CDSL notified regarding the Submission of Cyber Security Audit Report by June 30

May 25, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Central Depository Services (India) Limited (CDSL) on May 22, 2026, issued the notification regarding the Submission of Cyber Security Audit Report.

The following has been stated namely: -

• CDSL has issued compliance timelines and audit requirements for Depository Participants (DPs) under SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) circulars issued between August 2024 and August 2025. 

• Cyber audits must cover 100% of critical systems and 25% of non-critical systems on a sample basis, with auditors required to justify sample selection and ensure no audit period remains unaudited due to category changes. 

• Half-yearly cyber audit reports for Qualified REs and Mid/Small REs offering IBT or Algo Trading facilities for October 2025–March 2026 must be submitted by June 30, 2026, with Action Taken Reports (ATR) due by September 30, 2026. Annual reports for other REs follow the same timelines. 

• Depository Participants and other Regulated Entities (REs) must self-categorize as per SEBI CSCRF criteria, obtain approval from their Board/Designated Authority, and ensure auditors validate the categorization during audits. 

• Cyber audit reports must include management comments, detailed compliance status for each Terms of Reference item, audit scope, methodology, and findings. Failure to submit reports within prescribed timelines will attract penalties under the applicable CDSL communiqué.

[Notification No. CDSL/IS/DP/POLCY/2026/347]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT