The Central Depository Services (India) Limited (CDSL), on December 18, 2025, issued a circular mandating quarterly cyber incident reporting by Depository Participants (DPs), in continuation of SEBI Circular dated June 30, 2022 and earlier CDSL circulars on cyber security and incident disclosure. The circular reiterates that all cyber-attacks, threats, incidents, and data breaches experienced by DPs must be reported to CDSL in a timely and prescribed manner.
CDSL has informed that an online facility is available through the Audit Web Portal for submission of the quarterly cyber incident report. Depository Participants are required to submit a mandatory quarterly report within 15 days from the end of each quarter, even if no major incident has occurred, to ensure continuous cyber risk monitoring and regulatory oversight.
For the third quarter (October 2025 – December 2025), the last date for submission is January 15, 2026. Failure to submit the report within the stipulated timeline shall be treated as non-compliance and will attract penal action as per the applicable CDSL communique. DPs are advised to follow the reporting process detailed in Annexure A while making submissions.
[Circular No. CDSL/IS/DP/POLCY/2025/832]