The Pension Fund Regulatory and Development Authority (PFRDA) on January 15, 2026, issued the notification regarding the Reporting requirement under Information and Cyber Security Policy Guidelines issued by PFRDA.
The following has been stated namely: -
• All intermediaries/REs must submit a Certificate of Compliance in the prescribed Annexure I & II formats for each financial year within 30 days of the end of the FY.
• In addition to reporting to CERT-In, all PoPs (including APY-SPs) and Non-Individual RAs must mandatorily report cyber incidents to PFRDA at the specified email ID, following the timelines and formats in the Guidelines, Category I PoPs must also submit quarterly cyber incident reports with remedial actions.
• Category I PoPs are required to submit their Board-approved Cyber Security Policy to PFRDA within 30 days of Board approval.
• The revised reporting format will apply from FY 2025–26, superseding the April 21, 2020 circular, and all reports submitted on or after April 01, 2026 must follow the revised format.
[Notification No. PFRDA/2026/05/SUP-PoP/01]