The Securities and Exchange Board of India (SEBI) introduced the IT Resilience Index (ITRI) Framework for Market Infrastructure Institutions (MIIs) through a circular dated 24 August 2026 to measure how strong and resilient their critical IT systems are. The framework will assign a score out of 100 across nine parameters, with availability and security carrying the highest weightage. Full operationalisation, including an Early Warning System (EWS) and real time monitoring of service delivery, is set for 28 February 2027, and the first half-yearly ITRI submission will cover the period ending 31 March 2027.
What Are Market Infrastructure Institutions and Why Do They Matter?
Market Infrastructure Institutions (MIIs) are entities that provide the shared backbone on which the entire securities market runs. In India, this collective term covers stock exchanges, clearing corporations and depositories. They are regulated by SEBI, the statutory regulator for the securities and commodity market under the Ministry of Finance.
SEBI was first constituted as a non-statutory body on 12 April 1988 through a Government of India resolution and became a statutory body on 30 January 1992 when the SEBI Act, 1992 (Act No. 15 of 1992) came into force. The Act was enacted on 4 April 1992 to protect investors, promote the development of the securities market and regulate it. SEBI is headquartered at Bandra Kurla Complex, Mumbai, with regional offices in New Delhi, Kolkata, Chennai and Ahmedabad. It derives powers under Section 11(1) of the SEBI Act and regulates MIIs under the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018 (SECC Regulations, 2018) and the SEBI (Depositories and Participants) Regulations, 2018.
MIIs are considered systemically important because any disruption in their systems can halt trading, clearing, settlement or securities holding and affect millions of investors. The concept was strongly emphasised by the Bimal Jalan Committee (Committee on Review of Ownership and Governance of MIIs, 2010), chaired by former RBI Governor Dr. Bimal Jalan. The committee noted that well-functioning MIIs form the nucleus of capital allocation, and that the limited number of such institutions amplifies the fallout if any one fails, with effects that can extend well beyond the securities market.
In India, recognised MIIs include major stock exchanges such as the National Stock Exchange (NSE) and BSE Ltd, clearing corporations such as NSE Clearing Limited and Indian Clearing Corporation Ltd, and the two depositories, National Securities Depository Limited (NSDL) and Central Depository Services (India) Limited (CDSL). Under SEBI’s master circulars, critical systems of these entities include trading, clearing, settlement, risk management and depository operations, along with other systems that feed into them.
What Is IT Resilience and What Is the ITRI?
IT resilience means the ability of an organisation’s IT systems to remain available, secure and reliable, to withstand disruptions, to recover quickly and to continue delivering services without significant interruption. It goes beyond traditional disaster recovery, which focuses on restoring systems after a failure. Resilience also includes preventing failures, detecting early signs of weakening and adapting systems to absorb shocks.
Related concepts often appear alongside it. Cyber resilience is the ability to anticipate, withstand and recover from cyberattacks. Operational resilience is the broader ability of the organisation to maintain critical operations through any disruption, whether caused by technology, cyber incidents, people or processes. Business continuity refers to the plans and capabilities that allow essential services to continue during a disruption. The ITRI brings all these ideas together into a single measurable score.
The IT Resilience Index (ITRI) is a new system-driven, quantitative health score created by SEBI after discussions with its Technical Advisory Committee (TAC) and a consultation paper dated 25 March 2026. It is designed to capture how well the critical IT systems of an MII are functioning and how resilient they are, using a uniform set of parameters so that scores can be compared across different MIIs. SEBI has described it as a shift from a compliance-check approach to a measurable resilience barometer, similar in spirit to how capital adequacy measures financial strength for banks.
The framework builds on earlier SEBI technology mandates for MIIs, including the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities issued on 20 August 2024. The CSCRF applies to all SEBI regulated entities across five categories (MIIs, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs) and is built around five cyber resilience goals of Anticipate, Withstand, Contain, Recover and Evolve, mapped to functions of Governance, Identify, Protect, Detect, Respond and Recover. It introduced the Cyber Capability Index (CCI), Market SOCs set up by NSE and BSE for smaller entities, ISO 27001 certification requirements and CERT-In empanelled audits. The ITRI now adds a dedicated index focused specifically on IT resilience of MIIs.
How Is the ITRI Computed? The Nine Parameters and Weightage
The ITRI has a total score of 100 and is computed from nine parameters, each given a specific weightage based on its importance to systemic stability. The design gives priority to factors whose failure can immediately disrupt markets.
| Parameter | Weightage | What It Measures |
|---|---|---|
| Availability | 20 | Uptime and accessibility of critical IT systems |
| Security | 20 | Protection against compromise, cyber threats and unauthorised access |
| Integrity | 10 | Accuracy and consistency of systems and data |
| Governance | 10 | Oversight, policies, roles and accountability for IT resilience |
| Reliability and Monitoring | 10 | Stable performance and continuous monitoring of system health |
| Business Continuity | 10 | Ability to sustain and recover critical services during disruption |
| Modularity and Flexibility | 10 | Ability to adapt systems and support changes without risk |
| Scalability | 5 | Capacity to handle growth in volumes and users |
| Others, including Incident Handling | 5 | Other resilience aspects such as incident response and learning |
Availability and security together account for 40% of the score because outages or breaches can instantly halt trading or settlement. Parameters such as integrity, governance and business continuity each carry 10%, reflecting the need for trustworthy data, strong oversight and quick recovery. Scalability carries 5%, acknowledging rapid growth in Indian market volumes while signalling that capacity risk is less immediate than availability risk. Others, including incident handling, also carries 5% to capture how quickly and effectively incidents are managed.
The index will cover Critical Systems as defined in SEBI master circulars (Clause 9.1.2.3 of the Master Circular dated 30 December 2024 for Stock Exchanges and Clearing Corporations, Clause 4.31.2.3 of 3 December 2024 for Depositories and Clause 16.4.3(c) of 4 August 2023 for commodity derivatives), plus other systems that feed into or relate to them.
Who Decides the Detailed Scoring Rules?
SEBI has prescribed only the nine high-level parameters and their weightages. The detailed work of defining sub-parameters, measurement criteria, baseline values, acceptable threshold scores and the scoring methodology has been assigned to the Industry Standards Forum (ISF) of MIIs, a body constituted by SEBI. The ISF must finalise these by 30 November 2026 and formulate a Standard Operating Procedure (SOP) for calculation along with an objective, system-driven scoring methodology to ensure comparability across MIIs.
A key design choice is that ITRI computation must be system-driven and automatic, meaning the score is generated directly from IT systems or data extracted from them without manual intervention. This is intended to make it non-discretionary and verifiable. If any parameter cannot be computed automatically, manual data retrieval is allowed only after the MII has discussed the exception with its Standing Committee on Technology (SCOT).
Early Warning System and Real Time Monitoring: How Will Weakness Be Detected Early?
Two operational pillars support the ITRI so that a falling score actually triggers action before a failure occurs.
First, every MII must build an Early Warning System (EWS). The EWS is meant to detect possible deterioration in any ITRI parameter that could lead to performance issues, slowness or other system problems and to activate a framework for remedial action. In practice, declining indicators such as rising latency, falling availability, increasing security events or gaps in monitoring would raise alerts before they snowball into a market-wide disruption.
Second, MIIs must provide continuous visibility into service delivery to market participants. SEBI has already required MIIs under its Revised Guidelines for Capacity Planning and Real Time Performance Monitoring framework dated 10 December 2024 to continuously monitor process and application performance and resource utilisation at each IT component level. The new framework extends this by mandating systems that include consolidated dashboards to track system and application performance, continuity of service and any deviations or anomalies. MIIs must also formulate SOPs to monitor availability and continuity of service to all market participants and to flag any disruption or deviation.
Together, the ITRI, the EWS and the dashboards convert resilience from a periodic audit exercise into continuous monitoring.
How Will Reporting and Governance Work?
MIIs must compute the ITRI on a half-yearly basis within 60 days from the end of each half-year. They must also submit a comparative analysis of two consecutive half-years on a rolling basis, along with corrective actions taken or proposed, to their Standing Committee on Technology (SCOT) and Governing Board. The framework is intended to function as a self-operating model where MIIs regularly assess the health of their systems and report improvement areas to their boards, rather than waiting for regulatory inspection.
The detailed SOPs, once the ISF finalises sub-parameters, must be submitted to SEBI after review by the SCOT of each MII by 31 January 2027. MIIs must also take steps to implement the circular, including amending relevant bye-laws, rules and regulations where needed.
Timeline and Implementation Status
| Deadline | Requirement |
|---|---|
| 30 November 2026 | ISF to finalise sub-parameters and detailed measurement criteria for all nine parameters |
| 31 January 2027 | Detailed SOPs for ITRI calculation to be submitted to SEBI after SCOT review |
| 28 February 2027 | Full ITRI framework, including EWS and real time monitoring of service delivery, to be operationalised |
| 31 March 2027 | End of first half-year for which ITRI computation must be submitted |
SEBI has stated that MIIs have already implemented a beta version of the ITRI framework, so the period up to February 2027 is for moving from pilot to full-scale, system-driven operation. The first formal ITRI submission, covering the half-year ending 31 March 2027, will be due within 60 days thereafter.
Why Is SEBI Introducing a Measurable Resilience Index Now?
The move reflects how central technology has become to Indian capital markets. With high market capitalisation, more than 17 crore demat accounts, and heavy use of electronic trading, clearing and depository systems, even a short outage at an exchange or clearing corporation can affect price discovery, settlement and investor confidence. SEBI’s circular notes that IT systems of MIIs form the backbone of smooth market functioning and that any disruption or compromise can undermine trust.
Globally, most regulators follow a principle-based operational resilience model that sets expectations but does not produce a single score. SEBI’s ITRI attempts to quantify resilience in a uniform, comparable index, which could make it one of the first such efforts for market infrastructure. If implemented credibly, it could also provide a template for other jurisdictions grappling with similar technology risks.
The timing also aligns with broader technology governance. SEBI has set up a working group for a short-term and long-term technology roadmap for MIIs covering Artificial Intelligence (AI) and machine learning, cloud adoption, distributed ledger technology, quantum-safe systems, SupTech (supervisory technology) and RegTech (regulatory technology), along with tokenisation. In August 2024, SEBI also issued the Framework for Adoption of Cloud Services for regulated entities. As MIIs adopt cloud, AI and high-frequency trading infrastructure, a measurable resilience check helps ensure that innovation does not outpace stability.
Challenges remain. A common score must fairly compare institutions with different architectures, such as exchanges versus depositories. Weights may need refinement over time using actual outage and cyber incident data. Significant investment is also needed in automated monitoring, redundant infrastructure and continuous testing, especially as cyber threats evolve unpredictably.
What Does the ITRI Mean for Market Participants and Financial Stability?
For the market, the framework aims to ensure that trading, clearing and settlement remain available, reliable and secure even during stress, including cyber incidents or volume spikes. For individual investors, stronger resilience reduces the risk of being unable to trade or access holdings due to a technical failure at an MII. For the broader financial system, it protects the financial market infrastructure layer that India’s payments, custody and settlement chains depend on.
For MIIs themselves, the index creates accountability. Boards will receive regular, system-generated assessments of IT health and will be expected to act on deteriorating indicators. Over time, consistent half-yearly scores and rolling comparisons will allow SEBI, boards and market observers to track whether resilience is improving.
Key Takeaways
- SEBI introduced the IT Resilience Index (ITRI) Framework for Market Infrastructure Institutions (MIIs) on 24 August 2026 through Circular No. HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026.
- The ITRI is a 100-point, system-driven index covering nine parameters, with Availability (20) and Security (20) carrying the highest weightage.
- Other weightages are Integrity (10), Governance (10), Reliability and Monitoring (10), Business Continuity (10), Modularity and Flexibility (10), Scalability (5) and Others including Incident Handling (5).
- MIIs include stock exchanges (such as NSE, BSE), clearing corporations (such as NSE Clearing, Indian Clearing Corporation Ltd) and depositories (NSDL, CDSL).
- The Industry Standards Forum (ISF) of MIIs must finalise sub-parameters and measurement criteria by 30 November 2026, with detailed SOPs to be submitted to SEBI by 31 January 2027 after SCOT review.
- The full framework, including the Early Warning System (EWS) and real time monitoring of service delivery with consolidated dashboards, must be operational by 28 February 2027.
- The first ITRI computation will be for the half-year ending 31 March 2027, with half-yearly computation required within 60 days of each half-year and a rolling comparison of two consecutive half-years to be placed before SCOT and the Governing Board.
- SEBI was constituted as a non-statutory body on 12 April 1988 and became a statutory body on 30 January 1992 under the SEBI Act, 1992, with headquarters at Bandra Kurla Complex, Mumbai.