
SEBI Proposes Extending IT and Cyber Security Framework to Subsidiaries of Market Infrastructure Institutions
SEBI proposes extending IT and cyber security requirements to subsidiaries of market infrastructure institutions, strengthening cybersecurity and regulatory compliance.
The Securities and Exchange Board of India (SEBI) has issued a consultation paper proposing to extend its IT and Cyber Security Framework, currently applicable to Market Infrastructure Institutions (MIIs), to qualifying subsidiaries of stock exchanges, clearing corporations and depositories. Under the proposal subsidiaries that undertake MII-related activities, handle MII data, or share IT infrastructure with the parent institution would fall within the scope of the existing Cybersecurity and Cyber Resilience Framework (CSCRF) and related technology-governance requirements.
Subsidiaries meeting any of these three criteria would be required to comply with obligations relating to cyber security controls, system audits, incident reporting, business continuity and disaster recovery, and technology governance. SEBI has also proposed a proportionality-based exemption for subsidiaries that meet only the infrastructure-sharing criterion, subject to compensatory controls, with public comments invited until 2 October 2026.
The proposal reflects SEBI's focus on the interconnected nature of cyber risk within market infrastructure groups. As MIIs increasingly rely on subsidiaries for technology-driven functions and shared data systems, a cybersecurity gap at the subsidiary level could expose the parent institution, and by extension the wider securities market, to operational and systemic risk.
If implemented, affected MIIs and their subsidiaries would need to reassess existing governance structures, cyber controls and reporting lines. The move is in line with a broader regulatory trend, also visible in recent EU measures, of extending cybersecurity obligations to the wider corporate structures behind critical market functions.
📰 MINI HEADLINES
EU Cyber Resilience Act Reporting Obligations Go Live

The first mandatory reporting obligations under the EU Cyber Resilience Act (CRA) became applicable from 11 September 2026, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe cybersecurity incidents. The EU Agency for Cybersecurity (ENISA) has deployed the initial version of the Single Reporting Platform (SRP), the common electronic mechanism through which manufacturers, and from December 2027 open-source software stewards, must submit these notifications.
The regime establishes specific reporting timelines, requiring an early warning within 24 hours of becoming aware of an incident and a fuller notification within 72 hours. Once a report is submitted, the receiving national Computer Security Incident Response Team disseminates the information to other relevant CSIRTs across Member States while simultaneously notifying ENISA, so that other Member States are alerted to the same vulnerability without delay. The obligations make cybersecurity incident reporting a formal compliance requirement for digital-product supply chains, ahead of the CRA's broader cybersecurity requirements, which apply from 11 December 2027.
READ MORE -> EU Cyber Resilience Act Reporting Obligations Go Live
EU Data Act Access-by-Design Requirement Begins Applying to New Connected Products
A new phase of the EU Data Act has begun applying from 12 September 2026 to connected products and related services placed on the EU market after that date. Under Article 3(1) of the Regulation, such products must now be designed and manufactured so that the data generated through their use is, by default, easily and securely accessible to the user, free of charge, in a comprehensive, structured and, where applicable, machine-readable format.
The requirement extends the Data Act's access-by-design obligations to a wider set of connected products across sectors including consumer devices, vehicles and industrial equipment. Manufacturers and service providers will need to reassess product architecture, data-access mechanisms and contractual arrangements to ensure new offerings comply from the design stage rather than through retrofitted solutions, reinforcing the EU's broader push to give users greater control over data generated by their own devices.
READ MORE -> EU Data Act Access-by-Design Requirement Begins Applying to New Connected Products
ESMA Warns of Emerging Cyber Risks from Frontier AI in EU Financial Markets
The European Securities and Markets Authority (ESMA) has warned that frontier AI developments are creating new operational and cybersecurity risks for financial market infrastructures and key market participants. In its second risk monitoring report of 2026, published on 10 September, ESMA noted that while core market infrastructures, including central counterparties and settlement systems, have continued to function well even during periods of market stress, cyber risks are growing as advanced AI capabilities change the kinds of operational risks these institutions face.
The report identifies AI-linked threats to market infrastructures and key market players as area regulators are watching closely, alongside more familiar vulnerabilities such as stretched technology valuations and heightened geopolitical tensions. ESMA's findings point to a growing need for financial institutions and market infrastructures to strengthen cyber resilience, risk monitoring and operational controls in step with the pace of AI development, rather than treating AI risk as something to deal with later.
READ MORE:ESMA Warns of Emerging Cyber Risks from Frontier AI in EU Financial Markets




