circular sets the nine parameters and their weightages and stops there, directing the Industry Standards Forum of MIIs to finalise the sub-parameters and the detailed measurement criteria. The ISF also formulates the baseline parameters, the acceptable threshold scores and the scoring methodology, so that the results are comparable across institutions. Until that work lands, an MII knows what it will be scored on and not how.

The index has to compute itself

This is the requirement that makes the circular an engineering problem rather than a reporting one. The computation must be system-driven — produced automatically from IT systems, or from data extracted from them, without manual intervention. SEBI states the purpose in the same breath: so that the computation remains non-discretionary and, in the circular’s own word, fool proof.

The exception is narrow and supervised. Where a parameter genuinely cannot be computed automatically, the institution may retrieve the data by hand — but only after discussing that exception with its Standing Committee on Technology in advance. A manual figure produced first and explained afterwards does not meet the wording.

Read against the reporting line, the intent is clear enough. The index goes half-yearly to the SCOT and the Governing Board, as a comparative analysis of two consecutive half-years on a rolling basis, together with the corrective actions taken or proposed. A score a board is asked to act on is a score somebody could otherwise be tempted to smooth, and a computation nobody’s hands touch is much harder to smooth.

Early warning, and watching service delivery

Two further obligations sit beside the index and are easy to skip past, because neither is expressed as a score.

  • An Early Warning System. The MII must build one that detects possible deterioration in any ITRI parameter before it becomes a visible performance issue, along with the framework to remedy what it detects. The index measures the half-year; this is what is meant to catch the problem inside it.
  • Continuous visibility into service delivery. MIIs already monitor process and application performance and resource utilisation at each IT component level, under the capacity-planning circular of 10 December 2024. This adds systems that give continuous visibility into the service actually delivered to market participants, including consolidated dashboards.

Taken together, the three requirements describe a loop rather than a filing: measure the half-year, detect deterioration inside it, and show the board what was done about it.

The four dates

MIIs have already implemented a beta version of the framework, which the circular records rather than requires. What follows is dated.

DateWhat is due
30 November 2026The Industry Standards Forum finalises the sub-parameters and detailed measurement criteria for each of the nine parameters.
31 January 2027Detailed Standard Operating Procedures, reviewed by the institution’s SCOT, are submitted to SEBI.
28 February 2027The framework is operationalised, including the Early Warning System and real-time monitoring of service delivery.
31 March 2027The half-year for which the first ITRI computation under this framework is submitted.
The implementation timeline stated in the circular of 24 August 2026.

The ordering is the awkward part. Sub-parameters are due at the end of November, the SOPs that depend on them two months later, and the working system a month after that. An institution waiting for the ISF before it starts building has roughly three months to build once it can. The two obligations that do not depend on the ISF — the Early Warning System and the service-delivery monitoring — are the ones available to start on now.

Why this is not the CCI

Both are weighted parameters totalling 100, computed periodically by a SEBI regulated entity, and that is the whole of the resemblance. Confusing them is expensive in both directions: an MII that treats its CCI submission as covering this owes a framework it has not built, and a non-MII that reads coverage of the index as applying to it builds one it does not owe.

Cyber Capability IndexIT Resilience Index
InstrumentCSCRF, Annexure-KCircular of 24 August 2026
Who computes itCategorised regulated entities, by categoryMIIs alone
What it measuresCyber security maturity, across 23 weighted sub-goalsResilience of critical IT systems, across 9 weighted parameters
How it is producedAssessed, with a mandatory independent elementSystem-driven, manual retrieval only by supervised exception
The two SEBI indices an MII computes, and what separates them.

An MII computes both, against different criteria, on different cycles, for different readers. The CSCRF obligations are unchanged by this circular, and so is the incident-reporting clock — the FIRE alignment of the same month, HO/(449)2026-ITD-5_DIV1/I/19448/2026, changed the format and the staging of an incident report and moved none of its deadlines.

Parameters, weightages, obligations and every date on this page are from IT Resilience Index for Market Infrastructure Institutions (MIIs), HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026, issued 24 August 2026, read from the circular PDF on sebi.gov.in. It follows the consultation paper of 25 March 2026. The sub-parameters and measurement criteria beneath the nine parameters are not settled at the time of writing and are due from the Industry Standards Forum by 30 November 2026 — nothing here should be read as anticipating them. This page is commentary on a published circular, not legal advice, and the circular should be read in full before anyone relies on a characterisation of it, including this one. External measurement referenced here is a Bitsight capability; BitScore Cybertech LLP is an authorised Bitsight partner.

Questions this page answers

Who does SEBI’s IT Resilience Index apply to?
Market Infrastructure Institutions only — stock exchanges, clearing corporations and depositories. The circular of 24 August 2026 carves AMC Repo Clearing Ltd out of its addressee list by name. It does not bind brokers, portfolio managers, merchant bankers or any other SEBI regulated entity, which distinguishes it from CSCRF, and an entity that is not an MII owes nothing under it.
What are the parameters of the IT Resilience Index?
Nine, with weightages stated in the circular that total 100: Availability 20, Security 20, Integrity 10, Governance 10, Reliability and Monitoring 10, Business Continuity 10, Modularity and Flexibility 10, Scalability 5, and a residual 5 for other matters such as incident handling. The sub-parameters and detailed measurement criteria beneath each of the nine are not in the circular — SEBI has directed the Industry Standards Forum of MIIs to finalise them by 30 November 2026.
Can the IT Resilience Index be calculated manually?
No, other than by exception. The circular requires the computation to be system-driven — produced automatically from IT systems, or from data extracted from them, without manual intervention — and states the purpose plainly: so that the computation remains non-discretionary and fool proof. Where a parameter genuinely cannot be computed automatically, the institution may retrieve the data manually only after discussing that exception with its Standing Committee on Technology in advance.
When does the IT Resilience Index have to be in place?
Four dates. The Industry Standards Forum finalises sub-parameters and measurement criteria by 30 November 2026. Standard Operating Procedures go to SEBI, after review by the institution’s Standing Committee on Technology, by 31 January 2027. The framework itself — including the Early Warning System and real-time monitoring of service delivery — is operationalised by 28 February 2027. The first computation submitted under the framework is for the half-year ending 31 March 2027.
Is the IT Resilience Index the same as the CSCRF Cyber Capability Index?
No. They share a shape — weighted parameters totalling 100 — and nothing else. The Cyber Capability Index is a cyber security maturity score computed under Annexure-K of CSCRF against 23 weighted sub-goals, and every categorised regulated entity above a threshold computes it. The IT Resilience Index measures the resilience of critical IT systems against nine different parameters, binds Market Infrastructure Institutions alone, and reports half-yearly to a different audience. An MII computes both.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Work out your Cyber Capability Index