SEBI proposes extending IT, cyber security framework of MIIs to their arms
SEBI has proposed extending its IT and cybersecurity regulatory framework to the subsidiaries of Market Infrastructure Institutions. This move aims to ensure consistent oversight as these institutions increasingly rely on their arms for critical technical operations.
Why it matters
Strengthening cybersecurity regulations for financial infrastructure is vital to maintaining market stability and protecting sensitive data from systemic risks.
Markets watchdog Securities and Exchange Board of India (SEBI) on Friday (September 11, 2026) proposed extending the IT and cyber security framework of Market Infrastructure Institutions (MIIs) — comprising stock exchanges, depositories, and clearing corporations — to their subsidiaries to strengthen regulatory oversight.
While MIIs are governed by SEBI and operate in compliance with its IT and cybersecurity frameworks, the applicability and regulatory jurisdiction of these framework are not explicitly defined over their subsidiaries.
The move comes even as SEBI highlighted that there could be a case for MIIs to take services of their subsidiaries to carry out certain activities.
These subsidiaries may need to operate in close coordination with the parent MII and might use shared technology infrastructure, applications, market data or other critical IT resources.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in