惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Hugging Face - Blog
Hugging Face - Blog
量子位
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
D
Docker
罗磊的独立博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
IT之家
IT之家
MyScale Blog
MyScale Blog
Microsoft Azure Blog
Microsoft Azure Blog

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates
What SEBI's draft stock exchange technology rules propose
Prabhanu Kumar Das · 2026-06-24 · via MEDIANAMA

The Securities and Exchange Board of India (SEBI) has proposed opening up Direct Market Access (DMA) to all categories of investors as part of a broader overhaul of technology and trading infrastructure rules for stock exchanges. DMA allows investors to place orders directly into an exchange’s trading system through a broker’s infrastructure, without manual intervention from the broker’s dealing desk. It is currently available only to institutional clients.

On June 22, SEBI released a consultation paper titled “Consultation Paper on Draft Circular for Trading Software and Technology at Stock Exchanges and Draft Consolidated Circular on Common Information Technology (IT) Related Provisions for MIIs”. The paper proposes changes to technology, cybersecurity, audit, disaster recovery, algorithmic trading, and market access requirements. It also seeks to consolidate several existing provisions applicable to stock exchanges, clearing corporations, and depositories. Public comments on the proposals can be submitted until July 13, 2026.

This consultation paper is the fourth in a series stemming from the Finance Minister’s FY2023-24 budget announcement to simplify and reduce compliance costs in the financial sector. 

Investment managers using DMA need not be SEBI-registered: The draft proposes removing the requirement that investment managers acting on behalf of clients be registered with SEBI. However, clients would remain responsible for ensuring that their investment managers comply with the applicable terms and conditions. Exchanges and brokers would also be required to maintain audit trails that can identify both the ultimate client and the investment manager at all times.

Single-window approval proposed for Smart Order Routing: SEBI has proposed replacing the current system under which brokers must apply separately to each stock exchange for Smart Order Routing (SOR) approval, with a unified common portal. Under the draft, a broker would submit a single application listing all exchanges where it intends to offer SOR, and only one exchange would be responsible for processing that approval. The responsibility would be allocated on a round-robin basis across exchanges.

Stock exchanges, in consultation with the Industry Standards Forum, would be required to develop the portal and an accompanying standard operating procedure (SOP) within three months of the circular coming into effect.

Cybersecurity provisions updated

The draft proposes:

  • Replacing references to specific technologies, such as SSL with a broader requirement to use “strong and latest security/cryptographic protocols”.
  • Mandating two-factor authentication for system access.
  • Requiring port whitelisting based on business use.
  • Requiring network segmentation between public-facing systems and core trading infrastructure.
  • Requiring audits of firewall configurations, web application firewalls (WAFs), and intrusion detection and prevention systems (IDS/IPS).

The regulator has also proposed prohibiting the storage of sensitive authentication information, including user IDs, passwords, keys, hashes, hard-coded references, and session login details, on trading devices.

Backup and disaster recovery requirements revised: The paper proposes making adequate backup and restore systems mandatory for brokers, rather than merely advisable.

It also proposes changes to disaster recovery requirements. Stock exchanges and other market infrastructure institutions (MIIs) would be allowed to seek SEBI approval for exceptions to the requirement of maintaining one-to-one correspondence between production and disaster recovery infrastructure.

In addition, MIIs would be permitted to submit disaster recovery drill reports with comments from their technology committee first and provide board comments at a later stage.

Annual system audit framework streamlined

Under the proposed framework:

  • System audit reports would have to be submitted within three months of the end of the audit period.
  • Comments from the Standing Committee on Technology (SCOT) could accompany the report initially, with board comments submitted later.
  • Follow-up audits would be required by the next quarter.
  • Auditors could conduct audits for up to three consecutive years, subject to cooling-off requirements.

Certain routine submissions relating to algorithmic trading, simulated trading environments, cybersecurity incidents, and other technology-related matters would be routed to SCOT instead of being filed directly with SEBI.

Changes proposed for algorithmic trading: The draft introduces several modifications to algorithmic trading requirements. Instead of requiring all approved user IDs to participate in mock trading sessions, exchanges would require participation from all approved algorithms and related application servers. The proposal also removes the phrase “after market hours” from testing-environment requirements and adds Enhanced Trading Interface (ETI) to existing audit provisions covering trading connectivity systems.

Also read: