Current Affairs
economyUPSCState PCSIBPSSBIRBI Grade BSEBI Grade ANABARDSSCLIC

SEBI IT Resilience Index for Market Infrastructure Institutions: Nine-Parameter Framework and Implications for India's Capital Markets

27 August 2026 10 min read 49 SEBI Circular
Why in news

The Securities and Exchange Board of India (SEBI) issued a circular on August 24, 2026 mandating a standardised IT Resilience Index (ITRI) for all Market Infrastructure Institutions — stock exchanges, depositories and clearing corporations — rated on nine parameters including availability and security, to be operationalised within six months.

At a glance

Why in News

SEBI issued circular (Aug 24, 2026) mandating the IT Resilience Index (ITRI) for all Market Infrastructure Institutions — stock exchanges, depositories and clearing corporations.

What Changed

A standardised nine-parameter index replaces ad-hoc IT audits; MIIs must operationalise by February 28, 2027 and submit first report for half-year ending September 30, 2026.

Key Parameters

Availability (20%) and Security (20%) carry highest weight; others include Integrity, Governance, Business Continuity, Reliability & Monitoring, and Modularity & Flexibility (10% each).

Regulatory Basis

SEBI Act, 1992 (Sections 11, 11B); SCRA, 1956; Union List Entry 48; aligns with CPMI-IOSCO Principles for Financial Market Infrastructures.

Timeline

1992
SEBI Act, 1992 enacted
SEBI given statutory status; MIIs brought under regulatory oversight
1996
Depositories Act, 1996
NSDL and CDSL established as regulated depositories
2023
SEBI CSCRF
Cybersecurity and Cyber Resilience Framework issued for regulated entities
March 2026
Consultation Paper on ITRI
SEBI sought public comments on the nine-parameter resilience index framework
August 24, 2026
Final ITRI Circular
Mandatory IT Resilience Index introduced for all MIIs
September 30, 2026
First ITRI Submission
MIIs must submit ITRI score for the half-year ending this date
February 28, 2027
Full Operationalisation Deadline
All MIIs must have the ITRI framework fully operational

Why in News

The Securities and Exchange Board of India (SEBI) issued a circular on August 24, 2026 (Ref: HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026) mandating the introduction of a standardised IT Resilience Index (ITRI) for Market Infrastructure Institutions (MIIs). The index measures the operational and technological resilience of stock exchanges, depositories and clearing corporations through nine quantifiable parameters, with the first formal submission required for the half-year ending September 30, 2026.

Background

Market Infrastructure Institutions are the critical backbone of India's capital markets. They include:

  • Stock Exchanges: BSE (Bombay Stock Exchange, est. 1875 — Asia's oldest) and NSE (National Stock Exchange, est. 1992)
  • Depositories: NSDL (National Securities Depository Limited) and CDSL (Central Depository Services Limited)
  • Clearing Corporations: NSCCL (NSE Clearing), ICCL (Indian Clearing Corporation), and MCX-SX Clearing

As trading volumes have grown — NSE handles over 90% of India's equity derivatives volume — the technological reliability of MIIs has become a systemic risk concern. Disruptions at these nodes can cascade across brokers, investors and settlement systems.

Regulatory Timeline

SEBI had previously issued the Cybersecurity and Cyber Resilience Framework (CSCRF) in August 2023, applicable broadly to regulated entities. The IT Resilience Index builds upon that foundation but creates a quantitative, comparable scorecard specifically for MIIs. A consultation paper seeking public comments was released in March 2026, and the final circular follows stakeholder feedback.

Current Developments

The August 24, 2026 circular introduces the following key measures:

  1. Mandatory ITRI computation by all MIIs using a uniform nine-parameter methodology.
  2. MIIs that had participated in the beta phase must operationalise the framework within six months of the circular date (i.e., by February 28, 2027).
  3. The first formal half-yearly submission is due for the period ending September 30, 2026.
  4. SEBI will use the index for supervisory oversight, enabling early identification of weaknesses before systemic disruptions occur.

Key Facts

ParameterWeightage
Availability20%
Security20%
Integrity10%
Governance10%
Reliability & Monitoring10%
Business Continuity10%
Modularity & Flexibility10%
Other parameters (2)10% (combined)
  • Highest weightage: Availability (20%) and Security (20%) — reflecting that uptime and protection from cyber threats are the primary risk vectors.
  • The index applies uniformly across exchanges, depositories and clearing corporations, enabling cross-institutional comparison.
  • MIIs must submit the index semi-annually; SEBI will use results for supervisory action and remediation directives.
  • The index does not directly affect public disclosures but informs SEBI's internal oversight and inspection cycle.

Constitutional Provisions

Securities market regulation falls under the Union List (List I, Entry 48) — "Stock exchanges and futures markets" — of the Seventh Schedule to the Constitution of India. This gives Parliament exclusive legislative authority over securities markets, and by extension SEBI's regulatory jurisdiction is constitutionally grounded.

Legal Framework

SEBI Act, 1992: Establishes SEBI as a statutory body with powers to regulate securities markets, protect investor interests and promote market development (Sections 11, 11A, 11B). Section 11B empowers SEBI to issue directions to any registered intermediary, including MIIs.
Securities Contracts (Regulation) Act, 1956 (SCRA): Governs stock exchanges and their recognition; MIIs derive their operating authority from this Act.
Depositories Act, 1996: Governs NSDL and CDSL.
SEBI (Stock Brokers) Regulations, 1992; SEBI (Depositories and Participants) Regulations, 2018: Subsidiary regulations governing MII operations.

Institutional Framework

  • SEBI (Securities and Exchange Board of India): Statutory body under the SEBI Act, 1992. Headquartered in Mumbai. Chairperson appointed by the Government of India. Regulates MIIs, intermediaries, and listed companies.
  • Ministry of Finance (Department of Economic Affairs): Administrative ministry overseeing SEBI.
  • Financial Stability and Development Council (FSDC): Apex inter-regulatory body chaired by the Finance Minister; coordinates macro-prudential oversight including IT risk at financial institutions.
  • RBI: Has concurrent interest in MII resilience given the settlement of government securities and currency derivatives on MII platforms.

Economic Dimensions

India's capital markets have expanded dramatically — combined market capitalisation crossed ₹400 lakh crore by 2026. Daily equity turnover on NSE and BSE routinely exceeds ₹1 lakh crore. Any outage or cyber breach at an MII can:

  • Halt settlement of securities worth trillions of rupees.
  • Trigger margin calls and forced liquidations across brokers.
  • Undermine investor confidence in India's markets at a critical time of FPI (Foreign Portfolio Investor) inflows.

Banking & Financial Angle: Banks are among the largest participants in capital markets (through their treasury operations and subsidiaries). MII disruptions can affect bank treasury P&L and liquidity management. SEBI's ITRI framework reduces systemic risk across the financial system — a concern shared by the RBI and the FSDC. For IBPS/SBI/RBI Grade B examinees, understanding the MII ecosystem and its regulatory oversight is a core banking-awareness topic.

Environmental Dimensions

Resilient digital infrastructure reduces the need for paper-based backup processes, supporting sustainability objectives. SEBI has separately mandated Business Responsibility and Sustainability Reporting (BRSR) for listed companies; robust IT systems ensure the integrity of ESG-linked disclosures filed through MII platforms.

Social Dimensions

India now has over 17 crore demat accounts (as of 2026), with a large proportion from first-generation retail investors in semi-urban and rural areas (driven by UPI-linked investment platforms). MII outages disproportionately hurt retail investors who lack the hedging instruments available to institutional players. The ITRI framework thus has a financial inclusion dimension — resilient markets are inclusive markets.

International Relations

The ITRI framework aligns India's regulatory approach with international best practices:

  • CPMI-IOSCO Principles for Financial Market Infrastructures (PFMIs): The Bank for International Settlements (BIS) and the International Organization of Securities Commissions (IOSCO) have issued Principles for Financial Market Infrastructures that include Principle 17 (Operational Risk). SEBI's ITRI is India's quantitative operationalisation of these principles.
  • EU's DORA (Digital Operational Resilience Act): The European Union's financial sector ICT resilience framework (effective January 2025) is a comparable international reference point — the ITRI demonstrates India's convergence with global regulatory standards.

Challenges

  • Data standardisation: Nine parameters with sub-metrics require consistent measurement methodologies; differences in MII technology architectures may complicate cross-institutional comparisons.
  • Compliance burden on smaller depositories: While NSDL and CDSL are well-resourced, ensuring equivalent capabilities at smaller clearing corporations may require investment.
  • Cyber threat evolution: A static index may not capture emerging threats (AI-driven attacks, quantum computing risks) without periodic revision.
  • Vendor concentration risk: MIIs often rely on a small set of technology vendors; the index may not fully capture third-party dependency risks.

Government Initiatives

  • SEBI CSCRF (2023): Cybersecurity and Cyber Resilience Framework for regulated entities — the ITRI refines and quantifies this for MIIs.
  • National Cyber Security Policy (2020 revision): Designates financial market infrastructure as Critical Information Infrastructure (CII).
  • CERT-Fin: The Computer Emergency Response Team for the financial sector, coordinating between RBI, SEBI, IRDAI and PFRDA on cyber incidents.
  • Digital India Initiative: The broader government push for digitisation increases both the volume of transactions on MII platforms and the stakes of resilience failures.

Way Forward

  • SEBI should consider mandating real-time resilience dashboards shared between MIIs and SEBI, moving beyond semi-annual snapshots.
  • The FSDC should incorporate ITRI scores into its macro-prudential risk assessments to create a system-wide view of financial market technology risk.
  • India should engage with IOSCO to share the ITRI methodology as a model for emerging-market securities regulators — an opportunity for regulatory soft power.
  • SEBI's 2nd ARC equivalent — the Expert Committee on Technology and Market Regulation — should periodically review the nine parameters to incorporate new threat vectors (AI, quantum, cloud dependencies).

Possible Mains Questions

  1. Market Infrastructure Institutions (MIIs) are the critical backbone of India's capital markets. Examine the significance of SEBI's IT Resilience Index framework in the context of systemic risk management and India's aspiration to become a global financial hub. (GS III — Economy)
  2. Critically evaluate the regulatory architecture governing India's securities market infrastructure. How does SEBI's mandate align with international best practices such as CPMI-IOSCO Principles for Financial Market Infrastructures? (GS III — Economy)

Possible Prelims MCQs

  1. Q: Which of the following are classified as Market Infrastructure Institutions (MIIs) under SEBI's regulatory framework?
    (a) Mutual Fund AMCs and Portfolio Management Services
    (b) Stock exchanges, depositories and clearing corporations
    (c) Scheduled commercial banks and primary dealers
    (d) Credit rating agencies and investment advisors
    Answer: (b) — MIIs are stock exchanges (BSE, NSE), depositories (NSDL, CDSL), and clearing corporations (NSCCL, ICCL).
  2. Q: SEBI's IT Resilience Index (ITRI) assigns the highest combined weightage to which two parameters?
    (a) Business Continuity and Governance
    (b) Availability and Security
    (c) Integrity and Modularity
    (d) Reliability and Monitoring
    Answer: (b) — Availability and Security each carry 20%, the highest among the nine parameters.
  3. Q: Under which List of the Seventh Schedule does "Stock Exchanges and Futures Markets" appear?
    (a) State List (List II)
    (b) Concurrent List (List III)
    (c) Union List (List I)
    (d) Not enumerated; governed by residuary powers
    Answer: (c) — Entry 48 of List I (Union List): "Stock exchanges and futures markets."

Essay Dimensions

  1. Digital resilience as the new frontier of financial sovereignty: the case of India's capital market infrastructure.
  2. Regulating risk in real time: the challenge of quantifying technological resilience in complex financial ecosystems.
  3. From SCRA to SEBI ITRI: the evolution of securities market regulation in independent India.
  4. Systemic risk and the small investor: who pays the price when market infrastructure fails?
  5. Convergence vs. divergence: how India's financial regulators compare with global best practices.

Interview Questions

  1. SEBI is often described as a "market regulator." What are the distinct functions it performs — protective, developmental and regulatory — and how does the ITRI serve each of these functions?
  2. How would you distinguish systemic risk from market risk in the context of India's capital markets? Why does IT resilience of MIIs matter for systemic risk?
  3. If you were advising SEBI on the next revision of the ITRI, what additional parameters would you include to address emerging threats like AI-driven cyberattacks and cloud dependency?
  4. India aspires to become an International Financial Services Centre (IFSC) competitor to Singapore and Dubai. What role does regulatory credibility — including technology resilience standards — play in this ambition?
  5. The EU's DORA and India's ITRI both target financial sector IT resilience. What can India learn from the EU's experience, and what unique features of India's market warrant a different approach?

FAQ

What is a Market Infrastructure Institution (MII)?
An MII is a SEBI-recognized entity that provides core infrastructure for securities trading and settlement. This includes stock exchanges (NSE, BSE), depositories (NSDL, CDSL), and clearing corporations (NSCCL, ICCL). They are systemically important and directly regulated by SEBI.
What is the IT Resilience Index (ITRI)?
The ITRI is a standardised scoring framework with nine parameters — led by Availability (20%) and Security (20%) — that measures how robustly an MII's IT systems can withstand disruptions, cyberattacks and outages. It enables SEBI to compare resilience across MIIs and direct early corrective action.
When does the ITRI become mandatory?
MIIs must operationalise the framework within six months of the August 24, 2026 circular, i.e., by February 28, 2027. The first formal submission covers the half-year ending September 30, 2026.

Further Reading

Relevant Acts & Judgments

Acts
SEBI Act, 1992
Section 11B empowers SEBI to issue directions to MIIs; basis of regulatory authority over capital market infrastructure
Securities Contracts (Regulation) Act, 1956 (SCRA)
Governs recognition and operation of stock exchanges
Depositories Act, 1996
Governs NSDL and CDSL; their IT resilience is covered under the ITRI
Key distinction: Don't confuse the IT Resilience Index (ITRI) — a nine-parameter supervisory scorecard for MIIs — with the Cybersecurity and Cyber Resilience Framework (CSCRF, 2023), which is a broader set of cybersecurity guidelines for all SEBI-regulated entities including brokers, AMCs and rating agencies. ITRI is specifically for MIIs and produces a quantitative comparable score.
GS-IIIEconomySEBICapital MarketsCybersecurityMarket InfrastructureFinancial RegulationTechnologyBanking AwarenessIT Resilience

0 Comments

Sign in to join the discussion.

SEBI IT Resilience Index (ITRI) 2026: Nine-Parameter Framework for MIIs | UPSC Current Affairs | UPSC.wiki