The Securities and Exchange Board of India (SEBI) has introduced an IT Resilience Index (ITRI) framework for market infrastructure institutions (MIIs) — stock exchanges, clearing corporations, and depositories — to assess the functioning and resilience of their critical IT systems. The regulator issued a circular on August 24, 2026, following a consultation paper in March 2026 and discussions with SEBI's Technical Advisory Committee, according to Moneycontrol.
The move stems from the recognition that the IT systems of MIIs form the backbone of the securities market, and that any disruption, performance degradation, or compromise could affect critical market operations and pose risks to investor trust, as reported by The Economic Times and Moneycontrol. The Economic Times noted that SEBI's framework is aimed at ensuring availability, reliability, performance, and cyber resilience through robust governance, proactive monitoring, and timely corrective measures.
How the ITRI works
The ITRI is a 100-point index computed using nine parameters, each with a specific weightage. Availability and security carry the highest weightage at 20 points each, followed by integrity, governance, reliability and monitoring, business continuity, and modularity and flexibility at 10 points each. Scalability and other factors, including incident handling, carry 5 points each, as detailed by The Hindu Business Line and Moneycontrol.
A key feature of the framework is that computation must be entirely system-driven — automatically generated from IT systems or data extracted without manual intervention — to keep the process "non-discretionary and fool proof," as reported by Moneycontrol and The Economic Times. Any exception requiring manual data retrieval would need prior discussion with each MII's Standing Committee on Technology (SCOT).
Implementation timeline and responsibilities
The Industry Standards Forum (ISF) of MIIs, constituted by SEBI, is tasked with finalising detailed sub-parameters and measurement criteria for each ITRI component by November 30, 2026, according to The Economic Times and Moneycontrol. The ISF will also formulate baseline parameters, acceptable threshold scores, and standard operating procedures (SOPs) for calculating the ITRI, along with an objective, system-driven scoring methodology to ensure comparability across institutions.
MIIs are required to compute the ITRI on a half-yearly basis, within 60 days from the end of each half-year, and submit a comparative analysis of two consecutive half-years on a rolling basis, along with corrective actions taken or proposed, to their SCOT and Governing Board, as stated by The Economic Times and The Hindu Business Line.
MIIs have already rolled out a beta version of the ITRI framework, according to Moneycontrol and The Hindu Business Line. The full framework, including an Early Warning System (EWS) to detect deterioration in ITRI parameters and real-time monitoring of service delivery, must be operational by February 28, 2027. Detailed SOPs are due to SEBI by January 31, 2027, after review by each MII's SCOT, as reported by The Economic Times and Moneycontrol.
The first formal ITRI submission under the framework will cover the half-year ending March 31, 2027, according to The Economic Times, Moneycontrol, and The Hindu Business Line.
The Economic Times reported that SEBI has said MIIs will be required to take necessary steps to put systems in place for implementation, including amendments to relevant bye-laws, rules, and regulations where required.
Related move on incident reporting
In a separate development, SEBI aligned its Incident Reporting Portal with the Format for Incident Reporting Exchange (FIRE) framework developed by the Financial Stability Board (FSB), as reported by The Hindu Business Line. FIRE enables structured incident reporting by defining common information fields, standardised definitions, and consistent classification of incident attributes, promoting harmonisation across sectors or jurisdictions.
The Hindu Business Line noted that SEBI said the portal will facilitate reporting of incidents in stages, reflecting the incident life cycle from initial reporting to intermediate updates and final closure, while acknowledging that certain information may not be available at the time of initial reporting. SEBI has asked regulated entities to report cyber incidents through its Cyber Incident Reporting Portal.