On August 24, 2026, SEBI issued a circular introducing the IT Resilience Index, or ITRI, for Market Infrastructure Institutions, covering stock exchanges, clearing corporations, and depositories. The same week saw two related developments that together signal a decisive shift in how SEBI approaches technology risk. SEBI had already launched a revamped Incident Reporting Portal and a new Cyber Suraksha Portal on August 17, and on August 24 it issued a further circular aligning that Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange, commonly known as FIRE.
Taken together, these three moves mark a shift from cyber resilience being something MIIs assert to something SEBI expects them to measure, report in a standardised format, and be held accountable for at the board level. This is a strong, current development for anyone responsible for cyber governance in market infrastructure, and it offers useful signals for BFSI institutions more broadly, even those not directly regulated as MIIs.
What the IT Resilience Index Is
The ITRI is a 100 point, system driven framework designed to assess the resilience and reliability of technology systems at MIIs across nine weighted parameters. Availability and cybersecurity each carry the heaviest weighting at 20 percent, reflecting SEBI’s view that these two dimensions are the frontline operational defences of market infrastructure, followed by business continuity and reliability at 10 percent each, with scalability and other parameters weighted to reflect their systemic importance. SEBI has been explicit that computation of the index will be system driven to keep the process objective and non discretionary, with manual intervention permitted only in narrow, clearly justified exceptions discussed with the institution’s Standing Committee on Technology.
An Information Systems Framework will formulate the baseline parameters, acceptable threshold scores, and standard operating procedures for calculating the ITRI, creating a consistent, comparable scoring methodology across institutions. MIIs are required to operationalise an Early Warning System and real time service monitoring by February 28, 2027, giving institutions a defined runway to build the underlying telemetry and monitoring capability the index depends on.
Which Market Infrastructure Institutions Are Affected
The framework applies directly to stock exchanges, clearing corporations, and depositories, the core institutions that keep India’s securities markets functioning on a daily basis. Because these entities sit at the centre of trading, clearing, settlement, and custody, a resilience failure at any one of them carries systemic consequences that extend well beyond the institution itself, into every market participant, intermediary, and investor connected to it. This is precisely why SEBI has chosen to regulate their technology resilience with the same rigour traditionally reserved for capital adequacy in banking.
Why Cyber Resilience Must Be Measured Rather Than Assumed
For years, market infrastructure institutions could describe their cyber and technology resilience in largely qualitative terms, citing controls in place, audits completed, and incidents avoided. The ITRI moves this into quantitative territory, similar to how capital adequacy ratios measure financial health in banking. A numeric, benchmarked score forces a different kind of institutional honesty, weaknesses become visible in a comparable format rather than buried in narrative assurance, and boards receive a structured basis for asking where the institution actually stands rather than accepting a general assertion that systems are secure.
This mirrors a broader regulatory pattern seen in the RBI’s own cybersecurity framework, where qualitative assurance is increasingly being replaced with measurable, auditable evidence of resilience.
Governance and Board Oversight
Under the ITRI framework, MIIs will periodically compute the index and provide their governing boards with a structured assessment of overall IT system health and the specific areas requiring attention. This creates a direct, recurring channel of technology risk information into the boardroom, rather than leaving cyber resilience as a topic that surfaces only during an annual review or after an incident. Boards of MIIs will need the capability to interpret a nine parameter, weighted score meaningfully, understanding not just the headline number but which specific parameters are driving it, and what remediation is genuinely required versus cosmetic improvement to the score itself.
Incident Detection and Response Capability
The Early Warning System requirement, to be operationalised by February 28, 2027, calls for automated, real time telemetry capable of detecting performance degradation, latency spikes, or hardware stress before these issues escalate into outages. This shifts incident detection from a reactive posture toward continuous, automated monitoring, a capability many institutions will need to build or substantially upgrade rather than assume they already possess in adequate form.
Business Continuity and Recovery Testing
Business continuity and reliability together carry a meaningful share of the ITRI’s weighting, reflecting SEBI’s consistent focus on recovery time objectives and near zero data loss tolerances that have featured in its cybersecurity guidance for MIIs in recent years. Institutions will need documented, tested recovery procedures that can demonstrate actual achieved recovery performance, not simply a policy stating that recovery procedures exist.
Third Party and Technology Dependency
The ITRI’s scope extends to systems connected to or feeding into an MII’s critical infrastructure, which means third party and vendor technology dependencies fall within its assessment boundary rather than sitting outside it. This is a meaningful detail for governance teams, since it means resilience cannot be evaluated purely at the institution’s own perimeter, vendor and interconnected system risk needs to be factored into the overall resilience posture the index is meant to capture.
Audit Evidence and Control Assurance
Because the ITRI is designed to be system driven and objective, institutions will need audit trails and control evidence that can withstand a standardised, comparable scoring process rather than a bespoke, narrative based review. This raises the bar for how technology and cyber controls are documented, tested, and evidenced internally, since the index effectively functions as a continuous, semi automated audit rather than a periodic point in time assessment.
What Institutions Should Assess Immediately
Given the February 2027 deadline for Early Warning System and real time monitoring capability, institutions should not treat this as a distant compliance milestone. The parallel developments around the FIRE aligned Incident Reporting Portal and the Cyber Suraksha Portal add further urgency, since institutions now need to align internal incident classification and reporting workflows with FIRE’s standardised fields and definitions, while also determining how they will actively use the Cyber Suraksha Portal for threat intelligence sharing rather than treating it as a passive reporting obligation.
Ten Question Implementation Checklist
Institutions and governance teams can use the following questions to begin assessing readiness against this framework.
- Do we understand how each of the nine ITRI parameters is weighted and calculated, and which ones currently represent our weakest areas.
- Is our Early Warning System capability built, in progress, or not yet started against the February 28, 2027 deadline.
- Can our board currently interpret a resilience score meaningfully, or would it need structured briefing to do so.
- Do our incident classification categories align with the FIRE framework’s standardised definitions and fields.
- Are we meeting the existing six hour email and twenty four hour portal reporting timelines consistently.
- Have we mapped which third party and interconnected systems fall within the ITRI’s assessment boundary.
- Do we have documented, tested recovery time objectives with evidence of actual achieved performance, not just policy statements.
- Is our audit evidence structured in a way that supports a system driven, objective scoring process.
- Have we assigned clear internal ownership for Cyber Suraksha Portal engagement and threat intelligence use.
- Does our Standing Committee on Technology have a defined process for handling ITRI parameters that require manual computation exceptions.
Conclusion
SEBI’s IT Resilience Index brings a level of measurability to cyber and technology resilience that market infrastructure institutions have not previously faced, shifting governance from narrative assurance to quantifiable, board level accountability. Institutions that begin building the underlying monitoring, evidence, and reporting capability now will be far better positioned than those waiting for the February 2027 deadline to approach.
Build This Capability with RMAI
Professionals responsible for cyber governance, technology risk, audit, and operational resilience can explore RMAI’s related learning programmes. The Online Course on Cyber Security and Technology Risk Management in Banking builds the working fluency needed to interpret resilience metrics and technology risk frameworks of this kind. For governance and board oversight professionals, the Online Certificate Course on Governance, Risk and Compliance (GRC) connects regulatory frameworks like this one to practical board reporting and oversight design. Explore RMAI’s complete suite of risk management courses for a programme matched to your team’s needs.