Sebi Proposes Extending IT, Cybersecurity Framework To MII Subsidiaries (opens in a new tab)
Why readSEBI proposes pulling subsidiaries of market infrastructure institutions into the same IT and cybersecurity framework as their parents, which widens the compliance perimeter for Indian exchanges, depositories and clearing corporations.
SEBI has floated extending its IT and cybersecurity governance requirements to subsidiaries of market infrastructure institutions, rather than applying them only at parent level. For Indian capital-markets firms this means subsidiary entities that previously sat outside the CSCRF scope would need equivalent controls, audit and reporting. The item is a proposal at consultation stage, so the obligation is not yet fixed, but compliance teams at MIIs should be scoping the gap now.