The National Commodity & Derivatives Exchange Limited (NCDEX) on July 03, 2026, notified regarding the Quarterly Cyber Incident reporting under the Cyber Security & Cyber Resilience Framework for Regulated Entities (REs).
The following has been stated:
• It has directed regulated entities (REs) and trading members to submit their Quarterly Cyber Incident Report for the quarter ended June 30, 2026, in accordance with the SEBI Cyber Security and Cyber Resilience Framework. The report shall be submitted through the NCFE portal or via the designated Exchange email on or before July 15, 2026. Members are also required to follow the prescribed Standard Operating Procedure (SOP) for reporting immediate cybersecurity incidents. Further, members registered with both NCDEX and NSE are required to submit the quarterly report only to NSE under the common submission mechanism, while members registered only with NCDEX shall continue reporting to NCDEX.
• The circular also reiterates the penalty framework for delayed or non-submission of the quarterly cyber incident report. Monetary penalties ranging from ₹1,500 to ₹5,000 per day, depending on the category of the member, will be levied for delays, with a 50% escalation for repeat defaults. Continued non-compliance beyond the prescribed timelines may result in restrictions on new client registrations, issuance of a disablement notice, and eventual suspension of trading across all segments until the report is submitted.
[Notification no. - NCDEX/Member Tech Compliance-014/2026]