The Securities and Exchange Board of India (SEBI) has invited public comments on its proposed implementation of information technology (IT) and cybersecurity measures for subsidiaries of market infrastructure institutions (MIIs).
MIIs are SEBI-regulated financial entities, providing the systems necessary for capital market operations. The proposed changes provide greater clarity for MII subsidiaries to apply the IT and cybersecurity framework, which will strengthen oversight and implementation. The framework would help ensure that IT systems and activities conducted through MII subsidiaries are covered. cybersecurity and cyber resilience framework (CSCRF) for its regulated entities, along with IT and cybersecurity framework, mandates strict technology risk management. The risks have grown due to the increasing development and complexity of MII operations, their subsidiaries and regulated entities..
Subsidiaries often share technological infrastructure, applications, market data and other IT resources with their parent MIIs.
In the wake of such shared functions, concerns were raised with the SEBI that it was important to ensure MII subsidiaries were cybersecurity compliant. Hence, the proposed framework requires subsidiaries to meet the same compliance requirements as the parent MIIs.
However, this is not a blanket application on all subsidiaries. The IT and cybersecurity framework applies to subsidiaries that: conduct activities that MIIs undertake; handle the same data MIIs manage; and share infrastructure with MIIs.
Subsidiaries that do not meet this criteria, will not be subject to the same cybersecurity requirements as MIIs.
Any subsidiary that meets this criteria must be compliant with rules for cybersecurity, system audits, incident reporting, business continuity plan-disaster recovery and technology governance, etc.
MIIs can also seek exemptions for subsidiaries that only share infrastructure by submitting an exemption proposal to the SEBI. The exemption proposal must outline planned or existing compensatory controls to protect and ensure cybersecurity and IT resilience. The views of both the MII board and the standing committee on technology must accompany the exemption proposal.
Submit comments through the official SEBI website by 2 October 2026.

























