SEBI proposes extending the IT and cybersecurity framework that applies to market infrastructure institutions (MIIs) to their subsidiaries and “arms.” The proposal addresses gaps in how far SEBI’s existing technology and cyber-security requirements apply when MIIs operate through entities that may not fall clearly within the same regulatory jurisdiction.

Both outlets note that MIIs are already governed by SEBI and are expected to comply with its IT and cybersecurity frameworks. However, SEBI says the applicability and jurisdiction of those frameworks are not explicitly defined for subsidiaries. SEBI’s move also acknowledges an operational reality: there may be cases where MIIs use services of subsidiaries to carry out certain activities. The proposal therefore seeks to clarify and potentially broaden the reach of the framework rather than leaving cyber and IT obligations unclear across related entities.

The outlets emphasize the same core point—that SEBI is working to remove ambiguity about coverage over group entities—while reflecting on why MIIs may rely on subsidiaries. No final implementation details are reported in the provided summaries.