·The Hindu

SEBI proposes extending IT framework of MIIs to arms

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12–18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas
Practice
9 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

1. At a Glance

  • SEBI proposed extending its IT and Cyber Security framework — currently applicable to Market Infrastructure Institutions (MIIs) — to their subsidiaries engaged in MII-related activities [1][2].
  • MIIs comprise stock exchanges, depositories, and clearing corporations, entities central to India's securities market plumbing [1].
  • Regulatory gap addressed: subsidiaries were not explicitly covered under existing MII IT/cyber frameworks despite performing outsourced or coordinated functions [1].
  • Relevant for Prelims (SEBI institutional architecture) and Mains GS-III (economy/regulatory governance).

2. Why in the News

  • On 11 September 2026, SEBI issued a consultation paper proposing to extend the IT and cybersecurity framework of MIIs to their subsidiaries, to strengthen regulatory oversight [1][2].
  • Trigger: SEBI noted MIIs may increasingly use subsidiaries for certain activities, requiring close coordination with the parent MII, but jurisdictional applicability of IT/cyber rules over these subsidiaries was undefined [1].
  • Public comments invited until 2 October 2026 via SEBI's online public-comments portal [2].

3. Background & Evolution

  • SEBI has progressively tightened IT/cybersecurity norms for regulated entities:
  • August 2023: "Guidelines for MIIs regarding Cyber security and Cyber resilience" [3].
  • August 2024: Introduction of the unified Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) [4].
  • December 2024 & August 2025: Clarifications/technical clarifications issued to CSCRF [5][6].
  • March 2025: Extension of CSCRF adoption timelines for REs [7].
  • March 2026: Separate consultation paper on a Framework of IT Resilience Index for MIIs [8].

  • September 2026: Latest consultation paper specifically targets MII subsidiaries, closing a regulatory gap on jurisdiction over non-MII group entities [1][2].

4. Core Static Facts

Item Detail
Regulator Securities and Exchange Board of India (SEBI) [1]
MIIs defined as Stock exchanges, depositories, clearing corporations [1]
New proposal Extend IT & cyber security framework to MII subsidiaries [1][2]
Applicability criteria (proposed) Subsidiary performs MII-related activities, handles MII data, or shares IT infrastructure with the MII [2]
Compliance areas for subsidiaries Cyber security, system audits, incident reporting, Business Continuity Plan–Disaster Recovery (BCP-DR), technology governance [2]
Exemption clause If subsidiary meets only the infrastructure-sharing criterion, MII may seek SEBI exemption with compensatory controls disclosed [2]
Public comment deadline 2 October 2026 [2]
Date of proposal 11 September 2026 (Friday) [1]

5. Multi-Dimensional Analysis

Economic

  • Enhances resilience of core market infrastructure (exchanges/depositories/CCs), reducing systemic risk of cyber disruption spreading via subsidiaries [1].
  • Compliance costs likely to rise for MII subsidiary units required to meet system audit/BCP-DR standards [2].

Legal/Constitutional

  • Fills a regulatory jurisdiction gap — MIIs are directly SEBI-regulated, but subsidiaries previously fell outside explicit IT-framework applicability [1].
  • Consultation paper route reflects SEBI's standard rule-making process (draft → public comments → circular/notification) [2].

Scientific/Technological

  • Covers technology governance, cyber security, and incident reporting — aligning with SEBI's broader CSCRF push since 2024 [4][2].
  • Introduces a proportionality-based exemption mechanism tied to "compensatory controls" for infrastructure-only sharing arrangements [2].

Administrative/Governance

  • Establishes accountability structure: parent MII remains responsible for ensuring subsidiary compliance or securing exemption from SEBI [2].
  • Reflects growing use of subsidiary structures by MIIs for auxiliary activities needing close coordination with the parent [1].

6. Recent Developments (last 12–18 months)

  • August 2024: CSCRF introduced for all SEBI-regulated entities [4].
  • December 2024: Clarifications to CSCRF issued [5].
  • March 2025: Extension of CSCRF implementation timelines for REs [7].
  • August 2025: Further technical clarifications to CSCRF [6].
  • March 2026: Consultation paper on IT Resilience Index specifically for MIIs [8].
  • 11 September 2026: Consultation paper proposing extension of IT/cyber framework to MII subsidiaries, comments due by 2 October 2026 [1][2].

7. Prelims Hooks

  • SEBI's consultation paper on extending IT/cyber framework to MII subsidiaries was released on 11 September 2026 [1].
  • MIIs = Stock Exchanges + Depositories + Clearing Corporations [1].
  • The CSCRF (Cybersecurity and Cyber Resilience Framework) for SEBI-regulated entities was introduced in August 2024 [4].
  • SEBI's first MII-specific cyber security guidelines were issued in August 2023 [3].
  • Proposed subsidiary applicability criteria: (i) MII-related activity, (ii) handling MII data, (iii) sharing IT infrastructure [2].
  • Compliance areas proposed for covered subsidiaries: cyber security, system audits, incident reporting, BCP-DR, technology governance [2].
  • An exemption route exists for subsidiaries meeting only the infrastructure-sharing criterion, subject to compensatory controls [2].
  • Public comment deadline on this consultation paper: 2 October 2026 [2].
  • A separate SEBI Consultation Paper on "Framework of IT Resilience Index for MIIs" was floated in March 2026 [8].
  • SEBI regulates MIIs directly; the applicability of these frameworks to subsidiaries was previously not explicitly defined [1].

8. Mains Relevance

  • GS-III: Indian Economy — "Investment models," regulatory bodies (SEBI), securities market infrastructure, cyber security of financial systems.
  • GS-II (secondary): Governance — role of regulatory bodies, statutory/quasi-judicial functions.
  • Possible Mains stems: 1. "Discuss the significance of Market Infrastructure Institutions (MIIs) in India's securities market and evaluate SEBI's evolving cybersecurity regulatory approach." (GS-III) 2. "Cyber resilience of financial market infrastructure is critical to systemic stability. Examine this in light of SEBI's recent regulatory proposals." (GS-III) 3. "Regulatory jurisdiction often lags behind corporate structuring innovations. Discuss with reference to SEBI's proposal on MII subsidiaries." (GS-II/III)

9. Related Topics to Study Next

  • SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 — parent framework being extended.
  • Market Infrastructure Institutions (MIIs) regulatory architecture — governing regulations (SECC Regulations, Depositories Act).
  • Depositories Act, 1996 — statutory basis for depositories as MIIs.
  • Financial sector cyber security regulation (RBI, IRDAI parallels) — comparative regulatory approach across financial regulators.
  • SEBI's consultation paper process — rule-making methodology (draft, public comments, board approval).
  • Systemic risk in financial market infrastructure — broader macro-financial stability theme.
  • Data localization and IT governance in financial services — related digital governance theme.

10. Common Errors / Trap Areas

  • Do not confuse MIIs (stock exchanges, depositories, clearing corporations) with SEBI-Regulated Entities (REs) broadly, which include brokers, portfolio managers, etc. — CSCRF applies to REs generally, while this proposal is specific to MII subsidiaries [1][4].
  • This is a consultation paper (proposal stage), not yet a notified regulation/circular — avoid stating it as already in force.
  • Do not confuse this with the March 2026 IT Resilience Index consultation paper — that is a separate, related but distinct SEBI proposal [8].
  • Note the regulator is SEBI, not RBI — cybersecurity of financial market infrastructure spans multiple regulators depending on entity type.
  • The exemption clause applies only when a subsidiary meets solely the infrastructure-sharing criterion — not a blanket exemption [2].

Sources

  1. 1SEBI Proposes Extending IT, Cyber Security Framework To MII Subsidiaries — The Hindu Business Line (12 Sept 2026 e-paper)thehindu.com · tier 4
  2. 2SEBI Consultation Paper on Applicability of IT & Cyber Security Framework of MIIs to Their Subsidiariestaxguru.in · tier 4
  3. 3SEBI — Guidelines for MIIs regarding Cyber security and Cyber resilience (Aug 2023)sebi.gov.in · tier 1
  4. 4SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (Aug 2024)sebi.gov.in · tier 1
  5. 5SEBI — Clarifications to CSCRF for SEBI Regulated Entities (Dec 2024)sebi.gov.in · tier 1
  6. 6SEBI — Technical Clarifications to CSCRF for SEBI Regulated Entities (Aug 2025)sebi.gov.in · tier 1
  7. 7SEBI — Extension towards Adoption and Implementation of CSCRF for SEBI Regulated Entities (Mar 2025)sebi.gov.in · tier 1
  8. 8SEBI — Consultation Paper on Framework of IT Resilience Index for Market Infrastructure Institutions (MIIs) (Mar 2026)sebi.gov.in · tier 1
At the end · practice MCQs
9 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

Also on 12 September

All 12 September articles →