Indian financial-security analysts monitor market-infrastructure systems in a cybersecurity operations centre.
Indian financial-security analysts monitor market-infrastructure systems in a cybersecurity operations centre.
01

SEBI proposes extending the control perimeter

SEBI published a consultation on applying market-infrastructure IT and cybersecurity requirements to qualifying subsidiaries. Same-day reporting described three possible scope tests: performing an MII-domain activity, handling data the parent MII would otherwise process, or sharing technology infrastructure. [1] [2] [3]

The reported control areas include cybersecurity, audits, incident reporting, business continuity, disaster recovery and technology governance. Public comments are due 2 October 2026. [2] [3]

02

Subsidiary boundaries can conceal shared operational risk

A separate legal entity can still share systems, identities, vendors, data stores and recovery dependencies with its parent. The consultation addresses the risk that regulated activity or sensitive market data sits outside the parent’s direct control perimeter. [1] [2]

Same-day coverage also described a possible exemption path involving compensating controls and views from the technology committee and board. That path is a proposal, not an exemption already granted to any subsidiary. [2] [3]

03

The next evidence is the final scope and control standard

Market-infrastructure institutions should watch the definition of qualifying activity, data responsibility, shared-service boundaries, audit coverage, reporting timelines and how group-level controls must be evidenced at subsidiary level. [1] [2] [3]

This is a consultation rather than a binding final rule. The official SEBI page displays the date without a clock time, so the visible 17:50 IST time uses the first clocked same-day corroboration from The Economic Times. [1] [2]