The Securities and Exchange Board of India (SEBI) on September 11, 2026, issued the Consultation Paper on Applicability of IT and Cyber Security Framework of MIIs to their Subsidiaries.
The following has been stated:
• SEBI has proposed extending the IT and Cyber Security Framework applicable to Market Infrastructure Institutions (MIIs) to their subsidiaries where the subsidiary
o (i) performs activities directly contributing to the MII’s regulated domain,
o (ii) handles data that the MII is responsible for, or
o (iii) shares IT infrastructure with the MII. Covered subsidiaries would be required to comply with requirements relating to cybersecurity, system audits, incident reporting, BCP-DR and technology governance.
• Subsidiaries not meeting any of these criteria would be exempt. For subsidiaries sharing only IT infrastructure, an MII may seek SEBI exemption by demonstrating adequate compensatory controls and obtaining the views of its SCOT and Board.
• Public comments may be submitted by October 2, 2026.