Home India International Financial Services Centres Authority Amendment to the Circular titled “Guidelines on Cyber Securi...
Date: 2026-03-10 Category: Not Applicable State: Union Government Country: India

Amendment to the Circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs”

Issued by International Financial Services Centres Authority · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task
Official Source Record View Original Source →
See Full Document Text
CIRCULAR IFSCA-CSD0MSC/1/2026-DCS March 10, 2026 To, All Regulated Entities in the International Financial Services Centres (IFSCs) Dear Madam/Sir, Sub: Amendment to the Circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs” 1. Reference is drawn to the circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs” (hereinafter referred to as the “Cyber Security Circular”), dated March 10, 2025, issued by the Authority. 2. Following the issuance of the Cyber Security Circular, the Authority has received representations from various Regulated Entities (REs) highlighting the challenges faced in complying with certain provisions of the said Circular. 3. The Authority considered the representations received from the REs and has decided to amend the Cyber Security Circular as follows: i) For para 21 of the said Circular, the following para shall be substituted, namely:- “The following categories of REs are exempted from the requirements mentioned in this Circular for a period of three (3) years from the date of its issuance: a) The RE operating in the form of a branch of a regulated Indian or foreign entity; 1 | Pageb) The RE providing services to its group entities only e.g. Global In-House Centre (GIC); and c) The RE having less than 10 employees.” ii) For para 22 of the said Circular, the following para shall be substituted, namely:- “The REs specified in para 21 shall comply with the following conditions during the exempted period: a) The RE shall adopt the Cyber Security and Cyber Resilience framework and IS Policy of its parent entity or the holding company of such parent entity; b) The CISO of the parent entity shall act as the Designated Officer for the RE; c) The parent entity or the holding company of such parent entity of the RE, in India or overseas, must be regulated by a regulator/ Government Body in its home jurisdiction; d) The Designated Officer of the RE shall certify that all the necessary systems/processes, in line with these Guidelines, have been put in place, and shall submit the same to the respective supervision Department/ Division of IFSCA within ninety (90) days of the end of each financial year; and e) The RE shall submit the annual cyber security audit report to IFSCA.” iii) After para 22 of the said Circular, the following para shall be inserted, namely:- “23. The following categories of REs are exempted from the requirements mentioned in this Circular for a period of three (3) years from the date of its issuance: a) Foreign university set up in the IFSC; b) The RE which has been established as newly incorporated standalone entity within the IFSC and does not have any parent organisation; and c) Credit Rating Agency. 2 | PageProvided that the Designated Officer of such RE shall, during the exempted period, certify that the RE has implemented adequate cybersecurity measures proportionate to its risk exposure, and shall submit the same to the respective supervision Department/ Division of IFSCA within ninety (90) days of the end of each financial year.” 4. This Circular is issued in exercise of powers conferred by Section 12 and 13 of the International Financial Services Centres Authority Act, 2019, to develop and regulate the financial services market in the International Financial Services Centre, and shall come into effect immediately. A copy of this circular is available on the website at www.ifsca.gov.in Yours Faithfully, Praveen Kamat General Manager & Chief Information Security Officer Division of Cyber Security praveen.kamat@ifsca.gov.in Tel : +91- 079 - 61809820 3 | Page

Continue your research