The Multi-Commodity Exchange of India Ltd. (MCX) on April 27, 2026, issued a circular regarding Cyber Security and Cyber Resilience Audit of Trading Members.
The following has been stated: -
•Trading Members must conduct Cyber Security and Cyber Resilience Audits in line with SEBI’s CSCRF framework, covering all critical systems and a sample of non-critical systems.
•No audit cycle can be skipped, and any missed period must be included in the next audit cycle.
•Timelines are prescribed for submission of audit reports (by June 30, 2026) and corrective action reports (by September 30, 2026).
•Entities must categorize themselves as per SEBI guidelines, with approval from their governing body, and auditors must verify this classification.
•Audit reports must include detailed compliance status, proper documentation, and adherence to prescribed formats, failing which penalties or disciplinary actions may apply.
[Circular No: MCX/TECH/232/2026]