PFRDA Information & Cyber Security Policy Guidelines, 2024
Applies to: PFRDA regulated entities — CRAs, pension funds, PoPs, APY-SPs, trustee banks, custodians, non-individual retirement advisors
The pension-sector cyber regime protecting NPS and APY subscriber data. The 2024 guidelines classify regulated entities into Category I (CRAs and pension funds) and Category II (PoPs, APY-SPs, trustee banks, custodians, non-individual RAs), with obligations scaling by category. All entities must adopt a board-approved Information and Cybersecurity Policy, maintain audit trails, conduct annual external audit by a CERT-In empanelled auditor and six-monthly internal audit, and report cyber incidents to CERT-In and PFRDA within 6 hours. The September 2025 circular added a four-tier incident classification (Critical/High/Medium/Low) by business impact. The January 2026 update tightened reporting: PoPs must email incidents to PFRDA, Category I PoPs report quarterly with remedial-action detail, subscriber-affecting incidents are reported within 48 hours, and an annual compliance report is due within 30 days of FY close.
Why it matters
PFRDA has iterated three times in eighteen months — 2024 baseline, 2025 classification, 2026 reporting tightening — which signals an active, not dormant, supervisor despite the sector's lower profile. The Category I/II split is the first thing to get right: it determines your audit cadence and reporting frequency, and misclassification is an easy finding. The 48-hour subscriber-impact report sits alongside the 6-hour CERT-In window, so pension entities effectively run two clocks — build the runbook to trigger both off a single detection event. For an entity also regulated by RBI or SEBI, note PFRDA accepts principal-regulator compliance with a compliance-officer certification.