GIFT City Cyber Security Reporting: Preparing For The First 29 June 2026 CSCRF Deadline

The International Financial Services Centres Authority (IFSCA) has now moved from cyber policy design to concrete timelines. The first major compliance cut-off under the IFSCA Cyber Security and Cyber Resilience Framework (CSCRF) is fixed: 29 June 2026. By this date, every regulated entity operating in GIFT City that falls within the framework’s ambit must file its annual cyber security audit report for FY 2025-26.

This is more than a routine regulatory filing. For GIFT City’s vision as a competitive international financial hub, the quality and seriousness of these submissions will be read as a signal of operational resilience and governance maturity.

1. Why the 29 June 2026 CSCRF Deadline Matters

1.1 First real performance test for cyber governance

The CSCRF envisages an annual cycle of cyber audits and reporting. For FY 2025-26, the 90-day reporting window after year-end culminates on 29 June 2026. By this date:

  • Every full CSCRF entity must submit its annual cyber security audit report to IFSCA.
  • Entities covered by exemption categories (under Para 21 or Para 23 of the amended framework) must still comply with reporting obligations and Designated Officer Certification requirements.

This deadline is therefore the first structured demonstration of whether the regulated community in GIFT City has genuinely implemented robust cyber controls rather than treating the framework as a mere paperwork requirement.

1.2 Cyber resilience as a pillar of GIFT City’s positioning

IFSCA’s broader aim is to position GIFT City alongside global centres like Singapore, Dubai, and London. For sophisticated counterparties, tax and regulatory incentives are only part of the evaluation. They increasingly look at:

  • The continuity of operations under stress
  • Cyber resilience and incident handling capacity
  • The quality of governance and risk oversight at entity level

In that context, the CSCRF is not a peripheral framework. It is central to the credibility of institutions operating in GIFT City and, by extension, the jurisdiction itself.

2. Understanding IFSCA’s CSCRF Approach

2.1 Proportionate, risk-based framework

The CSCRF, issued under Circular IFSCA-CSD0MSC/13/2025-DCS, departs from the traditional “same controls for everyone” model. Instead, it is built on proportionality, meaning:

  • Controls must reflect the size, business complexity, and interconnectedness of the entity
  • Entities handling higher transaction volumes, more sensitive data, or deeper integration with market infrastructure are expected to adopt more mature and layered controls
  • Smaller or less complex entities are not forced into an over-engineered framework, but are still required to maintain a baseline of robust controls

This places responsibility squarely on each regulated entity to assess its own cyber risk profile and design controls that are commensurate with that profile, rather than merely copying a generic checklist.

2.2 No safe harbour through superficial compliance

Because the CSCRF anchors its expectations on proportionality and effectiveness, not formality, entities cannot satisfy the framework merely by:

  • Drafting a few policies
  • Adopting templates without implementation
  • Assembling an “on paper only” cyber structure

The annual audit, Designated Officer Certification, and incident reporting requirements are structured to test whether the controls actually work in practice and are aligned to real risks.

3. Exemptions: Relief on Implementation, Not on Reporting

3.1 Scope of March 2026 amendments

Circular IFSCA-CSD0MSC/1/2026-DCS issued in March 2026 introduced targeted exemptions under Para 21 and created a new Para 23 category, recognising the diversity of GIFT City entities. Broadly:

  • Para 21 exemptions now extend to:

    • Branches of regulated entities
    • Global In-House Centres
    • Entities with fewer than 10 employees
  • Para 23 covers:

    • Foreign universities
    • Newly incorporated standalone entities without a parent organisation
    • Credit Rating Agencies