India's digital-law week of 24 to 30 August 2026 belongs to one regulator and, almost entirely, to one day. On 24 August 2026 SEBI issued four cyber instruments. Circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 aligns SEBI's Cyber Incident Reporting Portal with the Financial Stability Board's Format for Incident Reporting Exchange (FIRE) — finalised 15 April 2025 with 87 information items, 39 of them optional — and introduces staged reporting across the incident life cycle. Circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026 imposes a 100-point IT Resilience Index on Market Infrastructure Institutions, computed system-driven without manual intervention. SEBI also launched the Cyber Suraksha Portal and announced a tripartite MoU with Rashtriya Raksha University and NISM. CERT-In, meanwhile, recorded five CRITICAL notes inside the security stack itself.
At a Glance — W35 Scoreboard
| # | Pillar | Development | Issuer | Date | Score |
|---|---|---|---|---|---|
| 1 | cybersecurity | Cyber Incident Reporting Portal aligned with FSB FIRE format — circular HO/(449)2026-ITD-5_DIV1/I/19448/2026; common fields, standardised definitions, consistent attribute classification; staged reporting initial → intermediate → final closure; 6-hour email + 24-hour portal clocks under CSCRF Annexure-O(B) unchanged; s.11(1) SEBI Act 1992 | SEBI | 24 Aug 2026 | 10 |
| 2 | cybersecurity | IT Resilience Index for MIIs — circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026; 9 parameters / 100 (Availability 20, Security 20); system-driven, non-discretionary; half-yearly within 60 days; ISF sub-parameters by 30 Nov 2026; live by 28 Feb 2027; first submission H/Y ending 31 Mar 2027 | SEBI | 24 Aug 2026 | 9 |
| 3 | cybersecurity | Five CRITICAL notes in one week — CIVN-2026-0421 (Splunk), 0422 (Cisco Secure Workload), 0423 (Zoom), 0425 (NetScaler ADC/Gateway), 0426 (Gitea RCE); HIGH 0424 (Fortinet), 0427 (Chrome); advisory CIAD-2026-0043 (Oracle) | CERT-In | 25–28 Aug 2026 | 8 |
| 4 | telecom-emerging | CIVN-2026-0428 — HIGH; hardcoded HTTP Digest credentials identical across all devices in CP Plus CP-XR-DE21-S 4G LTE router ≤ firmware 1.057.043_0027 (CVE-2026-19412); fix 1.057.043_0034 | CERT-In | 28 Aug 2026 | 7 |
| 5 | cybersecurity | Cyber Suraksha Portal launched — Press Release No. 51/2026; centralised hub for cybersecurity circulars, vulnerability warnings and incident insights for the securities market | SEBI | 24 Aug 2026 | 7 |
| 6 | cybersecurity | Tripartite MoU with RRU and NISM (signed 17 Aug 2026) — Press Release No. 52/2026; board-level cyber exercises, SOC/VAPT/red-team training, AI and quantum curricula, OSINT market intelligence, and a Technical Innovation Unit as command centre | SEBI | 24 Aug 2026 | 6 |
| 7 | telecom-emerging | PR No. 115 (25 Aug) extends the comment window on the draft QoS of Access and Broadband Regulations, 2024 amendments; PR No. 116 (28 Aug) July 2026 subscription data. No direction or regulation issued | TRAI | 25–28 Aug 2026 | 4 |
| 8 | data-protection | No RBI cyber / IT / payments-security / AI / data-governance instrument traced for the window on either RBI surface; notification index carried six s.35A BR Act 1949 deposit-rate Amendment Directions (RBI/2026-27/243–248, 25 Aug). IRDAI: one non-cyber circular (28 Aug). MeitY, DoT, NPCI, UIDAI and TDSAT surfaces not retrievable | RBI / MeitY | 30 Aug 2026 | 3 |
TL;DR for Founders
Three things to act on this week:
If you are a SEBI-regulated entity: your incident report now has a fixed international vocabulary. The portal at siportal.sebi.gov.in has moved to the FSB FIRE format, and it now accepts a report in stages — initial, intermediate updates, final closure — with SEBI expressly acknowledging that some information will not exist at first report. Rewrite your incident-response runbook around that. The six-hour email and twenty-four-hour portal deadlines have not moved.
If you are an exchange, clearing corporation or depository: the IT Resilience Index must be computed by machine, not by a compliance team. SEBI's words are "system-driven … without manual intervention", with the stated aim that the score be "non-discretionary and fool proof". If a parameter cannot be produced automatically today, that gap has to go to your Standing Committee on Technology as a named exception. The industry-level clock starts first: 30 November 2026 for Industry Standards Forum sub-parameters.
If you run any security operations centre: CERT-In put CRITICAL ratings on Splunk and Cisco Secure Workload in one day, and on NetScaler ADC and Gateway two days later. Those are the SIEM, the segmentation layer and the remote-access edge. Patch state for security tooling should be a board-reported metric, not a line in the vulnerability register — particularly now that "Security" carries 20 of the 100 points in a score SEBI will read.
Top 3 Developments
1. India's Securities Regulator Adopts a Global Incident Vocabulary (Cybersecurity)
What changed: On 24 August 2026 SEBI issued circular HO/(449)2026-ITD-5_DIV1/I/19448/2026, "Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format", signed by Mamata Roy, Deputy General Manager — the same officer who signed SEBI's AI vulnerability-detection advisory of 5 May 2026. It is addressed to twenty categories of regulated entity, from Alternative Investment Funds through Clearing Corporations, Custodians, Depositories, Investment Advisers and Research Analysts, KYC Registration Agencies, Mutual Funds, Stock Brokers and Stock Exchanges to Venture Capital Funds, plus BSE Limited in both its IAASB and RAASB capacities.
The mechanism: SEBI has aligned its Incident Reporting Portal with the "Format for Incident Reporting Exchange (FIRE)" Framework developed by the Financial Stability Board, which enables structured reporting by defining common information fields, standardised definitions and consistent classification of incident attributes, promoting harmonisation across sectors and jurisdictions.
The portal now reports in stages. SEBI states that it "will facilitate reporting of incidents in stages to reflect incident life cycle from initial reporting to intermediate updates and final closure, while acknowledging that certain information may not be available at the time of initial reporting." That last clause is the most practically valuable sentence SEBI has written on incident reporting in years, and it deserves quoting to every incident commander who has had to file at hour six with a half-understood event.
The clocks are unchanged. The circular restates the existing position under Annexure-O(B) of the Cybersecurity and Cyber Resilience Framework (CSCRF), headed Guidelines on Handling Cybersecurity Incidents: all regulated entities must report cyber incidents through mkt_incidents@sebi.gov.in within six hours and through the SEBI Incident Reporting Portal within twenty-four hours, by logging into siportal.sebi.gov.in. It is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992, must be read with applicable SEBI circulars including CSCRF, and requires consequential amendments to bye-laws, rules and regulations.
What FIRE is: The Financial Stability Board published FIRE as a final report on 15 April 2025, after a consultation report of 17 October 2024 that drew sixteen responses across banking, insurance, asset management and financial market infrastructure. It defines 87 information items, of which 39 are optional, in four sections, with a taxonomy package built on the Data Point Model method enabling machine-readable submission in formats such as XBRL, and builds on the FSB's 2023 Recommendations to Achieve Greater Convergence in Cyber Incident Reporting. The FSB does not collect incident reports and FIRE imposes no direct requirement on firms: an authority may adopt it in full or in part, rename fields for local context, and decide which items are essential.
Why it matters: Three things follow, and only the first is obvious.
The report becomes a data object. Free-text incident narrative has been the norm in Indian financial-sector reporting. A defined field set with standardised definitions and a machine-readable taxonomy changes what the regulator can do with a report — it can be aggregated, correlated across entities and compared over time without a human reading each one. That is a supervisory capability upgrade dressed as a formatting change, and the fields should be assumed to be analysed, not merely filed.
Staged reporting resolves a real conflict and creates a discipline. Under the pre-existing regime a firm faced a six-hour deadline against an incident it did not yet understand, so early reports were either thin or speculative. FIRE's life-cycle model legitimises the thin initial report — but the record now contains a dated sequence of what the firm knew and when. Every intermediate update should be treated as a document a later proceeding will read in order.
Multi-regulator reporting gets cheaper, not simpler. A SEBI regulated entity that is also a body corporate under the CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the Information Technology Act, 2000, still runs a second six-hour clock to a different channel. If it holds a telecom authorisation, the Telecommunications (Telecom Cyber Security) Rules, 2024 made under Section 22 of the Telecommunications Act, 2023 add a third. FIRE harmonises the vocabulary, not the deadlines — one internal capture template can now feed several reports, but alignment of format is not alignment of obligation.
Provenance (§5.11): the circular number, date and full operative text are read from the signed SEBI circular PDF attached to the circular's own page on sebi.gov.in. The FIRE publication date, item counts and adoption model are read from the Financial Stability Board's own publication record for the final report of 15 April 2025.
Practitioner takeaway: Map each FIRE-aligned field to an owner and a system of record — most firms will find a third of the fields have no automated source and are populated from memory. Then separate the hour-six set from the deferred-update set explicitly, in writing, before the next incident: the staged model rewards a firm that has pre-decided and punishes one that improvises.
Link: SEBI — Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format (24.08.2026) | FSB — FIRE final report, 15 April 2025
Score: 10/15.
2. SEBI Puts a Number on IT Resilience — and Insists a Machine Compute It (Cybersecurity)
What changed: Also on 24 August 2026, SEBI issued circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026, "IT Resilience Index for Market Infrastructure Institutions (MIIs)", signed by Darshil D. Bhatt, Deputy General Manager, Division of Policy and Development – 4, Market Regulation Department. It is addressed to all Stock Exchanges, all Clearing Corporations and all Depositories, excepting AMC Repo Clearing Ltd., and follows discussion with SEBI's Technical Advisory Committee and a consultation paper dated 25 March 2026.
The index: ITRI measures the robustness of Critical Systems as already defined at Clause 9.1.2.3 of the Master Circular of 30 December 2024 (Stock Exchanges and Clearing Corporations), Clause 4.31.2.3 of the Master Circular of 3 December 2024 (Depositories) and Clause 16.4.3(c) of the Master Circular of 4 August 2023 (Commodity Derivatives Segment), extending to other systems feeding into or related to them. The nine parameters and their weights:
| # | Parameter | Weight |
|---|---|---|
| 1 | Availability | 20 |
| 2 | Security | 20 |
| 3 | Integrity | 10 |
| 4 | Governance | 10 |
| 5 | Reliability and Monitoring | 10 |
| 6 | Business Continuity | 10 |
| 7 | Modularity and Flexibility | 10 |
| 8 | Scalability | 5 |
| 9 | Others (such as incident handling) | 5 |
| Total | 100 |
The design constraint that matters most: SEBI requires that computation be system-driven — "computed automatically from IT systems (or data extracted from such systems) without manual intervention" — and states the objective in terms: so that "computation of ITRI remains non-discretionary and fool proof." Where a parameter cannot be computed automatically, manual data retrieval is permitted only after prior discussion of such exceptions with the institution's Standing Committee on Technology (SCOT).
The cadence: half-yearly, within 60 days of each half-year end, submitted with a comparative analysis of two consecutive half-years on a rolling basis and the corrective actions taken or proposed, to the SCOT and the Governing Board. The framework is expressly described as self-operating — SEBI is not collecting the index centrally; the institution computes it and reports it to its own governance layer.
Two adjacent obligations: MIIs must build an Early Warning System to detect deterioration in any ITRI parameter before it becomes a performance issue, and systems giving continuous visibility into service delivery to market participants — including consolidated dashboards flagging deviations or anomalies, with SOPs for that monitoring. Both sit on top of the SEBI circular of 10 December 2024 on Revised Guidelines for Capacity Planning and Real Time Performance Monitoring.
The timeline:
| Date | Milestone |
|---|---|
| 30 November 2026 | Industry Standards Forum finalises sub-parameters, measurement criteria, baseline parameters, acceptable threshold scores, SOP and objective system-driven scoring methodology |
| 31 January 2027 | Detailed SOPs, after SCOT review, submitted to SEBI |
| 28 February 2027 | Full operationalisation including Early Warning System and real-time service-delivery monitoring (beta already implemented) |
| 31 March 2027 | Half-year end for the first ITRI submission under the framework |
Why it matters: This is a shift in the character of Indian cyber-resilience regulation, easy to miss because it arrives as a scorecard.
Compliance becomes telemetry. Almost every existing Indian cyber obligation — CSCRF, the RBI IT Governance Master Direction, 2023, the IRDAI Information and Cyber Security Guidelines, 2023 — is discharged by producing documents: policies, VAPT reports, board minutes, audit responses. ITRI cannot be discharged that way. A score that must be produced automatically from systems, with manual computation treated as a named exception requiring committee discussion, is a requirement to instrument the estate, not to describe it. An MII that cannot today emit availability, integrity and security telemetry in machine-readable form has an engineering project, not a compliance project — and roughly fifteen months.
"Non-discretionary and fool proof" is a supervisory statement about trust, and regulators do not write that phrase about a metric they expect to be computed honestly by default. It signals that SEBI expects the index to be read comparatively — which is also why the Industry Standards Forum, and not each MII, owns baselines, thresholds and scoring methodology, "with the intention of having comparability across MIIs." The Security parameter is where this week folds in on itself: twenty of the hundred points turn on security posture, and that telemetry comes from precisely the platforms CERT-In flagged this week — see Item 3.
A gap, stated as a gap (§5.10): SEBI has not published threshold scores, sub-parameters or a scoring methodology; those are for the Industry Standards Forum by 30 November 2026. Any statement today about what score an MII "should" achieve, or what a given score means, is unsupported by the circular. Advise on the obligation to instrument, not on a target number.
Practitioner takeaway: For MII clients the first deliverable is not a score but a parameter-by-parameter inventory of which of the nine can be computed automatically today — every "no" becomes a SCOT agenda item under paragraph 5.5. Vendors to MIIs should expect contractual demands for machine-readable telemetry and Early-Warning-System support in renewals from late 2026.
Link: SEBI — IT Resilience Index for Market Infrastructure Institutions (24.08.2026)
Score: 9/15.
3. Five CRITICAL Notes, and Two of Them Are in the Security Stack (Cybersecurity)
What changed: Between 25 and 28 August 2026 CERT-In recorded an unusually heavy set of vulnerability notes:
| Note | Date | Subject | Severity |
|---|---|---|---|
| CIVN-2026-0421 | 25 Aug 2026 | Multiple vulnerabilities in Splunk products | CRITICAL |
| CIVN-2026-0422 | 25 Aug 2026 | Multiple vulnerabilities in Cisco Secure Workload | CRITICAL |
| CIVN-2026-0423 | 27 Aug 2026 | Multiple vulnerabilities in Zoom products | CRITICAL |
| CIVN-2026-0424 | 27 Aug 2026 | Multiple vulnerabilities in Fortinet products | HIGH |
| CIVN-2026-0425 | 27 Aug 2026 | Multiple vulnerabilities in NetScaler ADC and NetScaler Gateway | CRITICAL |
| CIVN-2026-0426 | 27 Aug 2026 | Remote code execution in Gitea | CRITICAL |
| CIVN-2026-0427 | 27 Aug 2026 | Multiple vulnerabilities in Google Chrome for Desktop | HIGH |
| CIVN-2026-0428 | 28 Aug 2026 | Hardcoded credentials in CP Plus router — see Item 4 | HIGH |
Advisory CIAD-2026-0043 of 28 August 2026 covered multiple vulnerabilities in Oracle products.
Why it matters: Read the list by function rather than by vendor and a pattern emerges that bears directly on the two SEBI circulars issued three days earlier.
Splunk is the SIEM — the system of record for security events and, in most regulated Indian estates, the evidentiary substrate for incident reconstruction, the place a firm goes to answer the questions a FIRE-format report asks. A CRITICAL flaw there is a compromise of the audit trail, not merely of an application. Cisco Secure Workload is the segmentation layer, whose entire purpose is to constrain lateral movement after an initial foothold. NetScaler ADC and NetScaler Gateway terminate remote access into the estate, and Fortinet holds the same perimeter position. In a single week CERT-In therefore recorded critical or high-severity defects in the log store, the segmentation control, the remote-access edge and the perimeter firewall — four of the controls whose effectiveness a resilience metric is supposed to measure.
The regulatory bridge is already built. SEBI's advisory of 5 May 2026 on emerging advanced AI tools for vulnerability detection — the first Indian financial-markets circular to name a specific AI model — imposed a ten-point operational checklist on eighteen categories of regulated entity, including SOAR and SIEM integration, mandatory market-SOC onboarding, immediate patching with virtual patching as an interim measure and third-party COTS vendor risk assessment. Every one of those items is engaged by this week's notes, and the COTS vendor-assessment obligation in particular is not satisfied by a questionnaire returned in March about a product rated CRITICAL in August.
The uncomfortable inference, which is Veritect's own: an organisation computing its "Security" score from telemetry emitted by Splunk, and its segmentation assurance from Cisco Secure Workload, is measuring its resilience with instruments the national CERT rated CRITICAL in the same fortnight the measurement obligation was created. That is not an argument against the index. It is an argument for treating the patch state of security tooling as a governance-reported item in its own right, distinct from the general vulnerability backlog, and for building the ITRI Early Warning System so that it can detect degradation in its own sensors.
A provenance note requiring verification (§5.10, §5.11): CERT-In's Guidelines surface lists, under reference code CISG-2026-02 and dated 25 May 2026, a document titled "Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure". Veritect's research corpus and the W33 and W34 trackers cite a 25 May 2026 Blueprint under reference CISG-2026-02, titled "Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure". Whether these are the same instrument carried under two CERT-In series codes, or two separate documents, is not resolved here. Both records are reported as retrieved; neither is asserted to supersede the other, and the reference code should be confirmed against CERT-In's own guideline page before it is cited in client-facing material.
Practitioner takeaway: Ask the client for a single artefact — the current version and patch date of every product that produces evidence for a security control, listed separately from the application estate. Most will not have one. Then check that list against CIVN-2026-0421, 0422, 0424, 0425 and 0426 as a live test, exactly as the CERT-In AI Blueprint inventory step was tested against Langflow and MLflow in the two preceding weeks.
Link: CERT-In — Vulnerability Notes 2026 | CERT-In — Advisories 2026
Score: 8/15.
Beyond this Brief Preview — Veritect Legal AI
The full SEBI CSCRF Annexure-O incident-handling chain with the FIRE field mapping, the SEBI cyber-suraksha.ai task force advisory of 5 May 2026 with its complete ten-point Annexure-A checklist and eighteen addressee categories, the ITRI parameter set read against the CSCRF maturity-level classification thresholds, the CERT-In Vulnerability Notes tracker with security-tooling-layer classification, and the three-clock reconciliation across CERT-In's 28 April 2022 Directions, CSCRF Annexure-O(B) and the Telecommunications (Telecom Cyber Security) Rules, 2024 are available in Veritect Legal AI.
Regulatory Action Log — Items 4-8
| Date | Regulator | Pillar | Action | Source |
|---|---|---|---|---|
| 28 Aug 2026 | CERT-In | telecom-emerging | CIVN-2026-0428 (HIGH) — hardcoded HTTP Digest authentication credentials, identical across every device, in the CP Plus CP-XR-DE21-S 4G LTE router at firmware 1.057.043_0027 or below (CVE-2026-19412). An attacker on the local network can extract the credentials from the firmware and obtain full administrative control. Fix: firmware 1.057.043_0034. Credited to four named independent researchers. A rare CERT-In record against an Indian-brand consumer and small-office network device — and a live illustration of why the Telecommunications (Telecom Cyber Security) Rules, 2024 under Section 22 of the Telecommunications Act, 2023 treat equipment provenance as a regulatory question and not only a procurement one | cert-in.org.in |
| 24 Aug 2026 | SEBI | cybersecurity | Launch of the Cyber Suraksha Portal — Press Release No. 51/2026. Described as part of SEBI's Cyber Security Initiative and as a comprehensive, centralised hub for the securities market to share knowledge and disseminate cybersecurity information, through which market participants can directly access the latest cybersecurity circulars, vulnerability warnings and incident insights. The name is continuous with the cyber-suraksha.ai task force constituted under SEBI's advisory of 5 May 2026; the press release does not state the relationship between the two, and none is asserted here | sebi.gov.in |
| 24 Aug 2026 | SEBI | cybersecurity | Tripartite MoU with Rashtriya Raksha University (RRU) and NISM — Press Release No. 52/2026; the MoU itself was entered into on 17 August 2026 and announced on 24 August. RRU is an Institution of National Importance under the Ministry of Home Affairs; NISM is a Public Trust registered under the Maharashtra Public Trusts Act, 1950 and an educational initiative of SEBI. The eight salient features span joint training for regulators, law enforcement agencies and regulated entities; thematic training on secure software development and API security, board- and senior-management cybersecurity exercises, SOC, VAPT and red-team–blue-team live-fire drills, and AI and quantum computing; degree and certification programmes; a knowledge repository; enhancement of securities-market intelligence using OSINT techniques pioneered by RRU; and a Technical Innovation Unit (TIU) envisioned as a command centre for the securities market | sebi.gov.in |
| 25 & 28 Aug 2026 | TRAI | telecom-emerging | Press Release No. 115 (25 Aug) extended the last date for comments and counter-comments on the Consultation Paper on draft amendments in the Standards of Quality of Service of Access (Wireline and Wireless) and Broadband (Wireline and Wireless) Service Regulations, 2024 — the consultation paper itself having issued on 5 August 2026 as PR No. 112. Press Release No. 116 (28 Aug) released telecom subscription data as on July 2026. No TRAI direction or regulation was issued within the window; the most recent direction remains the 1601-series phased-implementation Direction of 10 August 2026 | trai.gov.in |
| 25 Aug 2026 | RBI | fintech-payments | RBI's notification surface for the window carried six Amendment Directions — RBI/2026-27/243 to RBI/2026-27/248, all dated 25 August 2026, covering Commercial Banks, Small Finance Banks, Local Area Banks, Regional Rural Banks, Urban Co-operative Banks and Rural Co-operative Banks — curtailing the temporary FCNR(B) and NRE deposit-rate relaxation to 31 August 2026 under Section 35A of the Banking Regulation Act, 1949. This is a prudential instrument with no digital-law content, and is recorded here only to establish what the RBI surface did carry | rbi.org.in |
| 28 Aug 2026 | IRDAI | data-protection | One IRDAI circular issued in the window, on migration of reinsurance regulatory returns and other reinsurance functionalities to the Integrated Business Analytics Platform (BAP). A regulatory-reporting platform migration rather than a cyber or information-security instrument — noted because platform migrations move regulated data between systems and engage purpose limitation and security safeguards under the Digital Personal Data Protection Act, 2023 where personal data is in scope, a question the circular does not address | irdai.gov.in |
Veritect daily-news cross-check: Veritect's daily-news output for 24–30 August 2026 carried both SEBI cyber circulars — the FIRE-format alignment and the IT Resilience Index — and the RBI deposit-rate Amendment Directions of 25 August. All three are cross-linked in related_articles and are treated here at tracker altitude rather than re-reported.
Research Gaps and Unretrieved Sources
Recorded under CLAUDE.md §5.10 — an absence of retrieval is not a finding of inactivity.
- RBI — a scoped negative, not a blanket one. Both the RBI notifications index and the RBI press-release surface were loaded for this tracker, and neither carried a cyber-security, IT, outsourcing, payments-security, AI or data-governance instrument dated 24 to 30 August 2026; the press-release surface was dominated by liquidity operations, auctions, statistical returns and supervisory action against individual co-operative banks. This is a statement about those two surfaces for that window — RBI also publishes through committee reports, draft guidance and speeches, which were not exhaustively swept.
- MeitY and DoT — unretrievable, not silent. Both ministries now serve listing pages that return HTTP 404 on the paths attempted (
/whatsnew,/media/press-release,/documents/press-release,/documents/gazette-notification) or render without any dated content. No MeitY or DoT instrument dated 24 to 30 August 2026 was confirmed either way. The status of the draft IT (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026 circulated in March 2026 therefore remains unverified, as it did in W34. - NPCI returned HTTP 403; the UIDAI circulars path and the TDSAT Delhi judgments path returned HTTP 404. Nothing is asserted about any of the three for this window.
- SEBI press-release and circular pages render server-side only as headers. The body of every SEBI page is delivered as an attached signed PDF. For this tracker those PDFs were retrieved and read in full, so the SEBI items above rest on the operative text of the instruments themselves, not on page metadata. This corrects the position recorded in W34, where the operative text of the 20 August circulars could not be read.
- Data Protection Board of India: no Tier 1 notification of constitution under Section 18(1) of the Digital Personal Data Protection Act, 2023 traced as at 5 September 2026. The Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) continues; composition is fixed at a Chairperson plus four Members. Confirm against the Gazette before asserting Board status.
- eGazette was not retrieved for this window. The Act number and Gazette publication date of the Taxation and Other Laws (Amendment) Act, 2026 — and therefore the commencement date of its Section 10A Payment and Settlement Systems Act, 2007 limb, carried as Item 1 of W34 — remain unconfirmed.
- CERT-In guideline reference codes: see the provenance note in Item 3. The CISG-2026-02 / CISG-2026-02 discrepancy on the 25 May 2026 AI Blueprint is open and should be resolved against CERT-In's own guideline page before either code is used in client-facing material.
What's Next
- 30 November 2026 — Industry Standards Forum deadline for ITRI sub-parameters, detailed measurement criteria, baseline parameters, acceptable threshold scores, the SOP and the objective system-driven scoring methodology. This is the document that will determine what the index actually measures; the circular does not.
- 31 January 2027 — MII SOPs, after SCOT review, due to SEBI.
- 28 February 2027 — full ITRI operationalisation including the Early Warning System and real-time service-delivery monitoring.
- 31 March 2027 — half-year end for the first ITRI submission; the computation is then due within 60 days, i.e. by end May 2027.
- Near-term, undated — whether RBI or IRDAI follow SEBI onto the FSB FIRE format for their own incident-reporting channels. Nothing has been traced either way; the FSB's model expressly contemplates authority-by-authority adoption, and divergence between Indian financial regulators on incident fields would reintroduce exactly the cost FIRE exists to remove.
- Also near-term — final RBI Guidance on Regulatory Expectations for Data Governance following the consultation that closed 17 August 2026, and the final Model Risk Management guidance after the 24 July 2026 close.
- ~August–September 2026 onward — 1601-series phase dates under the TRAI Direction of 10 August 2026; the outcome of the QoS Regulations 2024 amendment consultation now running on an extended window.
- ~November 2026 — DPDP consent-manager registration opens under Rule 4 of the DPDP Rules, 2025. ~13 May 2027 — end of the eighteen-month DPDP phased-compliance runway.
Founder Action Items
- Rebuild the incident runbook around FIRE's staged model. Map every FIRE-aligned field on siportal.sebi.gov.in to an owner and an automated source. Decide now, in writing, what goes in the hour-six filing and what is deferred to an intermediate update — the format rewards a firm that has pre-decided and creates a documented knowledge timeline for one that has not. The six-hour email and twenty-four-hour portal deadlines under CSCRF Annexure-O(B) have not changed.
- If you are an MII, start the instrumentation audit this quarter. Produce a nine-row table: for each ITRI parameter, can it be computed automatically, without manual intervention, today? Every "no" is a SCOT agenda item under paragraph 5.5 and an engineering ticket before 28 February 2027.
- Separate security-tooling patch state from the general vulnerability backlog and report it to the board. CERT-In rated Splunk and Cisco Secure Workload CRITICAL on 25 August and NetScaler ADC/Gateway CRITICAL on 27 August. When the SIEM, the segmentation layer and the remote-access edge are the vulnerable components, the vulnerability register is being maintained by systems that are themselves in the register.
- Patch CP Plus CP-XR-DE21-S routers to firmware 1.057.043_0034. Hardcoded credentials identical across every device on the affected firmware (CVE-2026-19412) mean the exposure is fleet-wide by design, and branch offices and small sites are where these devices live.
- Do not treat the Cyber Suraksha Portal as an obligation. Press Release No. 51/2026 describes an information hub, not a filing channel. Reporting still goes to mkt_incidents@sebi.gov.in and siportal.sebi.gov.in.
- Do not assert the DPDP Board's constitution. No Section 18(1) notification had been traced as at 5 September 2026. Check the Gazette before it goes in a client note.
Practitioner Watch-List
- Format harmonisation is not deadline harmonisation. A single firm may simultaneously owe CERT-In a report within six hours under the 28 April 2022 Directions made under Section 70B(6) of the Information Technology Act, 2000, SEBI an email within six hours and a portal filing within twenty-four under CSCRF Annexure-O(B), and — if it holds a telecom authorisation — a further report under the Telecommunications (Telecom Cyber Security) Rules, 2024 made under Section 22 of the Telecommunications Act, 2023. FIRE gives all of these a common vocabulary. It merges none of the clocks, and advising otherwise is the most likely error to arise from this circular in the next six months.
- The staged report as an evidentiary sequence. The life-cycle model produces a dated record of the firm's evolving understanding — a benefit in regulatory dialogue and a risk in litigation. The drafting discipline for intermediate updates should be set by counsel, not by the SOC.
- The Industry Standards Forum is doing quasi-regulatory work, and ITRI's "system-driven" requirement will surface in vendor contracts. Sub-parameters, baselines, thresholds and scoring methodology due by 30 November 2026 are functionally the substance of the obligation, so MII clients should treat Forum participation as a regulatory-affairs priority rather than a technical committee. Expect telemetry-emission, API-access and Early-Warning-System support obligations to enter vendor renewals from late 2026; vendors should read paragraph 5.5 now and price for it.
- The Technical Innovation Unit and OSINT market intelligence. Press Release No. 52/2026 records that the tripartite MoU will "enhance Securities market intelligence by leveraging the OSINT technologies and techniques pioneered by RRU" and establish a Technical Innovation Unit as a command centre. Open-source-intelligence capability held by a securities regulator in partnership with a Ministry of Home Affairs institution raises questions of scope, retention and interaction with the Digital Personal Data Protection Act, 2023 that the press release does not address and no instrument yet answers.
- Equipment provenance as a cyber-law question. CIVN-2026-0428 is a domestic-brand device with universal hardcoded credentials. The Telecom Cyber Security Rules, 2024 and the trusted-source regime under the Telecommunications Act, 2023 treat equipment as a regulated input; a hardcoded-credential finding in a widely deployed Indian router is the sort of fact that shapes how that regime is applied.
FAQ
What exactly did SEBI change by aligning its portal with the FIRE format?
It changed the shape of the report, not the deadline. SEBI circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 of 24 August 2026 aligns the Cyber Incident Reporting Portal at siportal.sebi.gov.in with the Format for Incident Reporting Exchange (FIRE) developed by the Financial Stability Board, which works by defining common information fields, standardised definitions and consistent classification of incident attributes. The portal now supports staged reporting across the incident life cycle — initial report, intermediate updates, final closure — and SEBI expressly acknowledges that certain information may not be available at the time of initial reporting. The pre-existing clocks under Annexure-O(B) of the CSCRF are restated unchanged: six hours by email to mkt_incidents@sebi.gov.in and twenty-four hours to the portal. The circular is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992, addressed to twenty categories of regulated entity plus BSE Limited in its IAASB and RAASB capacities, and requires consequential amendments to bye-laws, rules and regulations.
What is the IT Resilience Index, and what is the deadline?
A 100-point score that Market Infrastructure Institutions — all Stock Exchanges, Clearing Corporations and Depositories, excepting AMC Repo Clearing Ltd. — must compute automatically from their own systems. Circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026 of 24 August 2026 sets nine parameters: Availability 20, Security 20, Integrity 10, Governance 10, Reliability and Monitoring 10, Business Continuity 10, Modularity and Flexibility 10, Scalability 5, Others including incident handling 5. It measures Critical Systems as already defined at Clause 9.1.2.3 of the Master Circular of 30 December 2024 (Stock Exchanges and Clearing Corporations), Clause 4.31.2.3 of the Master Circular of 3 December 2024 (Depositories) and Clause 16.4.3(c) of the Master Circular of 4 August 2023 (Commodity Derivatives), plus related feeding systems. Computation must be system-driven, without manual intervention, so that it remains "non-discretionary and fool proof"; manual retrieval requires prior discussion of the exception with the Standing Committee on Technology. Reporting is half-yearly within 60 days of each half-year end, with a rolling two-half comparison and corrective actions, to SCOT and the Governing Board. The deadlines: Industry Standards Forum sub-parameters and scoring methodology by 30 November 2026; SOPs to SEBI by 31 January 2027; operationalisation including the Early Warning System by 28 February 2027; first submission for the half-year ending 31 March 2027. SEBI records that MIIs have already implemented a beta version.
Why should a board care that CERT-In flagged Splunk and NetScaler?
Because those products are the instruments the compliance regime assumes are working. Between 25 and 28 August 2026 CERT-In recorded five CRITICAL notes — CIVN-2026-0421 (Splunk), CIVN-2026-0422 (Cisco Secure Workload), CIVN-2026-0423 (Zoom), CIVN-2026-0425 (NetScaler ADC and Gateway) and CIVN-2026-0426 (Gitea remote code execution) — plus HIGH notes CIVN-2026-0424 (Fortinet) and CIVN-2026-0427 (Chrome), and advisory CIAD-2026-0043 (Oracle, 28 August). Splunk is the SIEM and evidentiary log store; Cisco Secure Workload is the segmentation control that limits lateral movement; NetScaler ADC and Gateway terminate remote access; Fortinet holds the perimeter. SEBI's advisory of 5 May 2026 already requires SOAR and SIEM integration, market-SOC onboarding, immediate patching with virtual patching as an interim measure and third-party COTS vendor risk assessment across eighteen categories of regulated entity — and the Security parameter carries 20 of the 100 ITRI points. A firm computing its resilience score from telemetry produced by components that the national CERT rated CRITICAL in the same fortnight has a governance question, not merely a patching queue. The practical response is to report security-tooling patch state to the board separately from the general vulnerability backlog.
Was there any RBI, MeitY or DPDP development between 24 and 30 August 2026?
For RBI, a scoped no. For MeitY, an honest unknown. Both the RBI notifications index and the RBI press-release surface were loaded for this tracker, and neither carried a cyber-security, IT, outsourcing, payments-security, artificial-intelligence or data-governance instrument dated within the window. What the notification surface did carry were six Amendment Directions of 25 August 2026 — RBI/2026-27/243 to 248 — issued under Section 35A of the Banking Regulation Act, 1949, curtailing the FCNR(B) and NRE deposit-rate relaxation to 31 August 2026: prudential, not digital-law. MeitY and DoT could not be retrieved at all — their listing surfaces returned HTTP 404 or rendered without any dated content — so no MeitY or DoT instrument dated 24 to 30 August 2026 was confirmed either way, and the status of the draft IT (Intermediary Guidelines) Second Amendment Rules, 2026 remains unverified. NPCI returned HTTP 403; UIDAI and TDSAT listing paths returned HTTP 404. IRDAI was readable and issued one circular in the window, on 28 August, migrating reinsurance regulatory returns to its Business Analytics Platform — a reporting-platform migration with no cyber content, though platform migrations move regulated data between systems and engage DPDP purpose-limitation and security-safeguard analysis where personal data is in scope. On the Board: no Section 18(1) notification constituting the Data Protection Board of India had been traced as at 5 September 2026, which is a statement about retrieval and not a conclusion that none exists.
Primary Sources
Tier 1 sources only: SEBI (sebi.gov.in), CERT-In (cert-in.org.in), RBI (rbi.org.in), TRAI (trai.gov.in), IRDAI (irdai.gov.in), MeitY (meity.gov.in), DoT (dot.gov.in), and the Financial Stability Board (fsb.org) as the issuing body of the FIRE format. All developments reported as of 30 August 2026 unless stated; the tracker was compiled on 5 September 2026 as a catch-up edition for a closed week. Every SEBI item rests on the operative text of the signed circular or press-release PDF, read in full. Items flagged 'expected', 'pending' or 'unconfirmed' carry that qualifier explicitly. Where a Tier 1 source could not be retrieved — notably MeitY, DoT, NPCI, UIDAI, TDSAT and eGazette — that is recorded in the Research Gaps section as an absence of retrieval and must not be read as an absence of regulatory activity. Reconfirm against primary-source URLs before acting.
- SEBI — Alignment of SEBI's Cyber Incident Reporting Portal with FIRE format, Circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 (24.08.2026)
- SEBI — IT Resilience Index for Market Infrastructure Institutions (MIIs), Circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026 (24.08.2026)
- SEBI — Press Release No. 51/2026 (24.08.2026), Launch of Cyber Suraksha Portal
- SEBI — Press Release No. 52/2026 (24.08.2026), MoU between SEBI, Rashtriya Raksha University and NISM
- SEBI — Circulars listing
- SEBI — Press Releases listing
- SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)
- SEBI — Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (05.05.2026)
- Financial Stability Board — Format for Incident Reporting Exchange (FIRE): Final report, 15 April 2025
- Financial Stability Board — FIRE Taxonomy package
- CERT-In — Vulnerability Notes 2026 (CIVN-2026-0421 to 0428)
- CERT-In — Advisories List 2026 (CIAD-2026-0043)
- CERT-In — Directions under Section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022
- CERT-In — Guidelines
- RBI — Notifications listing
- RBI — Press Releases listing
- TRAI — Press Releases
- IRDAI — Circulars
- MeitY — Digital Personal Data Protection Rules, 2025
- Gazette of India (eGazette)
Beyond this Brief Preview — Veritect Legal AI
Veritect Legal AI carries the research-grade layer behind this tracker: the SEBI CSCRF Annexure-O incident-handling chain mapped field-by-field against the FSB FIRE information items, the SEBI cyber-suraksha.ai task force advisory of 5 May 2026 with its full ten-point Annexure-A checklist and eighteen addressee categories, the CSCRF maturity-level classification thresholds read against the nine ITRI parameters, the CERT-In Vulnerability Notes tracker with security-tooling-layer classification, and the three-clock reconciliation across the CERT-In Directions of 28 April 2022, CSCRF Annexure-O(B) and the Telecommunications (Telecom Cyber Security) Rules, 2024.
Next edition: W36 tracker covering 31 August – 6 September 2026 — the SEBI–ESMA Memorandum of Understanding of 4 September, the SEBI derivative settlement-price methodology review of 3 September, CERT-In notes CIVN-2026-0429 to 0440 including the Manacle ERP and Next.js remote-code-execution items, the RBI non-resident bank account and CIMS-portal notifications of 2 September, and any MeitY or DoT instrument recoverable once those portals render dated content again.