IRDAI rewrote the guidelines. Here is your year under them.
On 6 April 2026 IRDAI replaced its 2023 cyber security guidelines with the Information and Cyber Security Guidelines, 2026, to be complied with from the current financial year. This page lays out an insurer’s year under them — testing windows, committee meetings, audit reports and deadlines — clears up five myths, and is plain about which parts must go to a CERT-In-empanelled auditor.
Indian insurers and intermediaries now follow the IRDAI Information and Cyber Security Guidelines, 2026, issued on 6 April 2026. They require vulnerability assessment and penetration testing of internet-facing systems every six months by a CERT-In-empanelled auditor, security testing of every change before production, incidents reported to CERT-In within six hours with a copy to IRDAI, a quarterly information security risk committee, and audit gaps closed within twelve months.
April 2026
The same shape, with sharper edges.
IRDAI’s Information and Cyber Security Guidelines, 2026 replace the guidelines of April 2023 and apply from the current financial year to insurers, foreign reinsurance branches and a long list of intermediaries: brokers, corporate agents, web aggregators, TPAs, insurance marketing firms, insurance repositories and others. Individual agents, micro-insurance agents, point-of-sale persons and individual surveyors sit outside them.
Governance moves closer to the bank model. The CISO must not report directly to the head of IT and must carry no business targets. The Information Security Risk Management Committee must meet at least every quarter. The Board must approve timelines for closing the gaps an audit finds and see them closed within twelve months, and the Risk Management Committee must include one or more independent external experts with substantial IT or cyber security expertise.
Testing is specific, and mostly reserved. Vulnerability assessment and external grey- or white-box penetration testing of every internet-facing system are due every six months, and VAPT of critical internal applications at least once a year — all by a CERT-In-empanelled auditor. Every change to an internet-facing system must be security-tested, with the gaps closed, before it reaches production, and business applications and APIs need a security audit, VAPT and secure code review before they go live. Ongoing vulnerability assessment by competent people, and periodic red-team exercises, are expected on top.
The consequences are no longer theoretical. In September 2024 the data of potentially 31 million Star Health customers — including policy and claims documents, ID copies and medical diagnoses — was offered for sale through Telegram chatbots. In July 2025 IRDAI fined the insurer ₹3.39 crore and issued a warning for violations of its 2023 cyber security guidelines. From May 2027, policyholders’ personal data — much of it health data — also comes under the DPDP Act.
The compliance calendar
An insurer’s year under the 2026 guidelines
Laid out on the April–March financial year. Your own dates depend on when your audit and testing cycles fall; the obligations do not.
April
The year opens
Confirm the guidelines’ scope across the group and every intermediary you engage. Plan the two six-monthly VA and PT cycles for internet-facing systems and the annual VAPT of critical internal applications with your empanelled auditor.
By end-June
Last year’s audit report to IRDAI
The auditor-signed audit report, with the Board’s comments, goes to IRDAI within 90 days of the financial year’s end — or within 30 days of the audit’s completion, if that is earlier. Intermediaries send theirs to each insurer they work with within 30 days of their own audit.
Every quarter
ISRMC meets In force now
At least four meetings a year, with the CISO and at least two members. Open findings, gap-closure progress, incidents and changes to the policy are the standing agenda.
By September
First six-monthly VA and PT In force now
Vulnerability assessment and external penetration testing of every internet-facing system, by the empanelled auditor. Where a test has to run in a test environment, it must match production, and any deviation goes to the ISRMC.
Every change
Test before production In force now
Security testing of every change to an internet-facing system, with the gaps closed before it goes live; security audit, VAPT and secure code review before any new business application or API is launched.
By March
Second cycle, internal VAPT and risk assessment Coming
The second six-monthly VA and PT, the annual VAPT of critical internal applications, and the annual risk assessment — plus a red-team exercise and participation in CERT-In drills.
Within 12 months
Gaps closed Coming
The Board approves timelines for closing the gaps the audit found, and they must be closed within twelve months of being reported.
Any day
The six-hour report In force now
A cyber incident goes to CERT-In within six hours of being noticed, with a copy to IRDAI. Logs must already be held for 180 days, in India.
May 2027
DPDP Act duties Coming
Policyholders’ personal data becomes subject to the DPDP Act’s safeguards and breach notice to the Data Protection Board and each affected person.
Summarised from the IRDAI Information and Cyber Security Guidelines, 2026 and the CERT-In Directions. Check the guidelines and their annexures for the formats and full requirements. General information, not legal advice.
What gets assumed
Five things insurers believe about the 2026 guidelines.
Each is common. Each is contradicted by the text.
What people assume“The 2023 guidelines still apply this year.”
What is actually trueThe 2026 guidelines replaced them on 6 April 2026, and IRDAI asked for compliance from the current financial year. Policies, audit scopes and intermediary contracts that cite the 2023 guidelines need updating now.
What people assume“Any competent firm can do our half-yearly VAPT.”
What is actually trueNot for the cycles the guidelines prescribe. VA and PT of internet-facing systems every six months, and VAPT of critical internal applications every year, are to be done by a CERT-In-empanelled auditor. Other firms — including us — can test changes before production, review code, run red-team exercises and carry out ongoing assessment in between.
What people assume“Our intermediaries are their own problem.”
What is actually trueThe insurer must ensure that the intermediaries it engages comply, under a Board-approved policy with a risk rating for each. Intermediaries must send their audit report to every insurer they work with within 30 days of completing their audit by an empanelled auditor.
What people assume“Cyber security is the CISO’s job.”
What is actually trueThe guidelines give named duties to the Board, which approves gap-closure timelines and sees gaps closed within twelve months; to the Risk Management Committee, which must now include independent external experts; and to the Chief Risk Officer. The CISO cannot report to the head of IT or carry business targets.
What people assume“A data leak is a technology problem, not a regulatory one.”
What is actually trueWhen Star Health’s customer data appeared on Telegram chatbots in 2024, the insurer first said there had been no widespread compromise, then acknowledged unauthorised access to certain data weeks later. In July 2025 IRDAI fined it ₹3.39 crore and issued a warning for violations of its cyber security guidelines. The regulator examines the controls, not only the intrusion.
Evidence
The numbers that set the pace
From the guidelines themselves and from the enforcement case that preceded them. Each is linked in the sources.
31MStar Health customers whose data was offered for sale through Telegram chatbots in 2024 [3]
₹3.39 crPenalty IRDAI imposed on the insurer in July 2025, with a warning, for cyber security guideline violations [4]
6 monthsLongest gap between VA and between PT of internet-facing systems, by a CERT-In-empanelled auditor [2]
12 monthsDeadline to close the gaps an audit reports, on timelines the Board approves [2]
90 daysAfter year-end to file the audit report with IRDAI — or 30 days after the audit, if earlier [2]
4 a yearMinimum meetings of the Information Security Risk Management Committee [2]
Star Health first said there had been no widespread compromise and later acknowledged unauthorised access to certain data; the 31 million figure is the hacker’s claim as reported at the time.
Where insurers get hurt
Three patterns the guidelines are written against
One from a reported case; two from the obligations the 2026 guidelines added or sharpened.
01
The data sold by chatbot
Way inPolicyholder data held somewhere it could be taken in bulk — claims documents, ID copies and diagnoses.
ThenSamples handed out by Telegram chatbots to prove the data was real, with the full set offered for sale; new bots appeared as fast as old ones were removed.
CostCustomers’ medical and identity documents in circulation, and a ₹3.39 crore penalty with a warning — Star Health, 2024–25.
What we test: Where claims and policy documents are stored, who and what can reach them in bulk, and whether anyone would notice a large export.
02
The intermediary’s portal
Way inA broker’s, web aggregator’s or TPA’s website or API that handles quotes, proposals or claims, and was tested less often than the insurer’s own.
ThenAccess to the policyholder data the insurer shared with it — and, through integrations, sometimes to the insurer’s systems.
CostA breach the insurer answers for, because the guidelines make it responsible for its intermediaries’ compliance.
What we test: The intermediary’s portals and APIs, the integration with your systems, and what you share with each partner.
03
The change that skipped testing
Way inA new feature, campaign page or API version pushed to an internet-facing system between the six-monthly cycles.
ThenA flaw that was not there at the last assessment, live for months until the next one.
CostExposure the half-yearly schedule cannot see — which is why the guidelines require security testing of every change before production.
What we test: Testing of each change before release, and continuous exposure management between the empanelled cycles.
Next step
Close the gaps between the empanelled cycles.
A 30-minute call with a practitioner who knows the 2026 guidelines. No charge, and no obligation.
Where your programme falls short of the 2026 guidelines
What must go to your empanelled auditor — and what we can do between cycles
How to oversee your intermediaries’ compliance
A fixed price, with a retest of every fix included
Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. None of it replaces the empanelled auditor’s cycles; all of it is designed to leave them less to find.
“Every change, before production.”
Service
Security testing of changes to your portals, apps and APIs before release, so gaps are closed before go-live as the guidelines require.
The IRDAI Information and Cyber Security Guidelines, 2026, issued on 6 April 2026 and replacing the 2023 guidelines.
ISRMC
Information Security Risk Management Committee — governs the information and cyber security policy; meets at least quarterly.
RMC
The Board’s Risk Management Committee, which must now include one or more independent external experts in IT or cyber security.
Independent external expert
A person with substantial IT or cyber security expertise, from outside the organisation, sitting on the Risk Management Committee.
CERT-In-empanelled auditor
An auditing organisation on CERT-In’s list; the guidelines reserve the six-monthly and annual VAPT cycles and the annual audit for such auditors.
Grey- or white-box PT
Penetration testing with some or full knowledge of the system — credentials, documentation or code — rather than none.
Continuous exposure management
Ongoing discovery and assessment of what an organisation exposes, between formal assessments.
FRB
Foreign reinsurance branch — a foreign reinsurer’s branch in India; covered by the guidelines.
TPA
Third-party administrator — handles health claims for insurers, and holds much of the medical data.
Web aggregator
An intermediary that compares insurance products online and passes leads to insurers.
CCMP
Cyber crisis management plan — including the information-sharing arrangements for a large incident.
Questions
Insurance security — answered.
What buyers in this sector ask us before they commit to anything.
What are the IRDAI Information and Cyber Security Guidelines, 2026?
The guidelines IRDAI issued on 6 April 2026 to replace its April 2023 cyber security guidelines, setting minimum standards and governance for insurers and intermediaries. They cover governance — the Board, the Risk Management Committee, the ISRMC and the CISO — and detailed policies on access, assets, cloud, incident response, testing and audit. IRDAI asked regulated entities to comply from the current financial year.
Who do the 2026 guidelines apply to?
All insurers including foreign reinsurance branches, and insurance intermediaries: brokers, corporate agents, web aggregators, TPAs, insurance marketing firms, insurance repositories, ISNP entities, corporate surveyors, MISPs, common service centres, and the Insurance Information Bureau. Individual insurance agents, micro-insurance agents, point-of-sale persons and individual surveyors are outside them.
How often must insurers do VAPT under the 2026 guidelines?
Vulnerability assessment of all internet-facing systems at least every six months, and external grey- or white-box penetration testing of them every six months; VAPT of critical internal applications and infrastructure at least once a year — all by a CERT-In-empanelled auditor. Every change to an internet-facing system must also be security-tested before production, and new business applications and APIs need a security audit, VAPT and secure code review before go-live.
Can a firm that is not CERT-In empanelled do our testing?
Not the prescribed six-monthly and annual VAPT cycles or the annual audit — those go to a CERT-In-empanelled auditor. SemperWise is not empanelled. The guidelines also require testing that is not reserved in the same way: testing of every change before production, ongoing vulnerability assessment by competent personnel, and periodic red-team exercises. That is where we fit, alongside your empanelled auditor rather than instead of it.
When is the annual cyber security audit report due to IRDAI?
Insurers must submit the auditor-signed report, with the Board’s comments, within 90 days of the end of the financial year or within 30 days of completing the audit, whichever is earlier. Intermediaries submit their report to each insurer they work with within 30 days of completing their audit by a CERT-In-empanelled auditor. Gaps must be closed within twelve months of being reported, on timelines the Board approves.
How quickly must an insurer report a cyber incident?
To CERT-In within six hours of noticing it or being told of it, with a copy to IRDAI and any other regulator concerned. Logs must be kept for a rolling 180 days, within India. From about May 2027, a breach of policyholders’ personal data also triggers notice under the DPDP Act to the Data Protection Board and each person affected.
What must an insurer do about its intermediaries?
Ensure the intermediaries it engages comply with the guidelines while they work together, under a Board-approved policy that includes a risk rating for each one, and collect their annual audit reports. In practice that means knowing which intermediaries hold your policyholders’ data or connect to your systems, and testing or assessing those links — see how a TPA or hospital connection can carry risk.
Does the DPDP Act apply to insurers?
Yes. From about 13 May 2027, insurers and intermediaries are Data Fiduciaries or Data Processors for policyholders’ personal data, much of it health data. The Act adds consent and notice duties, reasonable security safeguards, breach notice and rights handling, alongside the IRDAI guidelines. A DPDP readiness assessment maps both.
Sources
Checked by our research desk on 24 September 2026. Regulations and
figures move; where a number here matters to a decision, follow it to the source.
Arrive at the empanelled audit with fewer findings.
A 30-minute call, no charge. You leave knowing where the 2026 guidelines leave gaps in your programme, what must go to your CERT-In-empanelled auditor, and what we can test and fix in between — with a written scope and fixed price if the work makes sense.