The Evolving Threat Landscape
The insurance sector in India is going through some big changes when it comes to cybersecurity. On April 6, 2026, the Insurance Regulatory and Development Authority of India (IRDAI) came out with revised Information and Cyber Security Guidelines that replace the older 2023 framework. This isn't just another regulatory update—it's a complete overhaul of how insurance companies and intermediaries need to think about and handle cybersecurity.
The new guidelines apply to all insurers (including foreign re-insurance branches) and insurance intermediaries like brokers, corporate agents, web aggregators, TPAs, and even the Insurance Information Bureau of India (IIB). If you're working in the insurance sector, these changes directly affect you. And the regulator has made it pretty clear that compliance isn't optional—it's mandatory from the current financial year itself.
The driving force behind these changes is pretty straightforward. There have been some high-profile data breaches in the insurance sector lately that exposed just how vulnerable the industry really is. The evolving threat landscape, combined with feedback from industry players and recommendations from various IRDAI committees, pushed the regulator to act. The goal is simple—help the insurance industry strengthen its defences and governance mechanisms to deal with emerging cyber threats effectively.
So, what exactly has changed? Let me break it down for you in plain English.

What's New in the IRDAI Cybersecurity Guidelines 2026?
Governance Gets a Major Overhaul
One of the biggest changes is how governance is structured. The regulator has fundamentally altered the architecture within which cybersecurity decisions are made. And honestly, it's about time.
Board of Directors Now Accountable: Earlier, the board's role in cybersecurity was vaguely defined. Not anymore. The regulator now explicitly requires the board to receive and review the status of non-conformities identified during the annual cybersecurity audit. They also need to approve timelines for closing gaps and ensure those gaps are closed within 12 months of reporting. This is a big shift—cybersecurity is now treated as a core enterprise risk, not just a technical or operational concern.
Introduction of IT Steering Committee (ITSC): The new guidelines mandate that every regulated entity must constitute an IT steering committee. This committee is responsible for the organization's IT strategy and implementation of IT architecture that meets statutory and regulatory compliance. The creation of this committee basically separates the \"IT execution\" function from \"security oversight.\" The Information Security Risk Management Committee focuses on risk and compliance, while the ITSC focuses on implementation. The committee must meet at least quarterly with the Chief Technology Officer acting as its convener.
More Frequent ISRMC Meetings: The Information Security Risk Management Committee (ISRMC) used to meet at least twice a year. Now, they need to meet at least once every quarter. This shift from periodic oversight to continuous monitoring reflects the reality that cyber threats evolve rapidly and demand more frequent review.
Independent External Experts Required: Here's something interesting—the regulator now requires regulated entities to appoint one or more independent external experts to the Risk Management Committee. These experts must have substantial IT or cybersecurity expertise. This ensures that at least one independent voice with cybersecurity expertise scrutinises the entire programme from outside the management chain.
Elimination of Control Management Committee: The requirement to constitute a \"Control Management Committee\" has been abolished. Its functions are now merged into the Risk Management Committee. This simplifies the governance structure while ensuring that control and risk oversight continues under a streamlined framework.
CISO Gets Independence: This is a big one. The Chief Information Security Officer (CISO) can no longer report to the head of IT (usually the CTO). The regulator explicitly prohibits this to prevent business functions from influencing cybersecurity functions. The CISO also cannot be assigned business targets. Additionally, the CISO must be \"adequately staffed with people having relevant technical expertise,\" which implies that a solo CISO with no team would be non-compliant. Regulated entities must therefore budget for an entire CISO office. The CISO is now designated as the convener of the Information Security Risk Management Committee and a permanent invitee to the newly mandated IT Steering Committee. They're also responsible for developing scenario-based incident response plans, reviewing all security exception requests, and ensuring compliance with CERT-In directions.
Removal of CITSO Requirement: The requirement to appoint a Chief Information Technology Security Officer has been done away with. The functions previously assigned to this role are now to be absorbed by the CISO and the CTO.
Board-Level Budgeting Requirements
The regulator now requires the board to provide a sufficient cybersecurity budget that is proportional to the organisation's risk appetite. But here's the catch—the requirement for \"sufficient\" and \"proportional\" budgeting lacks any defined benchmark. This creates what some legal experts call a \"hindsight trap,\" where a regulated entity could be held liable post-breach simply because the regulator determines, in retrospect, that the budget was insufficient, regardless of the actual sum spent.
Security Domain Policies: A Shift in Approach
Unlike other Indian financial sector regulators that favour principles-based frameworks, IRDAI had been uniquely prescriptive under the earlier framework. It specified the terms of information security policies (like data classification policy, cloud security policy, etc.) that regulated entities were required to implement.
The 2026 guidelines attempt to soften this prescriptive approach. It clarifies that these information security policies constitute \"guidance\" for regulated entities to frame their own policies. However, the latest guidelines mandate that these domain policies \"shall be a part of\" the regulated entity's approved infosec policy. Many of the specific controls within these policies are mirrored word-for-word as controls that an auditor is required to assess as part of the annual cybersecurity audit. In practice, regulated entities are likely expected to adopt the guidance prescribed, unless any deviation can be adequately justified on the basis that such deviation does not conflict with the guidance or give rise to cybersecurity risks.
Strict Subcontracting Controls
The guidelines prescribe stringent supply chain controls that regulated entities must implement. Regulated entities must now include provisions that prohibit third-party service providers from further outsourcing any activity without prior written permission.
This requirement is actually somewhat incompatible with the modern tech economy. Hyperscale service providers (large cloud service providers, for instance) change sub-processors frequently and won't be able to seek permission from thousands of regulated entities. This effectively forces regulated entities to choose between technical non-compliance and abandoning major service providers. Legal experts suggest that careful implementation of \"deemed consent\" provisions for subcontracting would enable regulated entities to meet the regulatory bar.
Cloud Services and Data Localisation
The regulator's security domain policies prohibit regulated entities from using any cloud service providers unless they're empanelled with the Ministry of Electronics and Information Technology (MeitY) with a valid STQC audit status. For any cloud service provider to be empanelled, it must have data centres in India. While the insurance regulator had indicated in the past that certain datasets must be stored on data centres in India, this localization requirement under the guidelines broadly applies to any cloud service provider, including \"software-as-a-service providers.\"
This is a significant challenge. Most specialized software-as-a-service tools (from actuarial modeling to niche HRMS systems) operate on a globally distributed basis and may not use government-empanelled data centres in India. The IRDAI has effectively outlawed overseas deployment of software stacks offered by global players.
The guidelines also require all regulated entities to bind their cloud service providers to \"completely eliminate any trace\" of data upon termination of their engagement. Regulated entities must review all their cloud service provider relations for government empanelment and renegotiate contracts to include mandatory data deletion clauses.
Segregation of Infrastructure
Taking a cue from the securities regulator and to prevent group security incidents from spilling over to the regulated entity's infrastructure, the IRDAI requires infrastructure, networks, and databases to be logically and/or physically segregated where a regulated entity shares resources with its group companies. Where a service provider provides services to group companies, IT personnel with cross-entity access must also be segregated wherever possible.
As a matter of practice, most regulated entities share IT resources (data centres, network backbone, security operations centre, employees, etc.) across their group, sometimes even through an in-house \"shared services\" entity. Large insurance groups consisting of life insurance, general insurance, asset management, and sometimes a broking arm all draw from the same infrastructure pool. The guidelines now require these regulated entities to review their segregation practices.
DPDP Act Compliance Integration
The guidelines explicitly require all insurers and insurance intermediaries to implement technical and organizational measures to comply with the Digital Personal Data Protection Act, 2023 (DPDPA). Compliance in this regard will be evaluated as part of the regulatory annual audit.
The compliance requirement for a regulated entity is now three-tiered: CERT-In directions, the IRDAI Cybersecurity Guidelines (concerned with information and cybersecurity), and the DPDPA (concerned with lawfulness of processing and data rights). By incorporating DPDPA compliance into the annual cybersecurity audit, the regulator has confirmed that data protection and cybersecurity are not parallel obligations but overlapping mandates with distinct authorities, obligations, and penalty regimes.
Penetration Testing Requirements
The regulator has moved from less intrusive \"black box penetration testing\" to more intrusive \"grey/white box penetration testing\" for all internet-facing information systems. These tests must now be conducted by a CERT-In empanelled auditor.
Grey and white box testing may require regulated entities to provide auditors with internal architectural details, credentials, or source code. This requirement assumes that the regulated entity possesses an exhaustive inventory of all components that constitute internet-facing systems, even where it relies on third parties for these systems. Regulated entities must gear up to secure this inventory from their third-party service providers in sufficient granularity.
This requirement also creates a risk of disclosure of critical information (quite often, trade-secret data) to auditors that may often serve competitors of the auditee. Putting in place appropriate confidentiality controls for the auditor's team that undertakes testing is imperative.
Cryptographic Asset Inventory
Organisations must maintain an up-to-date inventory of cryptographic assets to prepare for the transition to post-quantum cryptographic environments. This is a forward-looking requirement that acknowledges the coming threat of quantum computing to existing encryption standards.
Exception Management Framework
A structured exception management framework has been introduced. Approval for exceptions is now tiered by duration:
- Up to 3 months: CISO approval
- 3 months to 1 year: ISRMC approval
- Beyond 1 year: Board approval
All exceptions exceeding 12 months must undergo reassessment and re-approval. All exceptions must formally document the associated risk. This ensures controlled and accountable exception handling.
IRDAI Cybersecurity Guidelines 2026: Detailed Requirements
Data Classification and Protection
- Four-Tier Classification System: All information assets must be classified into one of four tiers: Public, Internal, Restricted, or Confidential, with security controls calibrated to each level.
- Personally Identifiable Information (PII) Tagging: Organisations must dual-tag any PII—classified under the standard four-tier system and separately flagged as PII.
- Encryption Requirements: Confidential information must be encrypted when transmitted outside the organisation's network, including over the internet, and when stored on mobile or removable media.
- Regular Review: Classification labels must be reviewed at least every two years.
- Sensitive Data Handling: Sensitive data that is not regularly accessed must be removed from the network and either operated as a standalone system or fully virtualised and powered off until needed.
Access Control Measures
- Least Privilege Principle: Access to all systems must follow the principles of least privilege, need-to-know, segregation of duties, and individual accountability.
- Password Policy: Users must change passwords every 45 days. Previously used passwords must be blocked from reuse.
- Privileged Access: Privileged access must be limited to those with documented business justification, comprehensively logged, and reviewed at regular intervals. Vendors and contractors must not gain privileged access without close supervision and monitoring.
- Two-Factor Authentication: All connections to high-severity systems from outside the organisation's network require two-factor authentication.
Network Security
- Perimeter Security: Organisations must deploy perimeter security, including firewalls and intrusion detection systems.
- Network Segmentation: Networks must be segmented based on data classification. Micro-segmentation must be implemented to counter lateral movement.
- Web Application Firewalls: Web Application Firewalls (WAFs) must be deployed for all web-facing applications.
- Email Security: Organisations must implement DMARC, SPF, and DKIM standards to reduce the prevalence of spoofed emails. DNS filtering must be used to block malicious domains. Sandboxing must be deployed to analyse and block malicious email attachments.
Cryptographic Controls & Risk Assessment
- Key Management Lifecycle: Cryptographic controls must be applied based on data classification. Organisations must define a key management lifecycle and protect keys from modification and loss. Keys must not be transmitted over networks unless through secure channels.
- Risk Assessment Frequency: Risk assessments must be conducted at least annually and ahead of major technology changes, new outsourcing arrangements, or granting external access to critical systems.
Audit and Compliance
- Annual Cybersecurity Audit: An independent assurance team must carry out an annual audit and present the audit plan and findings to the Audit Committee, RMC, or Board, as applicable.
- Auditor Rotation: The independent assurance auditor must be rotated every three years.
- Audit Submission Timeline: Insurers must submit their audit report to IRDAI within 90 days of the end of the financial year or within 30 days of audit completion, whichever is earlier. Insurance intermediaries must submit their audit compliance report within 30 days of completion of the audit.
- DPDP Act Compliance: Regulated entities must take appropriate technical and organisational measures to comply with the Digital Personal Data Protection Act. Compliance in this regard will be evaluated as part of the annual audit.
Operational Security & Outsourcing
- Cyber Incident Reporting: All cyber incidents must be reported to CERT-In within six hours of detection, with copies to IRDAI and other relevant regulators.
- BCP and DR Testing: Business Continuity Planning (BCP) and Disaster Recovery (DR) plans must be tested at least annually, with results reported to the ISRMC. Tests must cover real disaster scenarios, not only planned shutdowns.
- Foreign Reinsurance Branches (FRBs): FRBs are not required to constitute separate governance committees at the branch level, provided that the prescribed responsibilities are discharged at the regional, controlling or head office level. FRBs may adopt a \"comply or explain\" approach, subject to the supervisory process.
- Third-Party Vendor Management: All third-party vendor contracts must include right-to-audit clauses. If a vendor holds a valid ISO 27001 certification covering the scope of services, the organization may waive periodic audits, subject to the vendor's self-certification and submission of valid certification copies.
- Cloud Service Providers: Cloud service providers must be empanelled by MeitY and hold a valid STQC audit status. NDAs covering privacy, confidentiality, security, and BCP must be signed. Contracts must require CSPs to eliminate all data from disks and backups upon termination.
- Sub-Outsourcing Control: Regulated entities must contractually require service providers to obtain prior written permission before any further sub-outsourcing.
Other Security Domains
- Remote Work Security: Provision VPN, endpoint protection, data encryption, and data loss prevention (DLP) mechanisms on all user systems. Hardening checks must be conducted on systems returned to the office.
- Business-Level Accountability: Functional heads are now responsible for enforcing cybersecurity policies within their teams, collaborating with CISO on risk management, and reporting incidents promptly.
- Cybersecurity Exercises: Organizations must participate in national and sectoral cybersecurity exercises and drills, such as CERT-In's Cybersecurity Exercises Programme.
- Forensic Investigations: The CISO may engage externally certified forensic experts for investigations as and when required.
- Scope Exclusions: Insurance agents, micro-insurance agents, point-of-sale persons, and individual surveyors fall outside the guidelines' direct scope. However, insurers must ensure that these entities follow a minimum security framework defined under the insurer's Board-approved policy.
Why These Changes Matter
The 2026 guidelines represent a fundamental shift in how IRDAI views cybersecurity. It's no longer just about ticking boxes—it's about building resilience. The regulator has made it clear that cybersecurity is a core governance obligation that requires board attention, independent oversight, and adequate resourcing.
For regulated entities, the message is clear: compliance is not optional, and the time to act is now. The immediate priority is implementation—and demonstrating that implementation to auditors, the regulator, and the market.
The changes introduced by the guidelines signal that the regulator expects organisations to view cyber risk as an evolving threat that demands frequent scrutiny. The increased frequency of ISRMC meetings from twice a year to quarterly is a clear indication of this expectation.
IRDAI Cybersecurity Compliance Checklist for 2026
If you're an insurer or insurance intermediary, here's a quick checklist to help you navigate the new requirements:
Governance & Leadership
- Ensure quarterly ISRMC meetings
- Establish IT Steering Committee with quarterly meetings
- Strengthen board-level cybersecurity oversight
- Appoint independent external cybersecurity experts to RMC
- Eliminate Control Management Committee (functions merged into RMC)
- Establish an independent CISO role (not reporting to IT Head)
- Ensure CISO has no business targets
- Define clear responsibilities for CTO and business heads
- Remove CITSO role (functions absorbed by CISO/CTO)
Security Operations & Data Protection
- Implement scenario-based incident response plans
- Conduct grey/white-box penetration testing every six months with CERT-In empanelled auditors
- Enable continuous monitoring and detection
- Test BCP and DR plans annually covering real disaster scenarios
- Classify all information assets (Public, Internal, Restricted, and Confidential)
- Dual-tag PII
- Review classification labels every two years
- Implement encryption for confidential data in transit and at rest
- Align with DPDP Act requirements
Cloud, Third-Party & Access Control
- Use MeitY-empanelled cloud providers with valid STQC audit status
- Enforce strict vendor contracts including right-to-audit clauses
- Include mandatory data deletion clauses in cloud contracts
- Control sub-outsourcing risks (require prior written permission)
- Maintain cryptographic asset inventory for post-quantum readiness
- Deploy immutable backups and resilient systems
- Implement infrastructure segregation across group entities
- Follow least privilege principle
- Implement 45-day password rotation
- Restrict and monitor privileged access
- Require two-factor authentication for high-severity systems
Incident, Compliance & Exception Management
- Report cyber incidents to CERT-In within six hours
- Ensure copies to IRDAI and other relevant regulators
- Complete annual cybersecurity audits
- Submit audit reports within defined timelines (90 days of FY end or 30 days of completion)
- Rotate independent assurance auditor every three years
- Implement comply or explain framework for FRBs
- Follow structured approval hierarchy for exceptions (Up to 3mo: CISO, 3-12mo: ISRMC, >12mo: Board)
- Document all risks and approvals and reassess long-term exceptions
- Participate in CERT-In cybersecurity exercises and drills
How to Get Started with IRDAI Compliance
First, don't treat this as a one-time compliance activity. The regulator has made it clear that cybersecurity is a continuous governance obligation. Organisations that proactively align with these changes will not only meet regulatory expectations but also build resilient, future-ready security frameworks.
- Review your governance structure: Do you have the mandated committees? Is your CISO properly positioned? Do you have independent experts on your RMC?
- Review your contracts: Do your cloud contracts include mandatory data deletion clauses? Do they restrict sub-outsourcing without prior permission? Do they include right-to-audit clauses?
- Review your cloud infrastructure: Are your CSPs MeitY-empanelled with valid STQC audit status? Are you in compliance with data localisation requirements?
- Update your penetration testing procedures: Are you conducting grey/white-box testing every six months? Are you using CERT-In empanelled auditors?
- Develop your cryptographic asset inventory: Are you ready for post-quantum security?
- Align with DPDP Act: Have you implemented technical and organizational measures for DPDP compliance?
- Implement exception management: Do you have a structured framework for approving exceptions with appropriate documentation?
- Train your Board: The Board now has expanded responsibilities. Ensure your board members have sufficient cyber literacy to provide meaningful oversight.
- Document your budget: Ensure your cybersecurity budget is \"sufficient\" and \"proportional\" to your risk appetite, and document the rationale behind your budgeting decisions.
- Review your BCP and DR plans: Do they cover real disaster scenarios? Are they tested at least annually?
Final Thoughts
The IRDAI Cybersecurity Guidelines 2026 represent a watershed moment for the insurance sector in India. The regulator has fundamentally altered the governance architecture within which cybersecurity decisions are made and imposed significant new obligations on regulated entities.
The push towards board accountability, independent oversight, and adequate resourcing signals that cybersecurity is no longer a technical concern—it's a core governance obligation. For regulated entities, the immediate priority is implementation. But beyond the compliance checklist, these guidelines offer an opportunity to build genuinely resilient security frameworks that can withstand the evolving threat landscape.
Those who treat this as a checkbox exercise will likely struggle. Those who embrace the spirit of the guidelines—building a culture of continuous improvement and resilience—will not only satisfy the regulator but also gain a competitive advantage in an increasingly digital insurance market.
The clock is ticking. The guidelines are already in effect from the current financial year. Start your compliance journey now—because when it comes to cybersecurity, being proactive is always better than being reactive.
Expert FAQ
Schedule an IRDAI Pre-Audit Readiness Review
IRDAI Cybersecurity compliance doesn't have to be overwhelming. With the right preparation, you can turn a regulatory mandate into a competitive advantage.
Connect with our expert consultants today to assess your governance structure, vendor agreements, cloud configuration, and penetration testing controls.
Get Compliant Now