The Multi Commodity Exchange of India Limited (MCX), on September 30, 2026, issued a circular requiring its trading members to report cyber security incidents for the quarter ending September 30, 2026. The requirement is issued in continuation of earlier MCX circulars and the Master Circular dated April 30, 2026, and applies whether a cyber security incident occurred or did not occur during the quarter.
Trading members are required to submit the cyber security incident details through the MCX Member Portal. The circular also refers to the technology-based mechanism for sharing common submissions among exchanges, under which trading members registered with NSE as well as BSE, MSE, MCX or NCDEX are required to submit their cyber security incident details to NSE, which will share the submission with the respective exchange(s).
Members who are not registered with NSE will continue to submit their cyber security incident details directly to MCX through the existing process. The requirement is intended to ensure periodic reporting of cyber security incidents in accordance with the Exchange's applicable Rules, Bye-Laws and Business Rules.
[Circular No. MCX/TECH/554/2026]