Cyber Security & Resilience Guidelines for Market Infrastructure Institutions

OVERVIEW


  • On April 20, 2026, the International Financial Services Centres Authority (“IFSCA”) issued a landmark circular introducing Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) operating in IFSCs, GIFT City.
  • This circular builds upon IFSCA’s earlier baseline framework issued on March 10, 2025, and establishes a more prescriptive, risk-sensitive regime tailored specifically for systemically important financial market infrastructure.
  • With a view to enhancing cyber resilience, mitigating systemic cyber risks and ensuring preparedness against evolving threat vectors, IFSCA has formulated these guidelines.
  • These Guidelines are structured around the cyber security functions of Govern, Identify, Protect, Detect, Respond, Recover, and Resilience.
 

ENTITIES COVERED 


  • The Guidelines apply to all MIIs operating in IFSCs, including: Stock Exchanges, Clearing Corporations, Depositories, Bullion Exchanges

  • These entities are recognized as systemically critical, given their role in maintaining market integrity, settlement finality, and operational continuity.

KEY HIGHLIGHT OF THE GUIDELINES 

 
  • Board-Level Governance & Accountability: MIIs are required to have a Board-approved Cyber Security and Cyber Resilience Policy, with a dedicated Chief Information Security Officer (CISO) reporting directly to the MD/CEO.
  • Future-Ready, Post-Quantum Cryptography (PQC): In a forward-looking provision, MIIs must conduct annual Cryptographic Risk Assessments and establish roadmaps for adopting PQC standards (e.g. NIST FIPS 203, 204 and 205) to future-proof critical systems against quantum computing threats.
  • 24×7 Cyber Security Operations Centre (C-SOC): All MIIs shall have a round-the-clock C-SOC with contingent capabilities at Disaster Recovery sites, and implement User and Entity Behaviour Analytics (UEBA) for advanced threat detection.
  • Robust Incident Response & Reporting: MIIs must notify IFSCA and CERT-In within 6 hours of detecting any cyber incident, submit an interim report within 3 days, and provide a full root-cause analysis within 30 days.
  • Third-Party & Supply Chain Risk: A risk-based approach to third-party management is mandated, including concentration risk management and contractual cyber security obligations for all critical service providers.
  • Alignment with National Standards: The framework is aligned with the IT Act 2000, the Digital Personal Data Protection Act 2023, and directives from CERT-In, NCIIPC, MeitY, and NQM, ensuring seamless integration with India’s national cybersecurity architecture.
  • ISO 27001 Certification: All MIIs are required to obtain ISO 27001 certification within two years of issuance of the Guidelines.
  • Effective Date: The Guidelines came into effect on April 1, 2026. MIIs are required to achieve full compliance within the timelines prescribed in the respective provisions of the Guidelines.
 

REGULATORY AND LEGAL CONSIDERATIONS

 
  • The regulatory framework shifts toward a prescriptive approach, replacing the earlier principles-based model with detailed and enforceable controls, particularly for critical institutions.
  • Cyber risk is now formally integrated into corporate governance structures, resulting in increased accountability for the board of directors and senior management
  • The inclusion of post-quantum cryptography preparedness reflects a forward-looking regulatory approach aligned with emerging technological risks
  • The introduction of a 6-hour incident reporting requirement strengthens regulatory oversight and aligns with global best practices on cyber incident disclosure.
  • The compliance requirements for MIIs are significantly enhanced, necessitating substantial investment in security infrastructure, skilled human resources, and robust monitoring and audit mechanisms.

CONCLUSION 

 
  • The Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC represent a significant regulatory step by the IFSCA to fortify the financial market ecosystem.
  • By moving from a general, principles-based approach to a more prescriptive and granular framework for MIIs, the regulator acknowledges their systemic importance and the unique, heightened risks they face.
  • Mandatory board-level governance and oversight improve institutional accountability, leading to more robust and transparent operations within GIFT City entities.
  • Overall, these measures enhance resilience and stability of the financial ecosystem in GIFT City, making it more attractive for global institutions and long-term investments

Download Brochure