The Bombay Stock Exchange (BSE) on October 08, 2026, notified regarding the Cyber Audit on Half Yearly basis for Audit Period ending September 30, 2026.
Trading Members classified as Qualified REs and Mid-size/Small-size REs providing Internet-Based Trading (IBT) or algorithmic trading facilities must conduct a half-yearly cybersecurity audit under SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) for the audit period ending September 30, 2026. The cyber audit must be conducted by a CERT-In empanelled auditor, with the report submitted to the Exchange after approval by the respective IT Committee by December 31, 2026. The submission of the Action Taken Report (ATR)/Revalidation Report, confirming closure status, is due by March 31, 2027.
Trading Members must ensure that the audit covers 100% of critical systems and 25% of non-critical systems on a sample basis, with the sampling rationale and sample size documented in the audit report. Any unaudited period arising from a change in category must be covered in the next audit cycle. Entities holding multiple SEBI registrations must determine their RE category in accordance with the CSCRF criteria, obtain annual approval from the applicable governing authority, and ensure that the auditor validates the categorisation during the cyber audit.
[Notice No. 20261008-51]