SEBI Proposes Extending MII IT and Cyber-Security Framework to Eligible Subsidiaries
SEBI has issued a consultation paper on applying the information-technology and cyber-security framework used by market infrastructure institutions to eligible subsidiaries, seeking feedback on objective applicability criteria and exemptions.
What changed
SEBI is consulting on how the MII IT and cyber-security control framework should extend to subsidiaries rather than leaving subsidiary risk outside the same structured supervisory perimeter.
Why it matters
MII subsidiaries can share technology, data, vendors and operational dependencies with critical market infrastructure. A broader control perimeter could raise compliance cost but reduce the risk that weaker subsidiary controls become an indirect route into systemically important platforms.
Who is affected
Stock exchanges, clearing corporations, depositories, their subsidiaries, technology and cyber-security teams, boards, internal auditors, vendors and capital-market participants exposed to shared infrastructure.
Action required
Treat the document as a consultation, not a final rule. MIIs should map subsidiaries, shared systems, outsourcing and cyber dependencies against the proposed objective criteria, but should not describe the proposal as operative until SEBI issues final requirements.
# SEBI Proposes Extending MII IT and Cyber-Security Framework to Eligible Subsidiaries
Finin2min 2-minute summary
SEBI has issued a consultation paper on applying the information-technology and cyber-security framework used by market infrastructure institutions to eligible subsidiaries, seeking feedback on objective applicability criteria and exemptions.
What changed
SEBI is consulting on how the MII IT and cyber-security control framework should extend to subsidiaries rather than leaving subsidiary risk outside the same structured supervisory perimeter.
Why it matters
MII subsidiaries can share technology, data, vendors and operational dependencies with critical market infrastructure. A broader control perimeter could raise compliance cost but reduce the risk that weaker subsidiary controls become an indirect route into systemically important platforms.
Who is affected
Stock exchanges, clearing corporations, depositories, their subsidiaries, technology and cyber-security teams, boards, internal auditors, vendors and capital-market participants exposed to shared infrastructure.
Action / control point
Treat the document as a consultation, not a final rule. MIIs should map subsidiaries, shared systems, outsourcing and cyber dependencies against the proposed objective criteria, but should not describe the proposal as operative until SEBI issues final requirements.
Key verified facts
- SEBI’s official website lists the consultation paper dated September 11, 2026.
- The stated objective is to consider applicability of the MII IT and Cyber Security framework to subsidiaries of MIIs.
- SEBI’s public comment interface asks for views on objective applicability criteria referenced in the consultation.
- The consultation also seeks views on an exemption construct for specified cases.
- The paper is consultative and does not itself constitute a final operative circular.
Detailed Finin2min analysis
The control rationale is straightforward: a subsidiary can create operational risk even when the parent MII’s core platform is strongly protected. Shared identity systems, networks, cloud environments, vendors, staff and data flows can make legal-entity boundaries weaker than technical boundaries.
Objective criteria can improve predictability because entities can determine in advance whether a subsidiary falls within scope. The trade-off is calibration. Criteria that are too broad can impose full critical-infrastructure controls on low-risk entities, while criteria that are too narrow can leave material dependencies outside the framework.
Boards should focus on dependency mapping rather than entity charts alone. If a subsidiary hosts data, develops software, operates shared services or relies on the same privileged-access environment, its failure can affect the regulated parent even if its direct business is smaller.
For finance teams, the proposal can affect cyber-security capex, audit cost, staffing, insurance, vendor contracts and business-continuity investments. These are compliance-enabling costs, but better resilience can also reduce outage and incident loss exposure.
Because this is only a consultation, any implementation date, transition period or final exemption should come from the eventual SEBI instrument. Finin2min keeps proposal-stage obligations separate from current law to avoid premature compliance instructions.
Finance, legal and compliance lens
The operative status is consultation-stage. Governance teams should preserve the exact SEBI paper, map current controls against the proposal and keep any gap-remediation plan separate from a claim that new law is already in force. Finance teams should budget scenario costs without booking a mandatory compliance liability before final requirements exist.
Practical decision framework
MIIs should use the consultation period to inventory not only legal subsidiaries but also technical trust relationships: privileged accounts, shared directories, code repositories, SOC coverage, network peering, common vendors, backup dependencies and incident-response escalation. This evidence can show whether a subsidiary is operationally capable of affecting the parent’s critical functions. It also gives boards a fact base for commenting on whether SEBI’s proposed criteria are proportionate.
Any final framework will also interact with outsourcing governance and third-party risk. A subsidiary may itself outsource cloud, managed security or software development, creating a chain of dependencies that is invisible in a simple organisation chart. Contractual audit rights, incident-notification timelines, data segregation, recovery objectives and tabletop testing can therefore become as important as technical controls. The consultation is a chance to test those arrangements now without falsely representing the proposal as already binding.
The consultation also has an audit-design dimension. If a subsidiary becomes subject to the framework, boards will need clarity on evidence ownership, audit frequency, incident reporting, penetration testing and remediation tracking across group boundaries. Duplicate audits can create cost without better security, while fragmented audits can miss common vulnerabilities. A proportionate final design should therefore preserve the critical controls of the MII framework while recognising when a parent-level control is genuinely shared and tested across the subsidiary environment.
What not to infer
Do not infer that every MII subsidiary is already subject to the full framework or that SEBI has finalised the objective criteria or exemptions.
What to watch next
- Final SEBI circular or framework
- Final applicability thresholds and exemptions
- Transition timeline and audit expectations
- Treatment of shared vendors, cloud and group technology services
Source and methodology
- Controlling source: Securities and Exchange Board of India — https://www.sebi.gov.in/reports-and-statistics/reports/sep-2026/consultation-paper-on-applicability-of-it-and-cyber-security-framework-of-miis-to-their-subsidiaries_104433.html
- Source date: 2026-09-11
- Research cutoff: 2026-09-14 11:43 IST
Finin2min uses a primary-source-first hierarchy. Official regulator, government, court, exchange and company documents control operative facts where reasonably available. Reuters is used for live market data, source-based reporting and developments where a public primary document is not practically available. Competitor finance portals are discovery-only where stronger evidence can be closed.
Disclaimer
This material is for general information and education only. It is not investment, tax, legal, accounting or financial advice. Markets, regulations, litigation, transaction terms and source-reported facts can change after the stated cutoff. Verify the latest controlling source and obtain appropriate professional advice before acting on a material decision.
View official source →
FinNews is educational and professional reference material, not financial, tax or legal advice. Confirm the current official position from the primary source before acting on any figure, rate, provision or deadline mentioned here.