SEBI proposes extending IT framework of MIIs to arms
In this note
Practice
9 questions on this article
Check the answer for each question, or reveal all at once.
1. At a Glance
- SEBI proposed extending its IT and Cyber Security framework — currently applicable to Market Infrastructure Institutions (MIIs) — to their subsidiaries engaged in MII-related activities [1][2].
- MIIs comprise stock exchanges, depositories, and clearing corporations, entities central to India's securities market plumbing [1].
- Regulatory gap addressed: subsidiaries were not explicitly covered under existing MII IT/cyber frameworks despite performing outsourced or coordinated functions [1].
- Relevant for Prelims (SEBI institutional architecture) and Mains GS-III (economy/regulatory governance).
2. Why in the News
- On 11 September 2026, SEBI issued a consultation paper proposing to extend the IT and cybersecurity framework of MIIs to their subsidiaries, to strengthen regulatory oversight [1][2].
- Trigger: SEBI noted MIIs may increasingly use subsidiaries for certain activities, requiring close coordination with the parent MII, but jurisdictional applicability of IT/cyber rules over these subsidiaries was undefined [1].
- Public comments invited until 2 October 2026 via SEBI's online public-comments portal [2].
3. Background & Evolution
- SEBI has progressively tightened IT/cybersecurity norms for regulated entities:
- August 2023: "Guidelines for MIIs regarding Cyber security and Cyber resilience" [3].
- August 2024: Introduction of the unified Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) [4].
- December 2024 & August 2025: Clarifications/technical clarifications issued to CSCRF [5][6].
- March 2025: Extension of CSCRF adoption timelines for REs [7].
-
March 2026: Separate consultation paper on a Framework of IT Resilience Index for MIIs [8].
-
September 2026: Latest consultation paper specifically targets MII subsidiaries, closing a regulatory gap on jurisdiction over non-MII group entities [1][2].
4. Core Static Facts
| Item | Detail |
|---|---|
| Regulator | Securities and Exchange Board of India (SEBI) [1] |
| MIIs defined as | Stock exchanges, depositories, clearing corporations [1] |
| New proposal | Extend IT & cyber security framework to MII subsidiaries [1][2] |
| Applicability criteria (proposed) | Subsidiary performs MII-related activities, handles MII data, or shares IT infrastructure with the MII [2] |
| Compliance areas for subsidiaries | Cyber security, system audits, incident reporting, Business Continuity Plan–Disaster Recovery (BCP-DR), technology governance [2] |
| Exemption clause | If subsidiary meets only the infrastructure-sharing criterion, MII may seek SEBI exemption with compensatory controls disclosed [2] |
| Public comment deadline | 2 October 2026 [2] |
| Date of proposal | 11 September 2026 (Friday) [1] |
5. Multi-Dimensional Analysis
Economic
- Enhances resilience of core market infrastructure (exchanges/depositories/CCs), reducing systemic risk of cyber disruption spreading via subsidiaries [1].
- Compliance costs likely to rise for MII subsidiary units required to meet system audit/BCP-DR standards [2].
Legal/Constitutional
- Fills a regulatory jurisdiction gap — MIIs are directly SEBI-regulated, but subsidiaries previously fell outside explicit IT-framework applicability [1].
- Consultation paper route reflects SEBI's standard rule-making process (draft → public comments → circular/notification) [2].
Scientific/Technological
- Covers technology governance, cyber security, and incident reporting — aligning with SEBI's broader CSCRF push since 2024 [4][2].
- Introduces a proportionality-based exemption mechanism tied to "compensatory controls" for infrastructure-only sharing arrangements [2].
Administrative/Governance
- Establishes accountability structure: parent MII remains responsible for ensuring subsidiary compliance or securing exemption from SEBI [2].
- Reflects growing use of subsidiary structures by MIIs for auxiliary activities needing close coordination with the parent [1].
6. Recent Developments (last 12–18 months)
- August 2024: CSCRF introduced for all SEBI-regulated entities [4].
- December 2024: Clarifications to CSCRF issued [5].
- March 2025: Extension of CSCRF implementation timelines for REs [7].
- August 2025: Further technical clarifications to CSCRF [6].
- March 2026: Consultation paper on IT Resilience Index specifically for MIIs [8].
- 11 September 2026: Consultation paper proposing extension of IT/cyber framework to MII subsidiaries, comments due by 2 October 2026 [1][2].
7. Prelims Hooks
- SEBI's consultation paper on extending IT/cyber framework to MII subsidiaries was released on 11 September 2026 [1].
- MIIs = Stock Exchanges + Depositories + Clearing Corporations [1].
- The CSCRF (Cybersecurity and Cyber Resilience Framework) for SEBI-regulated entities was introduced in August 2024 [4].
- SEBI's first MII-specific cyber security guidelines were issued in August 2023 [3].
- Proposed subsidiary applicability criteria: (i) MII-related activity, (ii) handling MII data, (iii) sharing IT infrastructure [2].
- Compliance areas proposed for covered subsidiaries: cyber security, system audits, incident reporting, BCP-DR, technology governance [2].
- An exemption route exists for subsidiaries meeting only the infrastructure-sharing criterion, subject to compensatory controls [2].
- Public comment deadline on this consultation paper: 2 October 2026 [2].
- A separate SEBI Consultation Paper on "Framework of IT Resilience Index for MIIs" was floated in March 2026 [8].
- SEBI regulates MIIs directly; the applicability of these frameworks to subsidiaries was previously not explicitly defined [1].
8. Mains Relevance
- GS-III: Indian Economy — "Investment models," regulatory bodies (SEBI), securities market infrastructure, cyber security of financial systems.
- GS-II (secondary): Governance — role of regulatory bodies, statutory/quasi-judicial functions.
- Possible Mains stems: 1. "Discuss the significance of Market Infrastructure Institutions (MIIs) in India's securities market and evaluate SEBI's evolving cybersecurity regulatory approach." (GS-III) 2. "Cyber resilience of financial market infrastructure is critical to systemic stability. Examine this in light of SEBI's recent regulatory proposals." (GS-III) 3. "Regulatory jurisdiction often lags behind corporate structuring innovations. Discuss with reference to SEBI's proposal on MII subsidiaries." (GS-II/III)
9. Related Topics to Study Next
- SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 — parent framework being extended.
- Market Infrastructure Institutions (MIIs) regulatory architecture — governing regulations (SECC Regulations, Depositories Act).
- Depositories Act, 1996 — statutory basis for depositories as MIIs.
- Financial sector cyber security regulation (RBI, IRDAI parallels) — comparative regulatory approach across financial regulators.
- SEBI's consultation paper process — rule-making methodology (draft, public comments, board approval).
- Systemic risk in financial market infrastructure — broader macro-financial stability theme.
- Data localization and IT governance in financial services — related digital governance theme.
10. Common Errors / Trap Areas
- Do not confuse MIIs (stock exchanges, depositories, clearing corporations) with SEBI-Regulated Entities (REs) broadly, which include brokers, portfolio managers, etc. — CSCRF applies to REs generally, while this proposal is specific to MII subsidiaries [1][4].
- This is a consultation paper (proposal stage), not yet a notified regulation/circular — avoid stating it as already in force.
- Do not confuse this with the March 2026 IT Resilience Index consultation paper — that is a separate, related but distinct SEBI proposal [8].
- Note the regulator is SEBI, not RBI — cybersecurity of financial market infrastructure spans multiple regulators depending on entity type.
- The exemption clause applies only when a subsidiary meets solely the infrastructure-sharing criterion — not a blanket exemption [2].
Sources
- 1SEBI Proposes Extending IT, Cyber Security Framework To MII Subsidiaries — The Hindu Business Line (12 Sept 2026 e-paper)thehindu.com · tier 4
- 2SEBI Consultation Paper on Applicability of IT & Cyber Security Framework of MIIs to Their Subsidiariestaxguru.in · tier 4
- 3SEBI — Guidelines for MIIs regarding Cyber security and Cyber resilience (Aug 2023)sebi.gov.in · tier 1
- 4SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (Aug 2024)sebi.gov.in · tier 1
- 5SEBI — Clarifications to CSCRF for SEBI Regulated Entities (Dec 2024)sebi.gov.in · tier 1
- 6SEBI — Technical Clarifications to CSCRF for SEBI Regulated Entities (Aug 2025)sebi.gov.in · tier 1
- 7SEBI — Extension towards Adoption and Implementation of CSCRF for SEBI Regulated Entities (Mar 2025)sebi.gov.in · tier 1
- 8SEBI — Consultation Paper on Framework of IT Resilience Index for Market Infrastructure Institutions (MIIs) (Mar 2026)sebi.gov.in · tier 1
At the end · practice MCQs
9 questions on this article
Check the answer for each question, or reveal all at once.