SEBI’s MII-Subsidiary Cyber Consultation: The Proposed Three-Part Test
SEBI proposes extending MII cyber and IT obligations to subsidiaries that perform an MII-domain activity, handle MII data or share infrastructure. Comments remain open through 2 October.

India’s securities market depends on more than the visible trading screen. Stock exchanges, clearing corporations and depositories rely on trading engines, networks, identity systems, data centres, cyber-security teams, disaster-recovery sites and operational vendors. Some of those functions may sit inside subsidiaries rather than the regulated parent market-infrastructure institution, or MII. SEBI’s 11 September consultation asks when the parent’s IT and cyber-security framework should extend to those subsidiaries.[[22]](/sources/regulation-market-structure/22)
The proposal uses a three-part test. A subsidiary would be covered when it directly performs activity belonging to the MII’s domain, handles data that the MII is responsible for, or shares infrastructure with the MII. The paper also sketches an exemption route for some shared-infrastructure-only cases. This remains a consultation, with comments invited through 2 October 2026. It is not yet a final rule.
Why the perimeter question matters
An MII can remain formally regulated while a critical technology function is performed by another legal entity in the same group. If that subsidiary develops the trading platform, runs the security operations centre, hosts production systems or handles settlement and investor data, an incident at the subsidiary can affect the parent’s regulated operations.
SEBI’s stated objective is to clarify when the parent framework reaches those connected entities. The paper says MIIs increasingly use subsidiaries for technology-driven and market-related activities, sometimes with shared applications, market data and other critical IT resources. Explicit perimeter rules can reduce the gap between the legal organisation chart and the operational dependency map.[[23]](/sources/regulation-market-structure/23)
The existing market-structure framework already separates regulators, exchanges, clearing corporations, depositories and market intermediaries. SEBI supervises securities-market institutions, while RBI has responsibilities across money markets, government securities, payments and financial-market infrastructure. Those institutional roles provide the foundation for understanding why uninterrupted systems and settlement integrity are public-market concerns.[[1]](/sources/regulation-market-structure/1) [[2]](/sources/regulation-market-structure/2) [[3]](/sources/regulation-market-structure/3) [[4]](/sources/regulation-market-structure/4)
Who counts as a market-infrastructure institution
In practical terms, MIIs include stock exchanges, clearing corporations and depositories. Exchanges operate venues and market systems. Clearing corporations stand between counterparties, calculate obligations and manage settlement risk. Depositories maintain dematerialised ownership records and support transfers and corporate actions.
The institutions are connected. A trade can move from exchange execution to clearing, fund and securities obligations, depository entries and final settlement. India’s shorter settlement cycles and optional T+0 framework increase the importance of reliable systems, synchronized data and operational continuity because less time is available to detect and resolve failures.[[5]](/sources/regulation-market-structure/5) [[6]](/sources/regulation-market-structure/6) [[8]](/sources/regulation-market-structure/8) [[10]](/sources/regulation-market-structure/10) [[11]](/sources/regulation-market-structure/11)
That does not mean every subsidiary is automatically critical. The consultation instead links coverage to what the subsidiary does, what data it handles and what infrastructure it shares.
The proposed three-part test
| Proposed trigger | Core question | Example risk |
|---|---|---|
| MII-domain activity | Is the subsidiary doing work the MII is supposed to perform? | Trading or market-operation function sits outside the parent |
| MII data | Does the subsidiary handle data the MII must protect? | Investor, trading, settlement or surveillance data is exposed |
| Shared infrastructure | Does the subsidiary share systems or infrastructure with the MII? | A common platform creates a path to critical operations |
The tests are alternatives rather than a requirement to meet all three. Under the proposal, one qualifying condition can bring a subsidiary into the parent’s IT and cyber-security framework. The language focuses on operational connection, not simply the subsidiary’s name or ownership percentage.[[23]](/sources/regulation-market-structure/23)
The first trigger looks at function. A subsidiary that develops, operates or maintains an exchange’s trading engine directly supports the regulated domain. The second looks at information. A subsidiary providing analytics or surveillance using trading, settlement or investor data handles information the parent must protect. The third looks at technology dependency. Shared production servers, databases, cloud environments, identity services or disaster-recovery systems can create common exposure.
What covered subsidiaries would need to address
The consultation says covered subsidiaries would comply with applicable requirements concerning cyber security, system audits, incident reporting, business continuity and disaster recovery, and technology governance. These categories describe a control system rather than one product checklist.
Cyber-security controls address prevention, detection, containment and recovery. System audits provide independent or structured examination of whether controls work as designed. Incident reporting determines when and how material events reach the parent, regulator and other responsible bodies. Business-continuity and disaster-recovery planning establishes how critical operations continue or resume. Technology governance assigns oversight, accountability, change management and risk acceptance.
SEBI’s surveillance and enforcement framework, exchange settlement rules and clearing-corporation interoperability provide related context for why technology controls cannot be isolated from market operations.[[9]](/sources/regulation-market-structure/9) [[16]](/sources/regulation-market-structure/16) [[18]](/sources/regulation-market-structure/18) [[19]](/sources/regulation-market-structure/19) [[20]](/sources/regulation-market-structure/20)
The proposal does not say every subsidiary receives an identical control set regardless of role. It says the applicable parent framework would extend to qualifying subsidiaries. Final obligations would still depend on the framework’s wording, the subsidiary’s activities and any later SEBI guidance.
Illustrative in-scope situations
The consultation’s examples make the operational logic easier to see. A technology subsidiary that develops and maintains a stock exchange trading platform is in scope because it directly supports a regulated function and manages critical systems. A subsidiary operating the security operations centre, security information and event management, vulnerability management or incident response is in scope because it manages cyber-security functions for the MII.
A shared data-centre or cloud subsidiary hosting production servers, databases or disaster-recovery infrastructure would meet the shared-infrastructure test. A technology subsidiary using trading, settlement or investor data for analytics, surveillance or artificial intelligence would meet the data test. Common identity, access, email or network services can also become critical when failure or compromise affects the parent’s operations.[[23]](/sources/regulation-market-structure/23) [[24]](/sources/regulation-market-structure/24)
These are illustrations, not findings that any named institution has weak controls. The consultation does not announce a cyber incident or accuse a subsidiary of non-compliance.
Illustrative out-of-scope situations
The paper also describes subsidiaries that would not meet the proposed test when they lack operational, data or infrastructure connection to the regulated function. Examples include an education or training subsidiary that does not access MII systems or data; a real-estate or facilities entity handling premises and administration; an independent financial-services business with separate infrastructure and its own regulatory framework; and an HR or payroll unit without access to trading, clearing, settlement or depository systems.[[23]](/sources/regulation-market-structure/23)
The distinction is not based on whether a subsidiary sounds “technology-related” in its name. It is based on the function, data and infrastructure facts. A payroll entity with privileged access to critical identity systems could present a different analysis from one using an isolated HR application. The final framework may therefore require MIIs to document dependencies at a more detailed level than the corporate organisation chart.
The proposed proportionality route
SEBI recognises that shared infrastructure can vary in importance. Where a subsidiary meets only the third condition—sharing infrastructure—the MII could seek an exemption from extending the framework. The proposal would require details of compensating controls and the views of the relevant Standing Committee on Technology and the MII board.[[23]](/sources/regulation-market-structure/23)
This is not a self-certified exclusion. The proposed route requires the MII to explain why the shared arrangement does not undermine cyber and IT resilience and to place governance views on record. The regulator would then consider the exemption request.
That structure reflects a wider market-regulation principle: the intensity of controls can be proportionate to operational risk, but the justification must be documented and reviewable. Securities Appellate Tribunal and SEBI enforcement records provide the broader accountability context, though they do not predetermine how a future exemption decision would be made.[[17]](/sources/regulation-market-structure/17) [[21]](/sources/regulation-market-structure/21)
Related compliance notice: different subject, similar operational discipline
BSE Notice 20260911-1 separately directed members to implement specified UN sanctions-list updates, scan existing and future accounts and follow the Section 51A UAPA procedure and SEBI AML/CFT obligations.[[25]](/sources/regulation-market-structure/25) The notice concerns sanctions screening and member compliance, not the proposed cyber perimeter.
The two records should not be merged, but they share an operational lesson. Financial-market compliance often depends on maintained systems, current data, documented controls, escalation routes and auditable action. The BSE notice is not evidence that a broker, issuer or investor committed wrongdoing; it is a general compliance instruction.
What happens next
SEBI invited comments through 2 October 2026. Respondents can address the trigger tests, examples, proportionality route and implementation implications. After consultation, SEBI may retain, amend, narrow or expand the proposal. A final circular or framework would need its own publication date, effective date and transition provisions.[[22]](/sources/regulation-market-structure/22) [[24]](/sources/regulation-market-structure/24)
Until then, accurate status language is proposes, would apply, consultation and comments due. Phrases such as “SEBI has imposed” or “all MII subsidiaries must now comply” would overstate the current record.
Evidence and limitations
| Claim | Controlling evidence | Limitation |
|---|---|---|
| Three proposed triggers | SEBI consultation text | Proposal may change after comments |
| Covered control areas | Consultation text | Final scope and implementation timing unknown |
| In-scope and out-of-scope examples | Consultation annexure | Illustrative and non-exhaustive |
| Shared-infrastructure exemption | Consultation text | Requires later SEBI consideration; not automatic |
| Comments due 2 October | SEBI landing page and consultation | Deadline does not equal adoption date |
| BSE sanctions-screening notice | BSE primary notice | Separate compliance subject; no wrongdoing allegation |
India’s market structure has evolved through settlement-cycle changes, clearing interoperability, depository systems and surveillance controls.[[7]](/sources/regulation-market-structure/7) [[12]](/sources/regulation-market-structure/12) [[13]](/sources/regulation-market-structure/13) [[14]](/sources/regulation-market-structure/14) [[15]](/sources/regulation-market-structure/15) The new consultation fits that continuing operational-resilience process, but it should be judged on its final text rather than assumed outcomes.
Research scope and risk: This Blog explains a regulatory consultation and related market-infrastructure concepts. It is not legal advice, cyber-security certification, investment advice or a recommendation concerning any exchange, intermediary, company or security.