The International Financial Services Centres Authority (IFSCA) on March 10, 2026, issued the amendment to the Circular titled “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs”.
The following has been stated:
• The amendment provides a three-year exemption from the cybersecurity requirements for specific categories of regulated entities, including branches of regulated Indian or foreign entities, entities providing services only to their group companies, such as Global In-House Centres, and entities with fewer than ten employees.
• During the exemption period, such entities shall adopt the cyber security framework and information security policy of their parent entity, designate the parent entity’s CISO as the responsible officer, ensure the parent entity is regulated in its home jurisdiction, submit an annual certification on implementation of necessary systems within 90 days of each financial year, and provide an annual cyber security audit report to IFSCA.
• The amendment further extends a similar three-year exemption to foreign universities established in the IFSC, newly incorporated standalone entities without a parent organization, and credit rating agencies. However, these entities shall ensure that their designated officer certifies that adequate cybersecurity measures proportionate to their risk exposure have been implemented and submit such certification to IFSCA within 90 days after the end of each financial year.
[Notification no. - IFSCA-CSD0MSC/1/2026-DCS]