NSDL Introduces e-PASS Facility for Electronic Submission of Cyber Audit Reports

May 13, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe National Securities Depository Limited (NSDL), on May 12, 2026, introduced a facility for submission of half-yearly and annual Cyber Security Audit Reports through the e-PASS portal. The circular refers to earlier directions issued pursuant to SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF), including auditor selection norms, Terms of Reference (TOR), and reporting requirements applicable to Regulated Entities (REs).

NSDL informed participants that Cyber Security Audits must be conducted strictly in accordance with the prescribed TOR under the CSCRF framework. Participants are required to upload audit reports electronically through the e-PASS application along with the Auditor’s Declaration in the prescribed format. The circular also mandates submission of compliance status on closure of audit findings within three months from the date of submission of the initial cybersecurity report.

The circular prescribes June 30, 2026 as the due date for submission of both half-yearly and annual Cyber Security Audit Reports for the relevant audit periods, while the Action Taken Report (ATR), wherever applicable, must be submitted by September 30, 2026. NSDL further clarified that non-submission of audit reports within the stipulated timelines will be treated as regulatory non-compliance and may attract penalties or further action under the NSDL Business Rules. 

[Circular No. NSDL/POLICY/2026/0074]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT