Skip to main content
Wednesday, 7 October 2026
TaxClue News

SEBI aligns its Cyber Incident Reporting Portal with the FIRE format: portal to take incident reports in stages, from first report to closure

SEBI has aligned its Incident Reporting Portal with the Format for Incident Reporting Exchange (FIRE) developed by the Financial Stability Board. Regulated entities report cyber incidents through the Cyber Incident Reporting Portal at siportal.sebi.gov.in, which will facilitate reporting in stages from initial report to final closure. The existing timelines — email within 6 hours and portal within 24 hours — are restated.

Key facts

In force
Circular dated 24 August 2026; no separate commencement date stated
Who it affects
All SEBI regulated entities — stock brokers, depository participants, AIFs, mutual funds, portfolio managers, investment advisers, research analysts, RTAs, KRAs, merchant bankers, debenture trustees, credit rating agencies, custodians
What it is
Action needed
Section
SEBI
Published
24 August 2026
Editor24 August 2026 · updated 7 Oct · 3 min read

In 30 seconds

  • Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026 is dated 24 August 2026.
  • FIRE is the Format for Incident Reporting Exchange framework developed by the Financial Stability Board.
  • It defines common information fields, standardized definitions and consistent classification of incident attributes.
  • The portal takes reports in stages: initial reporting, intermediate updates and final closure.
  • Existing rule under Annexure-O of the CSCRF: report by email within 6 hours and on the SEBI Incident Reporting Portal within 24 hours.
  • Regulated entities must put systems in place to implement the circular.

What SEBI has done

By a circular dated 24 August 2026, SEBI has told its regulated entities that its Incident Reporting Portal is now aligned with the Format for Incident Reporting Exchange (FIRE) framework developed by the Financial Stability Board (FSB).

The circular explains what FIRE is for. It enables structured incident reporting by defining common information fields, standardized definitions and a consistent classification of incident attributes, which promotes harmonisation across sectors or jurisdictions.

The reporting rule already in place

SEBI has already prescribed guidelines for reporting cyber incidents under Annexure-O (B: Guidelines on Handling Cybersecurity Incidents) of its CSCRF framework. As the circular restates them, all regulated entities must report a cyber incident:

ChannelTime limit
Email to mkt_incidents@sebi.gov.inWithin 6 hours
SEBI Incident Reporting PortalWithin 24 hours

Reporting in stages

The portal will facilitate reporting of incidents in stages, to reflect the life cycle of an incident: initial reporting, intermediate updates and final closure. The circular acknowledges that certain information may not be available at the time of the initial report.

Regulated entities shall report cyber incidents through the Cyber Incident Reporting Portal of SEBI, reached by logging in at https://siportal.sebi.gov.in.

Who the circular is addressed to

  • Alternative Investment Funds and Venture Capital Funds
  • Bankers to an Issue and Self-Certified Syndicate Banks
  • Stock exchanges, clearing corporations and depositories
  • Stock brokers (through exchanges) and depository participants (through depositories)
  • Mutual funds / asset management companies, portfolio managers and Collective Investment Schemes
  • Investment advisers and research analysts, and BSE Limited as their administration and supervisory body
  • Credit rating agencies, debenture trustees, merchant bankers
  • Custodians and Designated Depository Participants
  • KYC Registration Agencies, and Registrars to an Issue and Share Transfer Agents

What regulated entities should do

The circular requires regulated entities to take the necessary steps to put systems in place for its implementation, including amendments to the relevant bye-laws, rules and regulations, if any. It is to be read with the applicable SEBI circulars, including the Cybersecurity and Cyber Resilience framework, and any later updates.

The circular does not state a separate date of commencement.

Questions and answers

What is the FIRE format?

FIRE stands for Format for Incident Reporting Exchange, a framework developed by the Financial Stability Board. It enables structured incident reporting through common information fields, standardized definitions and consistent classification of incident attributes.

Within what time must a cyber incident be reported to SEBI?

As restated in the circular, regulated entities report a cyber incident through mkt_incidents@sebi.gov.in within 6 hours and on the SEBI Incident Reporting Portal within 24 hours, under Annexure-O of the CSCRF framework.

Where is the report filed?

On the Cyber Incident Reporting Portal of SEBI, accessed by logging in at https://siportal.sebi.gov.in.

Does everything have to be known at the first report?

No. The portal takes reports in stages — initial reporting, intermediate updates and final closure — and the circular acknowledges that certain information may not be available at the time of initial reporting.

SourceSEBI Circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 dated 24 August 2026
Open the original ↗
Share this story
Send on WhatsApp

Published 24 August 2026. Updated 7 October 2026. This report is for general information and is not professional advice. Read the source document before acting on it.

Share

The morning brief

One email each working morning with the day’s tax, GST and company-law news. It is starting soon; leave your address and it comes to you from day one.