The Securities and Exchange Board of India (SEBI) on August 24, 2026, issued circular on Alignment of SEBI’s Cyber Incident Reporting Portal with FIRE format.
SEBI has streamlined the reporting of cybersecurity incidents by aligning its Cyber Incident Reporting Portal with the Financial Stability Board’s (FSB) Format for Incident Reporting Exchange (FIRE) Framework. The framework provides common information fields, standardised definitions and consistent classification of cyber incidents, enabling harmonised reporting across sectors and jurisdictions.
Under the existing CSCRF requirements, all Regulated Entities (REs) must report cyber incidents to SEBI within 6 hours through email at [email protected] and within 24 hours through the SEBI Incident Reporting Portal. The updated portal will support stage-wise reporting covering initial notification, interim updates and final closure, recognising that complete information may not be available at the time of initial reporting.
Compliance Impact: REs must ensure systems and processes are in place for timely cyber-incident reporting through the SEBI Cyber Incident Reporting Portal, including necessary amendments to applicable bye-laws, rules and regulations.
[Notification No. HO/(449)2026-ITD-5_DIV1/I/19448/2026]