The International Financial Services Centres Authority (IFSCA) on April 20, 2026, introduced a strengthened cybersecurity framework specifically for Market Infrastructure Institutions (MIIs) such as stock exchanges, clearing corporations, depositories, and bullion exchanges operating in GIFT IFSC.
While earlier guidelines applied broadly to all regulated entities using a principles-based approach, this circular recognizes MIIs as systemically critical and therefore subject to a more detailed and prescriptive framework due to their higher risk exposure.
The following has been stated:
• Strengthen cyber governance and accountability at Board and senior management levels
• Address emerging cyber threats, including risks from technologies like quantum computing
• Align with national and international cybersecurity standards
• Ensure robust systems for incident detection, response, reporting, and recovery
The guidelines are based on seven core cybersecurity functions:
• Govern
• Identify
• Protect
• Detect
• Respond
• Recover
• Resilience
• Implementation:
Guidelines are effective from April 01, 2026. The MIIs shall ensure full compliance within the timelines specified in the respective provisions of these Guidelines.
Please refer to Annexure A attached below for guidelines.
[IFSCA-CSD/MSC/2/2026-DCS]