SEBI has aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange (FIRE) framework. The change standardizes the way cyber incidents are described and classified and enables reporting to continue through subsequent stages until the incident is closed.
SEBI Aligns Cyber Incident Reporting Portal With FIRE Format: What Regulated Entities Need to Know
SEBI has issued Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026 dated 24 August 2026 to align its Cyber Incident Reporting Portal with the Financial Stability Board’s FIRE framework. The immediate significance is not a replacement of the existing reporting channel, but a more standardized and structured process for reporting cyber incidents across their lifecycle.
For regulated entities, the practical point is straightforward: the existing cyber incident reporting obligations under SEBI’s Cybersecurity and Cyber Resilience Framework remain relevant, while the Incident Reporting Portal now follows a FIRE-based reporting structure with standardized fields, definitions, classifications and staged updates.
Quick Answer: What Did SEBI Change?
SEBI has aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s FIRE framework. The portal now supports a structured incident-reporting approach based on common information fields, standardized definitions and consistent classification of incident attributes.
The portal is also designed for staged reporting. A regulated entity can submit the information available at the time of the initial report and continue providing intermediate updates until the incident reaches final closure.
The circular does not state that the existing 6-hour email and 24-hour portal reporting timelines have been replaced. Instead, it builds a more structured FIRE-aligned reporting process around the existing SEBI cyber incident reporting framework.
What Changed Under SEBI’s 24 August 2026 Circular?
The circular’s focus is therefore broader than adding another reporting form. It is about making cyber incident information more consistent, comparable and usable during the full incident lifecycle.
What Is the FIRE Framework?
FIRE stands for Format for Incident Reporting Exchange. The framework was developed by the Financial Stability Board (FSB) to support structured reporting of financial-sector incidents.
According to SEBI’s circular, FIRE uses common information fields, standardized definitions and consistent classification of incident attributes. The objective is to promote greater harmonization across sectors and jurisdictions.
Different regulated entities may describe similar cyber incidents in different ways. FIRE creates a common reporting language so that important incident information can be categorized more consistently.
What Are the Existing Cyber Incident Reporting Timelines?
SEBI’s circular specifically records that its existing CSCRF framework already requires regulated entities to report cyber incidents through two channels.
Cyber incidents must also be reported through SEBI’s Incident Reporting Portal within 24 hours.
These timelines are stated in the circular as existing CSCRF requirements. The 24 August 2026 circular does not expressly announce a revised reporting deadline.
How Will Incident Reporting Work After the FIRE Alignment?
The revised portal is designed to accommodate the fact that a cyber incident evolves over time and that all information may not be available immediately.
The entity reports the incident when it becomes aware of it, using the information available at that stage.
Additional information can be submitted as the incident investigation and response progress.
Reporting continues until the incident reaches its final closure stage.
This lifecycle approach addresses a practical difficulty in cyber incident response: the organization may know that an incident has occurred before it knows its complete scope or consequences. The portal is therefore designed to accept progressively updated information rather than requiring every fact to be known at the first submission.
Who Must Comply With the Revised Reporting Approach?
The circular refers to SEBI-regulated entities (REs) and requires them to report cyber incidents through SEBI’s Cyber Incident Reporting Portal. The circular is addressed to a broad group of securities-market entities, including:
The circular itself should be read for the precise scope applicable to a particular regulated entity. It does not create a separate exemption list in this document.
Why Is SEBI Moving to the FIRE Format?
SEBI identifies the rapid growth of technology in the securities market and the increasing frequency and sophistication of cyber incidents as the backdrop for the measure. Prompt reporting is intended to support containment, mitigation and stronger defences.
The FIRE alignment adds another layer: harmonization of the information itself. Common fields, common definitions and consistent classification allow incident data to be organized in a more comparable way across sectors and jurisdictions.
The circular also indicates that improved categorization can help identify where cyber incidents occur and in which countries, supporting better preparedness.
What Should Regulated Entities Do Now?
The circular expressly requires regulated entities to take necessary steps to put systems in place for implementation. It also states that necessary amendments should be made to relevant bye-laws, rules and regulations, where applicable.
Compliance Checklist
Ensure internal teams can initiate cyber incident reporting promptly once an incident is identified.
Existing CSCRF reporting requirements cited in the circular require email reporting within 6 hours and portal reporting within 24 hours.
Internal processes should support initial reporting, subsequent updates and final closure rather than treating incident reporting as a one-time event.
Review how incident records are captured internally so that common fields, definitions and classifications can be supplied consistently.
Where relevant, examine bye-laws, rules and regulations and make the amendments necessary to implement the circular.
The circular specifically directs regulated entities to consider subsequent SEBI updates relating to cybersecurity and cyber resilience.
Practical note: The circular does not name a specific internal job title or department responsible for these actions. The allocation of responsibility among cybersecurity, information technology, compliance, risk and management teams is therefore an internal governance decision rather than a prescribed responsibility in this circular.
Does the FIRE Alignment Change the 6-Hour and 24-Hour Deadlines?
No change to those timelines is expressly stated in this circular. SEBI describes the existing CSCRF requirement as requiring cyber incidents to be reported to [email protected] within 6 hours and through the SEBI Incident Reporting Portal within 24 hours.
The new measure changes the structure of portal reporting by aligning it with FIRE and enabling reporting throughout the incident lifecycle.
Is the Initial Report Expected to Contain Every Detail?
No. The circular expressly recognizes that certain information may not be available when the incident is initially reported. The portal therefore facilitates intermediate updates so that information can be added as it becomes available.
A regulated entity may identify a cyber incident before it has determined the full scope of affected systems or the complete nature of the impact. The initial report should use the information available at that stage, while subsequent portal updates can capture information established during investigation and response.
Does This Circular Replace SEBI’s Cybersecurity Framework?
The circular does not state that the Cybersecurity and Cyber Resilience Framework (CSCRF) is replaced. Instead, SEBI states that this circular should be read in conjunction with applicable SEBI circulars, including the Cybersecurity and Cyber Resilience Framework, as well as subsequent SEBI updates.
This means the 24 August 2026 circular should be treated as part of the wider SEBI cybersecurity and cyber incident reporting framework rather than as a standalone replacement for that framework.
[INTERNAL LINK: SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)]
When Does the Circular Take Effect?
The circular is dated 24 August 2026. However, the document does not specify a separate effective date or state a distinct transition period.
It requires regulated entities to take the necessary steps for implementation, including amendments to relevant bye-laws, rules and regulations where applicable. Accordingly, entities should not assume that a later commencement date exists unless a separate SEBI communication provides one.
What Is the SEBI Cyber Incident Reporting Portal?
SEBI’s circular identifies the Cyber Incident Reporting Portal as the portal through which regulated entities are required to report cyber incidents. The circular states that the portal can be accessed by logging into:
The circular therefore places the portal at the center of the structured reporting process, while the existing email notification requirement remains relevant under the CSCRF guidance cited in the document.
Frequently Asked Questions
1. What did SEBI announce on 24 August 2026?
SEBI announced the alignment of its Cyber Incident Reporting Portal with the Financial Stability Board’s FIRE framework through Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026.
2. What does FIRE stand for?
FIRE stands for Format for Incident Reporting Exchange. The framework was developed by the Financial Stability Board (FSB) to support structured incident reporting.
3. What are the current cyber incident reporting timelines mentioned by SEBI?
SEBI states that regulated entities must report cyber incidents to [email protected] within 6 hours and through the SEBI Incident Reporting Portal within 24 hours under the existing CSCRF requirements.
4. Does the new circular introduce a new reporting deadline?
No new reporting deadline is expressly introduced in the circular. The document describes the existing 6-hour email and 24-hour portal requirements and focuses on aligning the portal with FIRE.
5. Can a regulated entity update a cyber incident after the first report?
Yes. The portal is designed to support initial reporting, intermediate updates and final closure as the incident progresses.
6. What happens if complete information is not available initially?
The circular recognizes that some information may not be available at the initial reporting stage. Subsequent updates can be provided as additional information becomes available.
7. Who is covered by the circular?
The circular is addressed to SEBI-regulated entities across a broad range of securities-market intermediaries and institutions, including AIFs, mutual funds and AMCs, stock exchanges, stock brokers, depositories, custodians, merchant bankers, portfolio managers, RTAs and other entities listed in the circular.
8. Does the circular replace the Cybersecurity and Cyber Resilience Framework?
No. SEBI states that this circular should be read together with applicable SEBI circulars, including the Cybersecurity and Cyber Resilience Framework and subsequent updates.
9. Does the circular specify an effective date?
No separate effective date is specified in the circular. The circular is dated 24 August 2026 and requires regulated entities to take necessary implementation steps.
10. Does this circular prescribe a penalty for non-compliance?
No specific penalty is prescribed in this circular. The document focuses on the reporting framework, implementation requirements and continued coordination with SEBI’s cybersecurity framework.
CorpLawUpdates Analysis
The most important practical change is not simply the adoption of the term FIRE. It is the move toward treating cyber incident reporting as a continuing information process rather than a single submission.
For compliance teams, this changes the operating question from “Have we submitted the incident report?” to “Can we maintain accurate reporting throughout the incident lifecycle?” That distinction matters because the first report may necessarily be incomplete, while the organization’s understanding of the incident can change rapidly during investigation and containment.
The FIRE structure also makes internal data discipline more important. Organizations may need to review how cyber incidents are recorded internally so that the information required for standardized fields, definitions and classifications can be produced consistently when reporting through the portal.
Another important point is timing. The circular does not provide a new grace period or a revised 6-hour / 24-hour deadline. Until a separate SEBI communication says otherwise, regulated entities should continue to treat the existing reporting timelines cited in the circular as operational requirements.
Finally, implementation should not be viewed only as an IT exercise. The circular requires systems for implementation and contemplates amendments to applicable bye-laws, rules and regulations. The practical response therefore sits at the intersection of cybersecurity, compliance, governance and regulatory reporting.
Source Note
Document: SEBI Circular — “Alignment of SEBI’s Cyber Incident Reporting Portal with FIRE format”
Issuing authority: Securities and Exchange Board of India (SEBI)
Reference: HO/(449)2026-ITD-5_DIV1/I/19448/2026
Legal authority: Issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992.
Date: 24 August 2026
Signatory: Mamta Roy, Deputy General Manager
Source: SEBI website, Legal → Circulars. The circular itself identifies www.sebi.gov.in as the official website.
Primary-source note: The above article is based on the uploaded SEBI circular.
This article is for informational and educational purposes only and does not constitute legal or regulatory advice. Readers should verify the applicable primary regulatory source before taking action.


