IRDAI · Cybersecurity

IRDAI cybersecurity guidelines
the 2026 revision of the 2023 rules.

IRDAI replaced its 2023 Information and Cyber Security Guidelines on 6 April 2026. What stayed, what changed, who is covered, the six-hour incident rule, the annual audit, and what insurers must now demand of their cloud providers.

Guidelines of 6 April 2026Six hours to CERT-In and IRDAIAnnual assurance auditDPDP named

Last updated Published by TryTrustableNot legal advice

01

Which IRDAI cybersecurity guidelines are in force?

The IRDAI Information and Cyber Security Guidelines, 2026, issued by IRDAI circular on 6 April 2026. They replace the IRDAI Information and Cyber Security Guidelines, 2023 of 24 April 2023, and regulated entities are to comply from the current financial year. The 2023 structure largely survives; governance, audit and exceptions changed most.

The 2026 guidelines are published with an Annexure A listing every amendment to the 2023 guidelines and an Annexure B holding the revised 175-page text, its NIST CSF applicability matrix, the classification of intermediaries by gross insurance revenue, the auditor's report format and the eligibility criteria for audit firms. If your policy set was written against the 2023 version, the Annexure A table is the fastest route to a gap list.

02

Who do the IRDAI guidelines apply to?

All insurers, including foreign reinsurance branches, and every insurance intermediary IRDAI regulates. Individual agents, micro-insurance agents, point-of-sale persons and individual surveyors are outside the guidelines, but each insurer must make them follow a minimum security framework set by its own board-approved policy.

Two further points of scope. The guidelines cover all data the regulated entity creates, receives or maintains, wherever the records are and whatever form they take, so a spreadsheet at a TPA is in scope as much as the core policy system. And insurers are responsible for the intermediaries they engage: an intermediary submits its audit report and compliance to each insurer annually, and an intermediary that holds only paper records and does not access the insurer's systems gives a self-certification instead. Foreign reinsurance branches whose systems interface with an overseas parent must comply and have an auditor certify it at each year end, and under the 2026 revision may comply or explain against the checklist.

03

What changed in the 2026 IRDAI guidelines?

The 2026 revision moves accountability upward. The board must fund security adequately and see gaps closed within twelve months; the CISO may not report to the head of IT or carry business targets; the security risk committee meets quarterly; a new IT steering committee is created; and long-running exceptions need board approval.

Area2023 guidelines2026 guidelines
BoardApproves policy and the CISO appointment.Also provides a security budget proportionate to risk, receives the status of non-conformities from the annual audit, approves closure timelines and ensures gaps are closed within twelve months of reporting.
CISOOwns the policy; reports on incidents.No direct reporting line to the head of IT and no business targets; adequately staffed; briefs the ISRMC and the board; permanent invitee to the IT steering committee; responsible for complying with CERT-In directions.
ISRMCMeets at least twice a year.Meets at least quarterly; reports audit non-conformities with closure timelines to the risk management committee.
IT steering committeeNoneNew. Senior IT and business members, meets at least quarterly, CTO convenes, takes CISO input on IT procurement.
Risk management committeeControl management committee as a separate board committee.Control management committee abolished; its work moves to the RMC, which gains one or more independent external IT or cybersecurity experts.
ExceptionsCISO reviews and approves.Up to three months: CISO. Over three months: RMC. Over a year: the board, with reassessment beyond twelve months and the risk documented.
Intermediary auditsSubmitted to insurers annually.Submitted within 30 days of an audit by a CERT-In empanelled auditor or audit firm meeting Annexure IV.
DPDP ActNot named.Regulated entities must take technical and organisational measures to comply with the DPDP Act and Rules.

Paraphrased from Annexure A to the IRDAI circular of 6 April 2026. The CITSO designation is also dropped, with its functions moved to the CISO and CTO.

Read together, the changes answer the commonest audit finding under the 2023 version: a CISO sitting inside the IT function, reviewing the controls of the person they report to.

04

How fast must an insurer report a cyber incident?

Within six hours. The guidelines require cyber incidents to be reported to CERT-In within six hours of noticing them or being told of them, with a copy to IRDAI and other regulators concerned, and IRDAI's March 2025 circular requires the report to IRDAI itself, in its prescribed format, within the same six hours.

The circular on Cyber Incident or Crisis Preparedness of 24 March 2025 added more than a deadline. Regulated entities must keep ICT logs for 180 days, synchronise clocks, maintain a Cyber Crisis Management Plan, empanel forensic auditors in advance so an investigation can start without procurement delay, and make sure the vendor running the SOC, attack-surface monitoring, red-teaming or the annual assurance audit is not the one engaged as forensic auditor. A compliance report goes to the board, and the minutes to IRDAI.

The guidelines also require ICT logs to be kept for a rolling 180 days within Indian jurisdiction, in line with CERT-In, and protected against tampering. If the incident is a personal data breach, the DPDP duties follow as well: tell the Data Protection Board and each affected person, with the detailed report to the Board within 72 hours. CERT-In and DPDP breach reporting compared sets out the overlap.

05

What audit do the IRDAI guidelines require?

An independent assurance audit every year, by an auditor meeting IRDAI's eligibility criteria, rotated at least every three years. Insurers file the signed report with the board's comments to IRDAI within 90 days of the financial year end or 30 days of the audit's completion, whichever is earlier.

The audit follows the Annexure III format: summary, findings, non-compliances, a risk rating and a checklist mapped to the NIST Cybersecurity Framework functions set out in Annexure I. Insurers use the intermediary's risk rating, under their own board policy, to decide whether to start or continue business with it. Because the board now owns closure within twelve months, a finding that rolls from one annual audit into the next is a governance failure, not only a technical one.

06

What must insurers require of cloud and other vendors?

Contractual control. Insurers must keep exclusive ownership of their data at a cloud provider, including backups; bar the provider from using it for advertising or any secondary purpose; and require notification of a confirmed breach without delay and of a suspected breach within four hours of its discovery.

Beyond cloud, the guidelines expect a right to audit in vendor contracts and security requirements flowed down to every third party that touches insurer data, including the intermediaries covered above. For a SaaS vendor selling to insurers, the four-hour suspected-breach clause is the one to check against your own incident process before you sign. The SaaS sector page covers what regulated customers flow down.

07

How do the IRDAI guidelines sit with the DPDP Act?

The guidelines secure the systems; the DPDP Act governs what an insurer may do with a proposer's or policyholder's personal data. The 2026 revision now requires compliance with the Act explicitly, but the Act's duties of notice, consent, purpose limitation and erasure are not satisfied by a security audit.

The place insurers most often come unstuck is data about people who never became customers: health and financial information collected during underwriting for proposals that were declined or lapsed. The insurance sector page works through that, and the DPDP Act and Rules guide sets out the timetable, with substantive duties from 13 May 2027.

08

Where TryTrustable fits, and where it does not

TryTrustable is not an IRDAI-eligible audit firm and does not ship the IRDAI checklist as a built-in framework. It maps controls across ISO 27001, SOC 2 and CERT-In, supports custom framework authoring for a regulator's list, and keeps a hash-chained evidence ledger. The consent platform handles the DPDP side: versioned notices, the consent record, rights requests and the breach clock.

Questions

The things people ask us

Which IRDAI cybersecurity guidelines apply in 2026?

The IRDAI Information and Cyber Security Guidelines, 2026, issued by circular on 6 April 2026. They replace the 2023 guidelines of 24 April 2023 and regulated entities are expected to comply from the current financial year. Most of the 2023 structure survives; the changes are in governance, audit and exceptions.

Who do the IRDAI cybersecurity guidelines apply to?

All insurers, including foreign reinsurance branches, and insurance intermediaries regulated by IRDAI, such as brokers, corporate agents, web aggregators and TPAs. Individual agents, micro-insurance agents, point-of-sale persons and individual surveyors are outside, but each insurer must make them follow a minimum framework through its board-approved policy.

How quickly must an insurer report a cyber incident?

Within six hours of noticing it, or of being told about it. The guidelines require reporting to CERT-In within six hours with a copy to IRDAI, and IRDAI's circular of 24 March 2025 requires regulated entities to report cyber incidents to IRDAI in its prescribed format within the same six hours.

How often must an insurer have a cybersecurity audit?

Every year. An independent assurance audit is carried out annually, the auditor is rotated every three years, and an insurer submits the signed report with its board's comments to IRDAI within 90 days of the financial year end or 30 days of the audit, whichever is earlier. Intermediaries submit theirs to their insurers.

Do the IRDAI guidelines mention the DPDP Act?

Yes. The 2026 guidelines require regulated entities to take appropriate technical and organisational measures to comply with the Digital Personal Data Protection Act and its rules. The DPDP duties to policyholders and proposers, including notice, consent and erasure, sit alongside the security controls rather than inside them.

What must an insurer's cloud provider do after a breach?

Tell the insurer. The guidelines require insurers to contract for notification of any confirmed breach without delay, and of a suspected breach within four hours of its discovery. The insurer must also keep exclusive ownership of its data, including backups, and bar the provider from using it for advertising or any other secondary purpose.

Board-owned, twelve-month closure

Make the finding list something the board can read.

See how control results, exceptions and their approvals land in one ledger, so the annual audit starts from evidence rather than from a spreadsheet.