CDSL issued a communique regarding the Quarterly Cyber Incident Reporting by DPs

Jul 01, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Central Depository Services (India) Limited (CDSL) on June 30, 2026, issued a communique regarding the Quarterly Cyber Incident Reporting by DPs.

Depository Participants (DPs) are advised to comply with the reporting requirements outlined in SEBI circular dated June 30, 2022, and CDSL circular dated January 10, 2025, regarding cyber security incidents. All cyber-attacks, threats, incidents, and breaches experienced by DPs must be reported to CDSL in a timely manner.

In this regard, DPs are required to submit a Quarterly Cyber Incident Report through the audit web portal. Even if no cyber incident has occurred during the reporting period, DPs must still submit the report by selecting the option “No” under the cyber-attack/breach section, ensuring mandatory compliance.

The report must be submitted within 15 days from the end of each quarter. For the first quarter of FY 2026–27 (April–June 2026), the deadline for submission is July 15, 2026. Failure to comply with this requirement will be treated as non-compliance and may attract penalties as per the applicable CDSL communique dated February 12, 2025.

DPs are advised to refer to Annexure A for detailed instructions on submitting the quarterly cyber incident report through the audit web portal.

[Circular No. CDSL/IS/DP/POLCY/2026/432]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT