SEBI Proposes Extending IT, Cyber Security Framework To MII Subsidiaries
Shilpa Soman
11 Sept 2026 5:13 PM IST

The Securities and Exchange Board of India (SEBI) has proposed extending the Information Technology and Cyber Security Framework applicable to Market Infrastructure Institutions (MIIs) to their subsidiaries that undertake certain MII-related activities.
The consultation paper seeks feedback on extending MIIs' IT and Cyber Security Framework to their subsidiaries, particularly as MIIs increasingly use subsidiaries for technology-driven and market-related activities involving shared IT infrastructure, applications, market data and other critical resources.
Under the proposal, the framework would cover subsidiaries that perform MII-related activities, handle MII data or share IT infrastructure with the MII. These subsidiaries would have to follow requirements on cyber security, system audits, incident reporting, BCP-DR and technology governance.
The framework would not apply to subsidiaries which do not meet any of these three criteria.
SEBI has also proposed an exemption in the interest of proportionality where a subsidiary meets only the infrastructure-sharing criterion. In such cases, the MII may seek exemption from SEBI, subject to details of compensatory controls to ensure that MII's cyber and IT resilience are not affected.
The regulator has invited public comments on the proposal by October 2, 2026.
