The National Commodity & Derivatives Exchange Limited (NCDEX), on April 23, 2026, issued a circular mandating compliance with the Securities and Exchange Board of India (SEBI) Cybersecurity and Cyber Resilience Framework (CSCRF). The circular prescribes requirements for conducting cyber audits covering 100% of critical systems and 25% of non-critical systems, ensuring no audit cycle remains unaudited, even in case of category changes of regulated entities (REs).
The circular lays down timelines for audit submissions—for FY 2025-26, both half-yearly (Oct 2025–Mar 2026) and annual audits must submit preliminary reports by June 30, 2026 and Action Taken Reports (ATR) by September 30, 2026. Trading members must classify themselves (Qualified, Mid-size, Small-size, etc.) as per SEBI criteria, with such categorization requiring approval from the Board or relevant authority and validation by auditors.
It also mandates adherence to CERT-In empanelled auditor guidelines, detailed Terms of Reference (TOR), and prescribed reporting formats. Members registered with multiple SEBI entities must ensure independent compliance. Additionally, members registered with NSE are required to submit reports to NSE, while others must submit to NCDEX. Non-compliance may attract penalties or disciplinary action as per prior circulars.
[Circular No. NCDEX/Member Tech Compliance-08/2026]