SEBI Aligns Cyber-Incident Reporting Portal with FSB’s FIRE Framework
Mumbai, 24 August 2026: The Securities and Exchange Board of India has aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange, or FIRE, to standardise how securities-market entities report cyber incidents.
Circular: HO/(449)2026-ITD-5_DIV1/I/19448/2026
Publication date: 24 August 2026
Issued under: Section 11(1), SEBI Act, 1992
What changes under the circular
FIRE introduces common information fields, standard definitions and consistent classification of incident attributes. SEBI’s portal will now collect reports in stages across the incident lifecycle: initial reporting, intermediate updates and final closure. The staged approach recognises that all facts may not be available when an incident is first detected.
Regulated entities must use the SEBI Cyber Incident Reporting Portal and put in place the systems needed to implement the circular, including amendments to relevant bye-laws, rules and regulations where necessary.
Existing reporting deadlines remain relevant
The circular records SEBI’s existing CSCRF requirement that regulated entities report a cyber incident by email within six hours and through the SEBI Incident Reporting Portal within 24 hours. The new FIRE alignment standardises the information structure and lifecycle updates; it should be read with the applicable cybersecurity and cyber-resilience circulars and later SEBI updates.
Entities covered
The addressees include stock exchanges, clearing corporations, depositories and participants, alternative investment funds, mutual funds and asset management companies, intermediaries such as brokers, merchant bankers, investment advisers and research analysts, credit-rating agencies, custodians, portfolio managers, registrars, KYC registration agencies and other listed regulated entities.
Practical significance
Covered entities should review incident-response playbooks, internal escalation paths and data-capture fields so that both rapid notification and subsequent lifecycle reporting can be completed consistently. Governance teams should also map the circular against existing CSCRF obligations.
Read the official SEBI circular and document.
This report is for legal information only and does not constitute legal advice.