The Central Depository Services (India) Limited (CDSL) on March 30, 2026, issued a communiqué mandating quarterly cyber incident reporting by Depository Participants (DPs), in continuation of earlier guidelines issued by Securities and Exchange Board of India (SEBI) and CDSL.
DPs are required to report all cyber-attacks, threats, incidents, and breaches through CDSL’s online audit web portal. The reporting has been made mandatory on a quarterly basis, and submissions must be completed within 15 days from the end of each quarter to ensure timely monitoring and regulatory compliance.
For the quarter ending March 2026 (Q4), the deadline for submission is April 15, 2026. Any failure to comply will be treated as non-compliance and may attract penalties as per the applicable CDSL audit guidelines.
[CDSL/IS/DP/POLCY/2026/221]