The Bombay Stock Exchange (BSE), on April 22, 2026, issued a compliance notice mandating Cyber Security and Cyber Resilience Audits for trading members in alignment with the Securities and Exchange Board of India (SEBI) CSCRF framework, prescribing audit scope, timelines, and submission requirements.
The notice requires cyber audits to cover 100% of critical systems and at least 25% of non-critical systems on a sample basis with proper justification. It also ensures that no audit cycle remains unaudited due to any change in categorization, with missed periods to be included in the current audit cycle. Timelines have been specified for submission of preliminary audit reports by June 30, 2026 and corrective action taken reports by September 30, 2026 for applicable entities.
Further, trading members must self-classify under the SEBI CSCRF framework with approval from their governing body, and auditors must validate such classification. The notice also lays down requirements for selection of CERT-In empanelled auditors, detailed reporting formats, audit scope coverage, and submission mechanisms, including provisions for entities registered across multiple exchanges.
[Notification No. 20260422-33]