PFRDA issued a circular regarding the reporting requirement under the Information and Cyber Security Policy Guidelines

Jan 16, 2026 | by TeamLease RegTech Legal Research Team

A |  A

Free Legal updates for the week 00


Labour ComplianceThe Pension Fund Regulatory and Development Authority (PFRDA) on January 15, 2026, issued a circular regarding the reporting requirements under the Information and Cyber Security Policy Guidelines.

The following has been stated: -

•PFRDA has classified intermediaries/Regulated Entities into Category I (Pension Funds registered as PoPs) and Category II (PoPs including APY-SPs and Non-Individual Retirement Advisors).

•All such entities must submit an annual cybersecurity compliance certificate within 30 days of the end of each financial year.

•Cyber incidents must be reported to PFRDA in addition to CERT-IN, with Category I PoPs also submitting quarterly incident and remedial action reports and Board-approved cybersecurity policies.

•The revised reporting format applies from FY 2025–26 and is mandatory for all reports submitted on or after April 01, 2026, superseding earlier guidelines.

[Circular No.: PFRDA/2026/05/SUP-PoP/01]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT