CDSL Quarterly Cyber Incident Reporting by Depository Participants

Oct 07, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Central Depository Services (India) Limited (CDSL) on October 01, 2026, directed all Depository Participants (DPs) to submit quarterly cyber incident reports in accordance with SEBI Circular No. SEBI/HO/MIRSD/TPD/P/CIR/2022/93 dated 30 June 2022 and the relevant CDSL communiqué. The reporting requirement covers all cyber-attacks, threats, incidents and breaches experienced by DPs.

All DPs must submit the Quarterly Cyber Incident Report through the Audit Web Portal within 15 days from the end of each quarter, irrespective of whether any cyber incident occurred. Where no incident has occurred, DPs must submit a Nil Report by selecting “No” under the field “Cyber-attack/Breach observed in the Quarter.” Failure to submit a Nil Report will be treated as non-submission.

The deadline for the report covering Q2 (July–September 2026) is 15 October 2026. Failure to submit the report within the prescribed timeline will be treated as non-compliance and attract the applicable penalty under CDSL Communiqué No. CDSL/AUDIT/DP/POLCY/2025/105 dated 12 February 2025. Submission instructions are provided in Annexure A. 

[CDSL/IS/DP/POLCY/2026/685]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

✦ NEW  ·  AI ASSISTANT