MCX reminds members to submit FY 2025–26 VAPT Reports under SEBI Cybersecurity Framework

Jul 28, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Multi Commodity Exchange of India (MCX), on July 27, 2026, has reminded members to submit their Vulnerability Assessment and Penetration Testing (VAPT) Reports for FY 2025–26 in accordance with the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) and subsequent clarifications. 

The following has been stated:

Trading members categorized as Self-certification REs, Small-size REs, Mid-size REs, and Qualified REs (excluding QSBs) are required to complete VAPT through a CERT-In empanelled auditor by June 30, 2026 and submit the approved VAPT report by July 31, 2026. Where applicable, the Action Taken Report (ATR)/Revalidation Report must be submitted by November 30, 2026 after approval by the respective IT Committee.

For Qualified Stock Brokers (QSBs) and Regulated Entities identified as Protected Systems and/or Critical Information Infrastructure (CII) by the National Critical Information Infrastructure Protection Centre (NCIIPC), the existing half-yearly VAPT timeline remains unchanged. For the period October 01, 2025 to March 31, 2026, the VAPT report must be completed and submitted by June 30, 2026, while the ATR/Revalidation Report, if applicable, must be submitted by September 30, 2026.

MCX has also reiterated that, under the technology-based common submission mechanism, trading members registered with NSE and other exchanges (BSE, MSE, MCX, or NCDEX) and using algorithmic trading software are required to submit VAPT details only to NSE, which will share the submission with the other exchanges. Members not registered with NSE must continue to submit the prescribed VAPT details directly through the MCX Exchange Portal.

[Circular No. MCX/TECH/433/2026]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT