India's Cyber Compliance Stack 2026: RBI, SEBI, IRDAI, CERT-In Obligations Mapped

Deep Dive Cybersecurity 15 May 2026
TL;DR

India's cybersecurity compliance framework in 2026 is a four-regulator stack: CERT-In (horizontal — 6-hour incident clock, log retention, SBOM), RBI (banks and payment systems — IT Governance MD 2023, Digital Payment Security Controls MD 2021, Cyber Security Framework 2016), SEBI (CSCRF, Aug 2024 — graded SRE/MII/QSB thresholds, 31 Dec 2024 + 28 Aug 2025 phase-in), and IRDAI (ICSG 2023 — 24 security-domain policies, dual 6h CERT-In + 24h IRDAI clock). Every regulated entity sits in at least two of these layers; banks and insurers that also operate as SEBI intermediaries face all four simultaneously.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
21 min read
Continue with Veritect

Read the regulator's position, alongside the litigation that tested it.

Try Veritect free Book a demo

India's cybersecurity regulatory landscape in 2026 is governed by four overlapping mandatory frameworks: the horizontal CERT-In Directions under Section 70B(6) of the Information Technology Act, 2000, and three sector-specific layers from RBI (banks and payment operators), SEBI (capital markets intermediaries), and IRDAI (insurance entities). Every regulated financial and technology entity sits inside at least two of these frameworks simultaneously. Understanding how the four stacks interact — and where their obligations conflict or compound — is the central compliance challenge of 2026.


TL;DR for founders

If your company operates a fintech, insurtech, or regulated financial platform in India, you are inside multiple mandatory cybersecurity frameworks at once. CERT-In's 6-hour incident clock applies to everyone. If you hold an RBI licence, the IT Governance Master Direction 2023 applies. If you are SEBI-registered, the CSCRF (phase-in complete as of August 2025) applies. If you hold an IRDAI licence, the Information and Cyber Security Guidelines 2023 apply. These are NOT alternatives — you comply with all that attach to your regulatory licences. The practical output is three parallel incident-reporting clocks (CERT-In 6h, SEBI 6h–48h, IRDAI 24h) running simultaneously for the same incident, separate VAPT cadences, distinct Board-reporting templates, and independent third-party audit requirements.


Layer 1 — CERT-In: The Horizontal Baseline

The CERT-In Directions issued under Section 70B(6) of the Information Technology Act, 2000 on 28 April 2022 established India's first binding horizontal cyber-incident mandate. The Directions apply to "service providers, intermediaries, data centres, body corporate, and government organisations" — language broad enough to capture every incorporated company operating digital infrastructure or processing user data in India.

Six core obligations under the Directions:

1. 6-hour incident reporting. Direction (ii) requires reporting any of 20 specified incident categories to CERT-In within 6 hours of noticing the incident. The clock starts on awareness, not confirmed attribution. The 20 categories span targeted scanning, compromise of critical systems, malware deployment, ransomware, data breach, DDoS, website defacement, DNS hijack, supply-chain attack, and rogue mobile application, among others. Reporting is via the CERT-In portal or email; the initial report may be preliminary with a 30-day follow-up for root-cause analysis.

2. Log retention for 180 days. All ICT systems must retain logs — including application, network device, system, and access logs — for a minimum of 180 rolling days within Indian jurisdiction. CERT-In can extend this to 365 days by specific direction in an active incident investigation. Cloud logs stored by AWS, Azure, or GCP in Indian regions qualify; logs held exclusively offshore do not.

3. NTP time synchronisation. ICT systems must synchronise clocks to the National Informatics Centre (NIC) or NPTEL NTP servers, or to traceable NTP servers. This is an evidentiary requirement: without consistent time-stamps, incident timelines are unreliable for both internal forensics and CERT-In reporting.

4. Virtual Asset Service Provider (VASP) and VPN registration. Data centres, VPN service providers, and VASPs must register with CERT-In and maintain subscriber records (name, IP addresses, KYC, purpose of hire) for 5 years.

5. CERT-In empanelment for government audits. Government bodies and critical sector entities are expected to use CERT-In empanelled auditors for cybersecurity audits. The empanelment list is published at cert-in.org.in.

6. Penalty ceiling under Section 70B(7). The Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023), effective 30 November 2023, substituted the penalty ceiling under Section 70B(7) from ₹1 lakh to rupees one crore. This is a civil penalty; CERT-In has not publicly issued any adjudication orders as of May 2026, but the ceiling increase substantially changes the risk calculus for compliance officers.


Practitioner note — CERT-In SBOM and AIBOM obligations: CERT-In's Guidelines for SBOM (Software Bill of Materials) and AIBOM (AI Bill of Materials) of October 2024 extend the foundational Directions into supply-chain transparency. Entities subject to CERT-In that are also government technology vendors must maintain component inventories. The SEBI CSCRF (Layer 3) requires MIIs to conduct third-party vendor risk assessments — CERT-In SBOM obligations and SEBI vendor risk requirements reinforce each other. See Veritect's companion explainer on CERT-In SBOM/AIBOM guidelines.


Layer 2 — RBI: Banks and Payment Operators

The RBI cybersecurity stack for banks has evolved through three instruments, each superseding or layering on the last.

RBI Cyber Security Framework 2016 (DBS.CO/CSITE/BC.11/33.01.001/2015-16, dated 2 June 2016) was the first structured mandate for scheduled commercial banks. It introduced the concept of a cyber-crisis management plan, information security governance at Board level, 24×7 SOC capabilities, and real-time threat-intelligence sharing. The 2016 Framework has been materially superseded by the 2023 MD (below) but the legal obligation to maintain the 2016 Framework's controls remained in force until entities mapped to the 2023 MD.

RBI Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21, dated 18 February 2021, effective 18 August 2021) covers scheduled commercial banks (excluding RRBs), SFBs, Payment Banks, and credit card issuers. Key controls:

  • Board-level digital payment security policy (Para 4): a documented policy signed off at Board level, not merely IT-department level.
  • Half-yearly Vulnerability Assessment + Annual Penetration Test (Para 24): VA must cover all payment infrastructure; PT must include external and internal attack surfaces.
  • Source-code escrow (Para 23): core banking and payment application source code must be held in escrow accessible to RBI in the event of vendor insolvency.
  • Multi-factor authentication with dynamic factor (Para 33): static passwords are not compliant for payment authorisation; the second factor must be non-replicable (OTP, biometric, hardware token).
  • Customer protection framework (Paras 42–50): zero-liability for customers reporting fraud within specified windows; 24-hour reversal timelines for disputed transactions — cross-referenced with RBI Limited Liability Circular of 6 July 2017.

RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/99, dated 7 November 2023) is the current definitive IT governance framework for scheduled commercial banks and select NBFCs. It supersedes and expands on the 2016 Framework. Principal obligations:

  • IT Strategy Committee at Board level with at least one independent director having IT expertise; meets at least quarterly.
  • Chief Information Security Officer (CISO) with direct reporting line to the Board Risk Management Committee, not the CIO or CTO. CISO cannot hold a dual role in IT operations.
  • IT Risk Assessment tied to the overall risk appetite framework, reviewed annually and updated upon material system change.
  • Vendor risk management: third-party IT service providers must be assessed against security standards; contracts must include CERT-In reporting flow-down clauses.
  • Para 7.9 — Board-level cyber incident reporting: the Board must receive a cyber incident report within 24 hours of a material incident. RBI's prescribed timeline for external reporting to RBI is in the companion CERT-In-aligned format.

The 2023 MD and the 2021 Digital Payment Security MD run in parallel for covered entities — they are not alternatives. Large banks comply with both simultaneously.


Layer 3 — SEBI: Capital Markets Cybersecurity

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), released on 20 August 2024 via circular SEBI/HO/ITD/ITD_VAPT/P/CIR/2024/113, established a risk-tiered cyber mandate for capital market entities. The framework introduced three tiers:

Market Infrastructure Institutions (MIIs) — stock exchanges (NSE, BSE), clearing corporations (CCIL, NSE Clearing), and depositories (NSDL, CDSL). MIIs face the most stringent controls: mandatory 24×7 Security Operations Centre (SOC), real-time event correlation (SIEM), quarterly penetration testing, dedicated CISO, and 6-hour incident reporting to SEBI.

Qualified Stock Brokers (QSBs) — brokers above SEBI-notified trading-volume and client-count thresholds. QSBs must maintain a documented cybersecurity policy, designated CISO, annual VAPT, and 24-hour incident reporting to SEBI. The SEBI FAQ of 11 June 2025 (para 3.4) confirmed that QSB classification is reviewed annually; a broker crossing the threshold mid-year has 3 months to implement QSB-level controls.

All other SEBI-registered entities — asset management companies, portfolio managers, investment advisors, registrars and transfer agents, credit rating agencies. These face a baseline framework: annual self-assessment against the CSCRF checklist, documented incident response plan, 48-hour incident reporting to SEBI, and Board-level cybersecurity review at least annually.

Phase-in timeline (fully complete as of May 2026):

  • 31 December 2024: MIIs + large intermediaries (Phase 1)
  • 30 April 2025: Mid-tier intermediaries (Phase 2)
  • 28 August 2025: All remaining entities above thresholds (Phase 3 — Final)

A regulated entity covered by both RBI's IT Governance MD 2023 and SEBI's CSCRF (e.g., a bank running a broking subsidiary) must maintain compliance with both simultaneously. The frameworks share common vocabulary (VAPT, SOC, CISO) but differ in reporting timelines, audit frequency, and Board-reporting format.


Veritect's private legal-research corpus covers the full text of the CERT-In Directions, RBI IT Governance MD 2023, RBI Digital Payment Security Controls MD, SEBI CSCRF and all three clarification circulars, IRDAI ICSG 2023 with all 24 policy domains, and NCIIPC Guidelines V2. Queries like "what is the CERT-In Direction on encrypted traffic inspection?" or "does the SEBI CSCRF SOC obligation extend to third-party SOC vendors?" return paragraph-cited answers from primary regulator documents. Explore Veritect Legal AI


Layer 4 — IRDAI: Insurance Cyber Compliance

The IRDAI Information and Cyber Security Guidelines 2023 (IRDAI/GA&HR/GDL/MISC/82/4/2023), dated 24 April 2023, established a 24-security-domain governance framework for the insurance sector. The Guidelines apply to:

  • Life, general, standalone health insurers, and reinsurers
  • Insurance brokers, corporate agents, web aggregators, insurance marketing firms (IMFs), and direct brokers
  • Third-party administrators (TPAs), repositories, and surveyors/loss assessors

Governance architecture under IRDAI ICSG 2023:

The ICSG requires a three-tier governance structure: Board (cybersecurity policy sign-off annually), Risk Management Committee (RMC) with at least 2 independent directors as members, and an Information Security Risk Management Committee (ISRMC) with a full-time CISO who reports to the Board RMC — and specifically not to the CIO or CTO. This separation mirrors the RBI requirement but is independently specified by IRDAI.

24 Security Domain Policies (Policies 2.1–2.24): These span network security, endpoint protection, identity and access management, application security, cloud security, third-party risk, data classification and handling, business continuity, physical security, and incident management. Each policy domain has minimum-standard clauses. IRDAI mandates an ISO/IEC 27001 certification for the entity's information security management system.

Dual incident reporting clock (Policy 2.10, Clause 3.5):

  • 6 hours to CERT-In (consistent with CERT-In Direction (ii))
  • 24 hours to the IRDAI Chairperson directly (by email to the designated address)

An insurer who also holds a corporate agency or web-aggregator registration faces this dual clock for any cybersecurity incident affecting its digital distribution channels.

Audit and assurance requirements:

  • Annual information and cyber security audit by a CERT-In empanelled auditor
  • Audit report submitted to IRDAI via Annexures III, V, and VI within the prescribed timeline
  • Annual VAPT (Vulnerability Assessment and Penetration Testing) by a CERT-In empanelled vendor; findings to be remediated within 30 days (critical) and 90 days (high)

Penalties: Section 102 of the Insurance Act, 1938 provides for penalties up to ₹1 crore per violation for non-compliance with IRDAI directions. Combined with the CERT-In Section 70B(7) ceiling of ₹1 crore, an insurer that fails to report an incident faces parallel penalty exposure from two regulators for the same event.


Cross-Regulator Interaction Matrix

The four layers create compounding obligations. The table below maps the six most common interaction scenarios:

Entity type CERT-In RBI SEBI IRDAI Key conflict points
Scheduled commercial bank Yes Yes (IT Governance MD 2023 + DPSC MD 2021) If holds broker/AMC licence No (unless insurance subsidiary) Parallel VAPT requirements (RBI annual, no SEBI requirement unless broker); separate Board reporting formats
Payment bank / small finance bank Yes Yes (DPSC MD 2021 applies to PBs; IT Governance MD 2023 applies to SFBs) No No CERT-In 6h runs parallel to RBI 24h Board report
SEBI-registered MII (exchange/depository) Yes No (unless also banking licence) Yes — SOC, quarterly PT, 6h SEBI reporting No CERT-In 6h and SEBI 6h run simultaneously for the same incident; separate portals and formats
SEBI-registered broker (QSB) Yes No Yes — annual VAPT, designated CISO, 24h SEBI reporting No CERT-In 6h runs faster than SEBI 24h; initial report to CERT-In, follow-on to SEBI
Life/general insurer Yes No (unless RBI-licensed co.) No (unless SEBI-registered subsidiary) Yes — ISRMC, 24h IRDAI, ISO 27001 Dual CERT-In 6h + IRDAI 24h clock for every incident; single incident response template must address both formats
Fintech with SEBI + RBI licences Yes Yes Yes No Triple compliance: CERT-In + RBI IT Governance MD + SEBI CSCRF. VAPT: annual (RBI), quarterly if MII-tier (SEBI). CISO must satisfy both regulator governance specs

NCIIPC — The Fifth Overlay for Critical Infrastructure

Beyond the four primary layers, entities designated as Critical Information Infrastructure (CII) by the National Critical Information Infrastructure Protection Centre (NCIIPC) under Section 70A of the IT Act, 2000 face an additional incident-reporting obligation directly to NCIIPC. NCIIPC's Guidelines Version 2 (published at nciipc.gov.in) establish:

  • Separate incident reporting to NCIIPC (distinct from CERT-In portal)
  • Mandatory participation in NCIIPC's vulnerability disclosure and advisory ecosystem
  • Sector-specific threat intelligence sharing through NCIIPC's Information Sharing and Analysis Centres (ISACs)

Most large scheduled commercial banks, stock exchanges, and payment clearing infrastructure would qualify as potential CII. The NCIIPC designation threshold assessment is initiated by NCIIPC itself or by application from the entity's sector regulator (RBI, SEBI, IRDAI can recommend); there is no self-designation mechanism. CII designation is not publicly disclosed.


Practical Compliance Architecture: What to Build in 2026

For a fintech or regulated entity managing all four framework layers, the following architecture minimises duplication:

Single unified cybersecurity policy: drafted to satisfy the highest-common-denominator requirement across CERT-In, RBI, SEBI, and IRDAI. The RBI IT Governance MD 2023 para 4.1 Board-approved policy template is the strongest baseline; augment with SEBI CSCRF Section 3 and IRDAI ICSG 2023 Policy 2.1 requirements.

Unified incident response plan with regulator-specific notification annexures: a single IRP that triggers the master process, then routes to notification sub-processes for each regulator (CERT-In portal — 6h, SEBI portal — 6h/24h/48h by entity tier, IRDAI email — 24h, RBI format — para 7.9 Board report — 24h). Timelines indexed to the fastest clock.

One VAPT programme, multiple report derivations: annual baseline VAPT satisfies RBI. Quarterly PT required by SEBI MII obligation; QSB entities can run annual and submit for SEBI. The VAPT vendor must be CERT-In empanelled (required by IRDAI; recommended by SEBI).

Single CISO governance structure with dual reporting lines: RBI requires CISO to report to Board RMC; IRDAI requires the same. A single CISO role with a clearly documented reporting line to the Board RMC satisfies both; the SEBI CSCRF does not specify the CISO reporting chain for non-MII entities.

Unified third-party risk register: CERT-In SBOM obligations, SEBI vendor risk requirements, RBI outsourcing directions (Master Directions on Outsourcing, 2023), and IRDAI's third-party risk domain (ICSG Policy 2.19) all require vendor inventory and risk assessment. A single registry with regulator-specific metadata fields reduces duplication.


The analysis above covers approximately 30% of the documented material across these four frameworks. Veritect Legal AI's private research corpus contains the full text of the CERT-In Directions, RBI IT Governance MD 2023 with all Board-level templates, SEBI CSCRF with June 2025 FAQs, IRDAI ICSG 2023 with all 24 policy domain clauses, NCIIPC Guidelines V2, and the Jan Vishwas amendment chain — with paragraph-level citations and an automated cross-regulator conflict mapper. Practitioners can query "does para 7.9 of RBI IT Governance MD supersede the CERT-In log-retention requirement?" and receive a cited, synthesised answer. Access Veritect Legal AI


FAQ

Q1: Does every regulated entity in India need to comply with CERT-In, RBI, SEBI, and IRDAI cyber rules simultaneously? Not all four at once. CERT-In applies horizontally to all entities. RBI, SEBI, and IRDAI each apply to entities within their respective licensing perimeter. A fintech with an RBI payment aggregator licence and a SEBI broker licence faces CERT-In + RBI + SEBI — all three. An insurer without any capital markets licence faces CERT-In + IRDAI. A technology company that is neither a licensed financial entity nor a payment operator faces CERT-In only. The key question is: how many regulatory licences does your entity hold?

Q2: What is the key difference between the CERT-In 6-hour clock and the RBI/SEBI/IRDAI incident reporting obligations? CERT-In starts the clock from "noticing" the incident — awareness triggers the obligation, not confirmed attribution. RBI's 24-hour Board-level reporting and SEBI's 6-hour / 24-hour / 48-hour (by entity tier) SEBI-portal reporting run in parallel, not instead of, CERT-In. For an insurer, the CERT-In 6-hour clock and the IRDAI 24-hour Chairperson-email clock run simultaneously from the same incident trigger. All three notifications for the same incident must be independently filed to separate portals and recipients in different formats.

Q3: When does the SEBI CSCRF phase-in complete? Phase 3 (28 August 2025) was the final phase. As of May 2026, the SEBI CSCRF is fully in force for all entities above applicable thresholds. SEBI FAQs (11 June 2025) confirmed that no further phase-in dates remain.

Q4: What are the Section 70B penalties for non-compliance with CERT-In Directions? Up to ₹1 crore per violation under Section 70B(7) as amended by the Jan Vishwas Act, 2023 (effective 30 November 2023). This is a civil penalty; criminal exposure may arise separately if the non-compliance enables or constitutes a cybercrime.

Q5: Does the SEBI CSCRF apply to fund managers and investment advisors in India? Yes, at the baseline tier. All SEBI-registered entities (including AMCs, PMS managers, investment advisors, and RTA entities) above applicable thresholds face the CSCRF baseline framework: annual self-assessment, documented IRP, 48-hour incident reporting to SEBI, and annual Board review. The SOC and quarterly PT obligations apply only to MIIs.

Q6: How does NCIIPC CII designation interact with the four-layer stack? CII designation adds a fifth overlay: separate incident reporting to NCIIPC (distinct from CERT-In portal), participation in NCIIPC ISACs, and NCIIPC advisory compliance. Most large banks, exchanges, and payment clearing infrastructure would qualify. CII designation is initiated by NCIIPC, not self-declared.

Q7: What is the best starting point for building a multi-regulator cyber compliance architecture? Begin with the CERT-In Directions as the horizontal baseline and build the log-retention, time-synchronisation, and incident-reporting infrastructure first. Then layer RBI IT Governance MD 2023 governance architecture (CISO, Board IT Strategy Committee, risk assessment), SEBI CSCRF (entity-tier determination, IRP, VAPT programme), and IRDAI ICSG 2023 (24 domain policies, ISO 27001, dual notification). Design the incident response plan with regulator-specific notification annexures triggered from the same root IRP — one process, multiple output formats.


Founder Checklist — India Cyber Compliance 2026

  1. Map your licences — identify every RBI, SEBI, and IRDAI licence your entity holds; this determines which framework layers apply.
  2. Build a unified CERT-In incident response process — the 6-hour clock starts at awareness; your IRP must trigger immediately on noticing an incident, before confirmation.
  3. Determine your SEBI entity tier — MII, QSB, or baseline; the SEBI FAQ of 11 June 2025 clarifies the thresholds. QSB determination triggers CISO and annual VAPT requirements.
  4. Implement the CISO governance structure — for RBI and IRDAI covered entities, the CISO must report to the Board Risk Management Committee, not the CIO. Document the reporting line explicitly.
  5. Commission a CERT-In empanelled VAPT vendor — required by IRDAI for the annual ICS audit; recommended by SEBI; aligned with RBI half-yearly VA requirement. One empanelled vendor can service all four framework obligations.

Primary source

Title: CERT-In Directions under Section 70B(6) IT Act, 28 April 2022
Issuer: CERT-In
Effective: 2022-06-28

Frequently asked

Does every regulated entity in India need to comply with CERT-In, RBI, SEBI, and IRDAI cyber rules simultaneously?

Not all four at once. The CERT-In Directions under Section 70B(6) of the Information Technology Act, 2000 apply horizontally to all companies, intermediaries, and government bodies that handle digital systems — so every regulated entity faces them. Sector-specific layers stack on top: RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices (7 November 2023) and the Digital Payment Security Controls Master Direction (18 February 2021) apply to SCBs, SFBs, Payment Banks, and licensed payment operators. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) dated 20 August 2024 applies to Market Infrastructure Institutions, registered intermediaries, and Qualified Stock Brokers meeting the thresholds. IRDAI's Information and Cyber Security Guidelines 2023 apply to insurers, FRBs, brokers, TPAs, and web aggregators. A bank that also carries a SEBI broker registration — as many large banks do — faces CERT-In + RBI + SEBI all three simultaneously.

What is the key difference between the CERT-In 6-hour clock and the RBI/SEBI/IRDAI incident reporting obligations?

CERT-In Direction (ii) of 28 April 2022 requires reporting of any of the 20 specified incident categories to CERT-In within 6 hours of noticing the incident — the clock starts on awareness, not on confirmation. RBI's IT Governance MD Para 7.9 requires the regulated entity to first report to its own Board within 24 hours and then to RBI within the prescribed sector-specific timeline; the 6-hour CERT-In obligation runs parallel and is not subsumed. SEBI's CSCRF para 7 requires MIIs to report to SEBI within 6 hours, QSBs within 24 hours, and all others within 48 hours after discovery. IRDAI's ICSG 2023 Policy 2.10 Clause 3.5 requires simultaneous 6-hour CERT-In + 24-hour IRDAI Chairperson reporting. An insurer that is also an SEBI-registered entity would need to run three parallel clocks — CERT-In (6h), SEBI (6h or 24h by category), and IRDAI (24h) — for the same incident.

When does the SEBI CSCRF phase-in complete?

SEBI's Cybersecurity and Cyber Resilience Framework (SEBI/HO/ITD/ITDVAPT/P/CIR/2024/113 dated 20 August 2024) had three critical phase-in dates. Phase 1 (31 December 2024): Market Infrastructure Institutions (NSE, BSE, CCIL, depositories) and top-tier SEBI intermediaries went live. Phase 2 (30 April 2025): mid-tier intermediaries including large brokers, mutual funds, and portfolio managers. Phase 3 (28 August 2025): all remaining SEBI-registered entities above the asset-under-management and trading-volume thresholds. As of May 2026, the framework is fully in force for all entities within scope. SEBI also issued FAQs on 11 June 2025 clarifying penetration testing frequency, SOC scope, and third-party risk definitions.

What are the IT Act Section 70B penalties for failure to comply with CERT-In Directions?

Section 70B(7) of the Information Technology Act, 2000, as substituted by the Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023) with effect from 30 November 2023, provides for a civil penalty of up to rupees one crore for failure to provide information or comply with the directions issued under Section 70B(6). This replaced the original ₹1 lakh ceiling. Separately, if the non-compliance constitutes a cybersecurity incident itself (e.g., breach notification delay enabling further damage), exposure may extend to Section 66A-type offences depending on the facts. CERT-In has not yet publicly issued adjudication orders post-Jan Vishwas; the penalty ceiling increase is noted in all subsequent advisories.

What does 'Significant Risk Entity' mean under the SEBI CSCRF?

SEBI's CSCRF creates a tiered risk classification. A 'Market Infrastructure Institution' (MII) — comprising stock exchanges, clearing corporations, and depositories — sits at the top and faces the most stringent controls including mandatory SOC, quarterly penetration testing, and real-time event correlation. A 'Qualified Stock Broker' (QSB) is a broker exceeding the turnover or client threshold notified by SEBI and must maintain a documented cybersecurity policy, designated CISO, annual VAPT, and 6-hour incident reporting. All other registered entities (asset management companies, portfolio managers, investment advisors) face a baseline framework with annual self-assessment, 48-hour reporting, and documented incident response plan. The SEBI FAQ of 11 June 2025 confirmed that third-party IT service providers to MIIs are not directly captured under CSCRF but must be contractually bound by the intermediary.

Does the CERT-In Direction apply to startups and small technology companies?

Yes. The CERT-In Directions of 28 April 2022 under Section 70B(6) of the IT Act, 2000 apply to 'service providers, intermediaries, data centres, body corporate, and government organisations' — a deliberately wide formulation that captures incorporated companies of any size operating digital systems or collecting user data in India. The log-retention obligation (180 days, extendable to 365 on direction), ICT system time-synchronisation to NTP servers, and 6-hour incident reporting apply regardless of turnover or headcount. Startups hosting cloud SaaS products are intermediaries under Section 2(w) of the IT Act and squarely within scope. The only practical size-based relief is that CERT-In's enforcement posture has focused on larger entities, but there is no statutory exemption.

How does the RBI Cyber Security Framework 2016 interact with the IT Governance Master Direction 2023?

The RBI Cyber Security Framework for Banks of 2 June 2016 (DBS.CO/CSITE/BC.11/33.01.001/2015-16) was the first structured cybersecurity mandate for scheduled commercial banks. The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices dated 7 November 2023 (RBI/2023-24/99) supersedes and substantially expands on the 2016 Framework. The 2023 MD introduces a Board-level IT Strategy Committee, defines a Chief Information Security Officer role with direct reporting to the Board Risk Management Committee, requires half-yearly vulnerability assessments and annual penetration tests, mandates source-code escrow for core banking systems, and introduces the Technology Risk and Operational Risk reporting architecture. Entities that have CISO policies and controls mapped to the 2016 Framework should treat the 2023 MD as a complete overhaul requiring a fresh gap assessment, not an incremental amendment.

What is the NCIIPC's role in the cyber compliance stack and does it interact with CERT-In?

The National Critical Information Infrastructure Protection Centre (NCIIPC), constituted under Section 70A of the IT Act, 2000 by notification of 16 January 2014, is the designated agency for protecting critical information infrastructure (CII) in seven sectors: power, banking, telecom, transport, e-governance, defence, and space. CII designation is a threshold determination: NCIIPC assesses whether a system, if compromised, could cause severe economic, social, or national security impact. Once designated, the entity must implement NCIIPC's guidelines, report incidents to NCIIPC (separate from the CERT-In 6-hour clock), and participate in vulnerability disclosure exercises. CERT-In and NCIIPC share a coordination MoU; CERT-In incidents affecting CII sectors are also escalated to NCIIPC. Most banks, stock exchanges, and critical payment infrastructure are treated as potential CII — operators in these sectors should conduct a self-assessment against NCIIPC guidelines independently of their CERT-In and RBI/SEBI obligations.

Tags

india-cyber-compliance cert-in-directions-2022 rbi-it-governance-2023 sebi-cscrf-2024 irdai-cyber-guidelines-2023 cybersecurity-regulations-india incident-reporting-india sebi-cscrf cert-in rbi-cybersecurity irdai-cybersecurity
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free