SEBI has proposed extending the IT and Cyber Security framework β including the Cybersecurity and Cyber Resilience Framework (CSCRF) β currently applicable to Market Infrastructure Institutions (MIIs), to their subsidiaries. Under the proposal, a subsidiary would be covered if it carries out an activity that the MII is supposed to perform, handles data the MII is responsible for, or shares IT infrastructure with the MII. Subsidiaries meeting none of these three criteria would remain outside the framework, and MIIs may separately seek SEBI's exemption for a subsidiary that only shares infrastructure, subject to compensatory controls. The consultation paper is dated September 11, 2026, and public comments are invited until October 2, 2026.
Background: Why SEBI Is Consulting on This
SEBI has, from time to time, prescribed an IT framework for Market Infrastructure Institutions (MIIs) β stock exchanges, clearing corporations and depositories β to maintain uninterrupted securities market operations. Alongside this, SEBI has prescribed the Cybersecurity and Cyber Resilience Framework (CSCRF) to strengthen the cybersecurity posture of SEBI-regulated entities so they can anticipate, withstand, contain and recover from cyber incidents. Together, these frameworks mandate strict technology risk management for MIIs covering market data protection, operational continuity and cyber-attack prevention.
As MIIs have grown in scale and complexity, they increasingly rely on subsidiaries to carry out technology-driven and market-related activities. These subsidiaries β defined per Section 2(87) of the Companies Act, 2013 β often operate in close coordination with the parent MII and may use shared technology infrastructure, applications, market data or other critical IT resources. SEBI notes that while MIIs themselves are governed by the IT and cyber security framework, its applicability and regulatory jurisdiction over their subsidiaries is not explicitly defined. This consultation paper is intended to close that gap.
The concern was deliberated in SEBI's Technical Advisory Committee (TAC) at its meeting held on December 9, 2025, leading to the present proposal.
What Does SEBI Propose?
SEBI proposes that the IT and Cyber Security framework applicable to a parent MII should also extend to its subsidiary wherever the subsidiary meets any one of three criteria.
Where any one of these three conditions is met, the subsidiary would have to comply with all applicable requirements relating to cyber security, system audits, incident reporting, business continuity planning and disaster recovery (BCP-DR), and technology governance β the same obligations that apply to the parent MII.
π In Plain English: If a subsidiary is doing the MII's job, touching the MII's data, or plugged into the MII's IT systems, SEBI wants that subsidiary to follow the same cyber and IT rules as the MII itself β regardless of the fact that the subsidiary is a separate legal entity.
Subsidiaries Outside the Framework β and a Proportionality Exemption
Where a subsidiary meets none of the three criteria above, SEBI's proposal is that the IT and Cyber Security framework applicable to the parent MII would not apply to it. Illustrative categories such as investor education/training subsidiaries, facility management subsidiaries, independent financial services subsidiaries regulated separately, and HR/payroll subsidiaries fall outside scope under the paper's own examples (see the illustrative table below).
SEBI has also proposed a narrower carve-out for proportionality. Where a subsidiary meets only the shared-infrastructure criterion β and none of the other two β the MII may apply to SEBI for exemption from extending the framework to that subsidiary. Such an exemption request must include:
- Details of compensatory controls already in place, or proposed, to ensure the MII's own cyber and IT resilience is not compromised by the exemption; and
- The views of the Standing Committee on Technology (SCOT) and the Board of the MII.
Practical Example: Suppose an MII's subsidiary hosts only a non-critical internal application on infrastructure shared with the MII, with no access to trading, settlement or investor data. If the MII can demonstrate adequate compensatory controls and secures SCOT and Board sign-off, it may apply to SEBI to exclude that subsidiary from the full framework β this is illustrative of how the proposed mechanism could operate and does not represent a decided SEBI position on any specific case.
SEBI's Illustrative Scenarios (Annexure-A)
SEBI has provided a non-exhaustive set of illustrations clarifying how the applicability test would work in practice.
Source: SEBI Consultation Paper, Annexure-A. Illustrations are stated by SEBI to be non-exhaustive.
Who Is Affected?
- MIIs directly β stock exchanges, clearing corporations and depositories, which would need to map every subsidiary against the three-criteria test.
- Subsidiaries of MIIs β particularly technology, data-processing, cybersecurity-services and shared-infrastructure subsidiaries, which would inherit compliance obligations currently applicable only to the parent.
- IT, cybersecurity and compliance teams within MII groups β who would need to plan for system audits, incident reporting, BCP-DR and technology governance requirements extending group-wide.
- Subsidiaries with unrelated business lines β such as HR, facilities or education-focused entities β are expected to remain outside scope under the proposal as currently drafted.
What Should Practitioners Watch?
This is a consultation paper, not a notified regulation. No compliance obligation currently arises from it. Practitioners and MII groups should instead track the following:
- Comment deadline: Public comments and suggestions, with rationale, are invited until October 2, 2026, via SEBI's online public comments portal.
- Consultation process: Comments can be submitted through SEBI's web-based public comments form. In case of technical difficulty, comments may be emailed to Shri Darshil Bhatt, Deputy General Manager, and Shri Abhijeet Srivastava, Assistant General Manager, with the subject line "Applicability of IT and Cyber Security Framework of MIIs to their Subsidiaries."
- Provisions likely to matter most: The precise scope of "handling data which the MII is supposed to handle" and "sharing infrastructure" are likely to be the most contested points, since broad readings could pull in a wide range of shared-services subsidiaries.
- Preparatory action that does not assume finalisation: MII groups may find it useful to begin an internal inventory of subsidiaries against the three proposed criteria, and to assess which subsidiaries might qualify for the proportionality exemption, without treating either step as a compliance requirement at this stage.
Practical Implications If Finalised
If adopted as proposed, MII groups with technology, data-processing or shared-infrastructure subsidiaries would need to extend system audits, cyber incident reporting, BCP-DR planning and technology governance processes to those subsidiaries β effectively multiplying the compliance footprint of the existing IT and CSCRF frameworks across group entities rather than confining it to the MII alone. The proportionality exemption route offers a possible relief mechanism, but it requires MIIs to proactively demonstrate compensatory controls and secure internal sign-off from SCOT and the Board before approaching SEBI β meaning it is not an automatic carve-out.
Frequently Asked Questions
What is SEBI proposing in this consultation paper?
SEBI is proposing to extend the IT and Cyber Security framework, including the CSCRF, currently applicable to MIIs, to their subsidiaries that meet at least one of three criteria: performing an MII activity, handling MII data, or sharing infrastructure with the MII.
Is this already a binding rule?
No. This is a consultation paper open for public comment until October 2, 2026. It does not create any compliance obligation as of now.
Which subsidiaries would be covered under the proposal?
Subsidiaries that carry out an activity the MII is supposed to perform, handle data the MII is responsible for, or share technology infrastructure with the MII would be covered, based on SEBI's proposed three-criteria test.
Which subsidiaries would be excluded?
Subsidiaries meeting none of the three criteria β such as those focused on education/training, facility management, independent regulated financial services, or HR/payroll β would fall outside the framework under SEBI's illustrative examples.
Can an MII seek exemption for a subsidiary?
Yes, but only where the subsidiary meets solely the infrastructure-sharing criterion. The MII must apply to SEBI with details of compensatory controls and the views of its SCOT and Board.
By when must comments be submitted?
Public comments, along with rationale, must be submitted by October 2, 2026, through SEBI's online public comments portal.
What triggered this consultation paper?
SEBI's Technical Advisory Committee deliberated the lack of explicit clarity on the framework's applicability to MII subsidiaries at its meeting on December 9, 2025, leading to this proposal.
CorpLawUpdates Analysis
For MII groups, the immediate task is not compliance but mapping. The three-criteria test is activity-based rather than ownership-based, which means a subsidiary's regulatory exposure will depend on what it actually does for the parent MII, not merely on its corporate structure. Groups with technology or shared-services subsidiaries that straddle multiple business lines β serving both the MII and unrelated clients, for instance β are likely to face the most interpretive difficulty in applying the "handling data which the MII is supposed to handle" and "sharing infrastructure" criteria. This consultation paper is consistent with a broader regulatory trend of tightening technology governance and cyber resilience expectations across market infrastructure, and MII groups may find it useful to track whether SEBI issues related guidance on MII group-level governance as this proposal is finalised.
Document: Consultation Paper β "Applicability of IT & Cyber Security Framework of MIIs to their Subsidiaries"
Issuing Authority: Securities and Exchange Board of India (SEBI)
Date: September 11, 2026
Comment Deadline: October 2, 2026
Contact: Shri Darshil Bhatt, Deputy General Manager ([email protected]); Shri Abhijeet Srivastava, Assistant General Manager ([email protected])
Primary source: SEBI Public Comments Portal
Related reading: SEBI Consultation Paper β Strengthening Governance of MIIs
This article is for informational and educational purposes only and does not constitute legal or regulatory advice. Readers should verify the applicable primary regulatory source before taking action.


