The Multi Commodity Exchange of India Limited (MCX), on September 2, 2026, issued a circular regarding Standardisation Testing & Quality Certification (STQC) and other compliance requirements for vendors under SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF).
As per the CSCRF requirements, software services including SaaS/hosted services, COTS, customised COTS and in-house developed software are required to undergo application security and functional audits. COTS products empanelled by stock exchanges/depositories are also required to undergo application security testing and functional audit by an STQC auditor at the time of empanelment.
Accordingly, empanelled and prospective vendors covered by the framework are required to conduct application security testing and functional audits through an STQC auditor, in accordance with standard PR.IP.S15 of the CSCRF. MCX has advised its vendors and members to take note of the requirements and ensure compliance.
[Circular No. MCX/TECH/501/2026]