**Executive Summary**
This circular, issued by the PFRDA on January 15, 2026, outlines the reporting requirements for intermediaries/Regulated Entities (REs) under the Information and Cyber Security Policy Guidelines-2024. It mandates compliance certificates and cyber incident reporting. The revised reporting format will come into effect for the FY 2025-26, with all reports submitted on or after April 1, 2026, required to be furnished in the revised format.
**Key Points / Main Content**
* **Scope and Classification:**
* Applies to all Points of Presence (PoPs) under NPS, NPS-Lite and APY, and all Non-Individual Retirement Advisers (RAs).
* Regulated Entities (REs) are classified into Category I (Pension Funds registered as PoPs) and Category II (PoPs including APY-SPs, Retirement Advisors excluding individuals).
* **Compliance Certificate:**
* Intermediaries/REs (PoPs and Non-Individual RAs) must submit a compliance certificate in the format of Annexure I & II.
* The certificate is to be submitted within 30 days from the end of the respective Financial Year (FY).
* **Cyber Incident Reporting:**
* In addition to reporting to CERT-IN, all PoPs including APY-SPs and Non-Individual RAs must report cyber incidents to PFRDA (reports-pop-@pfrda.org.in) with the subject 'Reporting of Cyber Incident'.
* Category I PoPs must also submit a quarterly report on cyber incidents to PFRDA, along with details of remedial actions taken.
* **Cyber Security Policy Submission:**
* Category I PoPs must submit their Board-approved Cyber Security Policy to the Authority within 30 days of the Board’s approval.
* **Reporting Format:**
* The revised reporting format applies from FY 2025-26 reports.
* Reports submitted on or after April 1, 2026, must use the revised format.
* Circular No. PFRDA/2020/13/SUP-POP/2 dated 21st April 2020 is superseded.
**Impact Analysis**
**Category I PoPs (Pension Funds registered as PoPs):**
* **Impact:** Required to submit compliance certificates, report cyber incidents to PFRDA, submit a quarterly report on cyber incidents with remedial actions, and submit Board-approved Cyber Security Policy to PFRDA.
* **Action Required:** Prepare and submit the compliance certificate, report cyber incidents as per the guidelines, submit quarterly reports, and submit the Board-approved Cyber Security Policy to PFRDA.
**Category II PoPs (PoPs including APY-SPs, Retirement Advisors excluding individuals):**
* **Impact:** Required to submit compliance certificates and report cyber incidents to PFRDA.
* **Action Required:** Prepare and submit the compliance certificate and report cyber incidents as per the guidelines.
**Non-Individual Retirement Advisors (RAs):**
* **Impact:** Required to submit compliance certificates and report cyber incidents to PFRDA.
* **Action Required:** Prepare and submit the compliance certificate and report cyber incidents as per the guidelines.
Key Entities Referenced
Pension Fund Regulatory and Development Authority (PFRDA): The regulatory body issuing the circular and responsible for the Information & Cyber Security Policy Guidelines.
Information & Cyber Security Policy Guidelines-2024: The set of guidelines for intermediaries/Regulated Entities (REs) regarding information and cyber security issued by PFRDA.
Point of Presence (PoPs): Entities that are required to comply with the circular and the associated Information & Cyber Security Policy Guidelines-2024 under NPS, NPS-Lite and APY.
APY-SPs: APY Service Providers, specifically mentioned as needing to comply and report cyber incidents.
CERT-In: Indian Computer Emergency Response Team, to which cyber incidents are to be reported.
Circular
Circular No.: PFRDA/2026/05/SUP-PoP/01 Date:15 January, 2026
To,
All Point of Presence (PoPs) under NPS, NPS-Lite and APY
All Non-Individual Retirement Advisers (RAs)
Subject: Reporting requirement under Information and Cyber Security Policy Guidelines
issued by PFRDA
This has reference to Circular no. PFRDA/2024/14/ICS/01 dated 1st August 2024 on the subject
“Information & Cyber Security Policy Guidelines-2024 for intermediaries/Regulated Entities
(REs)” issued by the PFRDA. For the purpose of these guidelines, the intermediaries/Regulated
Entities (REs) are classified into two categories as (i) Category I - consisting of Pension Funds that
are registered as Point of Presence (PoPs) (ii) Category II - consisting of Point of Presence (PoPs)
including APY-SPs, Retirement Advisors excluding individuals.
2. In compliance with the said Guidelines, intermediaries/REs (PoPs and Non-Individual RAs) shall
submit the certificate of compliance as per the format enclosed as Annexure I & II, for the
respective Financial Year (FY), within 30 days from the end of the said FY.
3. Further, in addition to reporting to CERT-IN (in-case of any Cyber-incident), all PoPs including
APY-SPs and Non-Individual RAs shall mandatorily report cyber incidents mentioned in the
Guidelines dated 1st August 2024 to the PFRDA at reports-pop-@pfrda.org.in with the subject
‘Reporting of Cyber Incident’ in accordance with the reporting timeline and format outlined in
the said Guidelines. Additionally, category I PoPs shall also required to submit the report on the
cyber incidents to PFRDA on quarterly basis, along with the details of remedial actions taken.
4. Category I PoPs shall be required to submit their Cyber Security Policy which has been reviewed
and approved by the Board to the Authority within 30 days of such approval by the Board of the
regulated entity (RE).
5. The revised reporting format shall come into effect from the report applicable for the FY 2025-
26 and will supersede Circular No. PFRDA/2020/13/SUP-POP/2 dated 21st April 2020.
Accordingly, all reports submitted on or after 1st April 2026 shall be required to be furnished in the
revised format.
(Ashish Kumar)
Chief General Manager
Encl: Annexure I & II
Page 1 of 3
5th Floor, Tower E, World Trade Center, Nauroji Nagar, New Delhi – 110 029
Phone: 011 - 26517501, 26517503. website: www.pfrda.org.inAnnexure I
Cyber Security Compliance certificate for Category I PoPs the FY _________
(To be submitted by PoP through modes as specified by the Authority from time to time within 30
calendar days from the end of the FY)
This is to certify that _________________________________ (Name of PoP) registered vide Reg.
No. __________________ with Pension Fund Regulatory and Development Authority (PFRDA) has:
Adopted and complied with the Information and Cybersecurity Policy approved by the Board and has
adhered to the Information and Cybersecurity Policy Guidelines issued by PFRDA, for the protection
of data, information, and IT systems.
Further, a Cyber Security Audit was conducted in accordance with the guidelines issued by PFRDA
and all remedial actions recommended in the audit report have been duly implemented. Cyber incidents,
if any, were reported to CERT-In and PFRDA, in terms of the Information and Cybersecurity Policy of
PFRDA. The PoP has also submitted the report on the cyber incidents to PFRDA on quarterly basis,
along with the details of remedial actions taken.
It is further submitted that the Information and Cybersecurity Policy was approved by the board on
_____________ and the same was last reviewed on _______________. The reviewed and approved
Cyber Security Policy has been submitted to PFRDA within 30 days of such approval by the Board of
the regulated entity (RE).
Additionally, the details of the members of Information and Cyber Security Risk Management
Committee (ICSRM) is as mentioned below:
S.No Name of the Member Designation
1
2
3
4
The changes in the constitution of the member of ICSRM committee, if any has duly been reported to
the PFRDA.
Name of CISO/Compliance Officer:
Designation:
Mobile No.:
Email ID:
Date:
Place Signature of CISO/Compliance officer
Page 2 of 3Annexure II
Cyber Security Compliance certificate for category II PoPs for the FY ________
(To be submitted by PoP through modes as specified by the Authority from time to time within 30
calendar days from the end of the FY)
This is to certify that _________________________________ (Name of PoPs including APY-SPs
/non-individual RAs) registered vide Reg. No. __________________ with Pension Fund Regulatory
and Development Authority (PFRDA) has:
Adopted and complied with the Information and Cybersecurity Policy approved by the Board and has
adhered to the Information and Cybersecurity Policy Guidelines issued by PFRDA or the respective
Principal Financial Sector Regulator (RBI / SEBI / IRDAI / NHB), as applicable, for the protection of
data, information, and IT systems.
Further, a Cyber Security Audit was conducted in accordance with the guidelines issued by the
respective Principal Financial Sector Regulator, and all remedial actions recommended in the audit
report have been duly implemented. Cyber incidents, if any, were reported to CERT-In and PFRDA,
and were also reported to the respective Principal Financial Sector Regulator, wherever applicable, in
terms of the Information and Cybersecurity Policy of such Principal Financial Sector Regulator.
Name of CISO/Compliance Officer:
Designation:
Mobile No.:
Email ID:
Date:
Place Signature of CISO/Compliance officer
Page 3 of 3