Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

RBI Cybersecurity Directions 2026: What Regulated Entities Must Do Now

RBI replaced its IT governance and cyber framework with entity-specific 2026 Directions for banks, SFBs and NBFCs. What they require and how to respond.

14 min readBy , Director

Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

Regulatory Compliance: What RBI's 2026 Directions changed. Illustrated cover by SecureRoot Risk Advisory.

Yes, the earlier framework has been replaced for the largest groups of regulated entities. On July 31, 2026 the Reserve Bank of India issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs. Each came into force immediately and repealed the existing IT governance and cybersecurity instructions for that entity type. The core obligations are familiar, including six-hour incident reporting on DAKSH for banks and larger NBFCs, but they now sit in one instrument per entity type.

The current instruments at a glance

The RBI has moved from one set of IT governance Directions covering several entity types to a family of Directions, one per regulated entity type. The three we confirmed on rbi.org.in are below.

Entity type Instrument Reference Issued In force
Commercial banks Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 RBI/DoS/2026-27/410 July 31, 2026 Immediately
Small finance banks Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 RBI/DoS/2026-27/419 July 31, 2026 Immediately
NBFCs Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 RBI/DoS/2026-27/461 July 31, 2026 Immediately

If your entity is not in this table, do not assume anything yet. Payments banks, credit information companies and All India Financial Institutions were all inside the scope of the 2023 Directions. We could not confirm from rbi.org.in that a final 2026 instrument exists for each of them. Check the RBI Master Directions listing for your entity type before you re-baseline.

What was replaced, and what was not

The instrument most compliance teams have worked to since April 2024 is the Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023 (RBI/2023-24/107, dated November 7, 2023). It took effect on April 1, 2024 and itself consolidated and repealed twelve earlier circulars. It applied to scheduled commercial banks other than regional rural banks, small finance banks, payments banks, Top, Upper and Middle Layer NBFCs, credit information companies, and the All India Financial Institutions (EXIM Bank, NABARD, NaBFID, NHB and SIDBI).

The 2026 Directions cut that shared instrument apart. The commercial bank Directions state that the existing directions, instructions and guidelines on the cybersecurity framework and IT governance, as they apply to commercial banks, stand repealed. The repeal is tied to circular DoS.CO.PPG.66/11.01.005/2026-27 of July 31, 2026. The small finance bank Directions use the same wording for small finance banks. The NBFC Directions repeal the existing IT Framework and IT governance instructions as they apply to NBFCs.

Two practical points follow. First, the repeal is scoped to the entity type. Nothing in these three documents repeals the 2023 Directions for an entity type they do not cover. Second, each instrument keeps the usual savings language: rights and obligations that arose under the old instructions continue to be governed by them. Evidence from past audits and past incident reports still matters.

Who each set of Directions covers

Commercial banks. The commercial bank Directions apply to commercial banks as defined under the Banking Regulation Act, 1949. They exclude small finance banks, payments banks and local area banks. Foreign banks operating through branches follow a "comply or explain" approach for specified chapters.

Small finance banks. A standalone instrument, RBI/DoS/2026-27/419, applies only to small finance banks. It covers board oversight through an IT Strategy Committee, a senior CISO, a cyber security operations centre, VAPT, business continuity, third-party controls and incident reporting.

NBFCs. The NBFC Directions are the biggest change. The 2023 Directions covered only Middle, Upper and Top Layer NBFCs. The 2026 Directions apply to all NBFCs registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 and the National Housing Bank Act, 1987, with requirements layered by size:

NBFC category Applicable chapter
Base Layer with assets below ₹500 crore, and Core Investment Companies Chapter III
Base Layer with assets of ₹500 crore and above Chapter IV
Middle, Upper and Top Layers (excluding CICs) Chapter V

For a Base Layer NBFC that sat outside the 2023 Directions, this is a new baseline to build, not a re-mapping exercise.

Governance: board, IT Strategy Committee and CISO

The commercial bank Directions are organised into eight chapters: Preliminary; Role of the Board; Information Technology Governance and Oversight; IT and Information Security Risk Management; Baseline Cybersecurity and Resilience Requirements; Cyber Security Operations Centre; Information Systems Audit; and Repeal and Other Provisions.

For commercial banks, the governance requirements are specific:

  • Board. The board approves the IT and cybersecurity strategy and reviews the related policy at least annually.
  • IT Strategy Committee. At least three directors, chaired by an independent director with a minimum of seven years' experience in managing information systems. It meets at least quarterly.
  • CISO. A senior executive, preferably at General Manager rank or equivalent, with the requisite technical background and a reasonable minimum term. The CISO reports directly to the Executive Director or equivalent executive overseeing risk management, and updates the board or its committee at least quarterly.

Chapter V of the NBFC Directions (paras 81-82) carries the same CISO reporting line: to the executive overseeing risk management, not to the head of IT. Read the chapter that applies to your layer to confirm which governance provisions bind you.

The CISO reporting line is where we expect many findings. Plenty of mid-sized lenders still have the security lead reporting to the CTO. That structure does not match the text.

Operational controls you will be tested on

The table compares headline operational requirements in the two instruments we reviewed in detail. NBFC obligations differ by layer, so the NBFC column names the chapter each one sits in. Where a row says nothing about Chapter III, we found no matching requirement for Base Layer NBFCs below ₹500 crore or CICs.

Requirement Commercial banks NBFCs
Cyber incident reporting Within six hours of detection on DAKSH; proactively notify CERT-In Chapters IV and V only: within six hours of detection on DAKSH (paras 28 and 141). Chapter V only: proactively notify CERT-In (para 141)
Vulnerability assessment At least every six months (critical systems) Chapter V only: at least once every six months
Penetration testing At least once in 12 months (critical systems) Chapter V only: at least once in 12 months
DR drills, critical systems Half-yearly Chapter V only: half-yearly (para 129)
Security operations centre CSOC with 24x7 monitoring Chapter V only (Middle, Upper and Top Layers)
IS audit Audit Committee approves the IS Audit Policy and reviews it annually; risk-based planning Chapter IV (Base Layer, ₹500 crore and above): ideally at least once a year (para 56). Chapter V: risk-based audit planning (para 153) and may consider continuous auditing of critical systems (para 154); no fixed annual cycle

Sources: commercial bank Directions and NBFC Directions.

Incident reporting. The commercial bank Directions require reporting within six hours of detection on DAKSH, the RBI's supervisory monitoring platform, with proactive notification to CERT-In. The NBFC Directions set the same six-hour DAKSH requirement for Base Layer NBFCs of ₹500 crore and above (Chapter IV, para 28) and for Middle, Upper and Top Layer NBFCs (Chapter V, para 141). Only Chapter V adds proactive notification to CERT-In (para 141). Chapter III, which covers smaller Base Layer NBFCs and CICs, contains no equivalent reporting provision. The small finance bank Directions carry the same six-hour DAKSH requirement. The clock runs from detection, so your logs need to show when it started.

VAPT. For commercial banks, the six-monthly VA and annual PT cadence covers critical information systems and systems in the DMZ with a customer interface, with a risk-based approach for non-critical systems. Both the commercial bank and the NBFC texts require testing by independent information security experts or auditors, with post-implementation testing on the production environment. For NBFCs, the VA/PT provisions sit in Chapter V of the NBFC Directions (paras 121 to 126), so they bind Middle, Upper and Top Layer NBFCs.

Cyber Crisis Management Plan. Commercial banks must document a CCMP as part of the board-approved cybersecurity framework, addressing detection, containment, response and recovery. The Directions also describe red teaming as an exercise to identify vulnerabilities and assess the efficacy of defences.

Third parties. Commercial banks must satisfy themselves about the credentials of vendor and third-party personnel who access critical assets, with background checks, non-disclosure agreements and security policy compliance agreements mandated. Chapter IV of the NBFC Directions (para 62) requires outsourcing contracts to give the NBFC and the RBI access to documents, records of transactions, and other necessary information, and a right to audit the service provider.

What to do in the next 90 days

  1. Confirm your instrument. Identify which 2026 Directions apply, or confirm that none has been finalised for your entity type. NBFCs should record their layer and the chapter that follows from it.
  2. Re-map your control library. Every control, policy clause and board paper that cites a 2023 paragraph needs a new reference.
  3. Test the six-hour path. If the six-hour DAKSH duty applies to you (commercial banks, small finance banks, and Chapter IV and V NBFCs), run a tabletop that starts at first detection and ends with a DAKSH submission and, where your instrument requires it, a CERT-In notification. Time each step.
  4. Check the CISO reporting line. If the CISO reports into IT, take the change to the board now.
  5. Reset the VAPT calendar. Commercial banks and Chapter V NBFCs should list critical and customer-facing systems and confirm the six-monthly VA and annual PT cadence with an independent tester.
  6. Close the SOC gap. Middle, Upper and Top Layer NBFCs without a SOC need a build-or-buy decision. Commercial banks should test their CSOC against the 24x7 expectation.

Where SecureRoot fits

We help regulated entities turn these Directions into a working control set. A virtual CISO engagement can run the gap assessment against your applicable instrument, prepare board and IT Strategy Committee papers, and track remediation. Our VAPT service covers six-monthly vulnerability assessments and annual penetration tests for critical and internet-facing systems. SOC as a service gives lenders without an in-house operations centre round-the-clock monitoring and triage that can feed a six-hour reporting process. Where an ISO 27001 programme already exists, we reuse its risk register and evidence rather than starting again, and where customer personal data is in scope the same work supports DPDP Act compliance.

Frequently asked questions

Did the RBI replace the 2023 IT Governance Directions in 2026?

For commercial banks, small finance banks and NBFCs, yes. On July 31, 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for each of these three entity types. Each instrument repeals the existing directions, instructions and guidelines on IT governance and the cybersecurity framework as they apply to that entity type. The repeal is scoped by entity type, so it is not a blanket withdrawal of the November 2023 Directions. Payments banks, credit information companies and the All India Financial Institutions were also covered by the 2023 Directions. If you are one of them, check the RBI Master Directions listing for your entity type before assuming either instrument applies to you. Rights and obligations that arose under the repealed instructions continue to be governed by them, so older audit reports, remediation trackers and incident records still matter at inspection.

How quickly must a bank or NBFC report a cyber incident to the RBI?

Within six hours of detection, if your instrument carries the duty. The commercial bank and small finance bank Directions of 2026 require cyber incidents to be reported on DAKSH, the RBI's supervisory monitoring platform, within six hours of detection. The NBFC Directions set the same six-hour DAKSH requirement for Base Layer NBFCs of ₹500 crore and above (Chapter IV) and for Middle, Upper and Top Layer NBFCs (Chapter V), and Chapter V adds proactive notification to CERT-In. Chapter III, which covers smaller Base Layer NBFCs and Core Investment Companies, has no equivalent provision. The commercial bank text also requires proactive notification to CERT-In. Where the duty applies, the clock starts at detection, not at the end of internal triage, so your SIEM and ticketing records need a clear detection timestamp. We recommend that the people who can submit on DAKSH should be reachable at any hour, with a named deputy. Run a timed tabletop exercise and fix whichever step takes the longest.

Do Base Layer NBFCs now have to comply with RBI cybersecurity requirements?

Yes, but not all to the same depth. The November 2023 IT Governance Directions applied only to Middle, Upper and Top Layer NBFCs. The NBFC Directions issued on July 31, 2026 apply to all NBFCs registered with the RBI, with obligations layered by size. Base Layer NBFCs with assets below ₹500 crore, together with Core Investment Companies, follow Chapter III. Base Layer NBFCs with assets of ₹500 crore and above follow Chapter IV, which adds six-hour incident reporting on DAKSH. Middle, Upper and Top Layer NBFCs, excluding CICs, follow Chapter V, which also carries six-hour reporting, VAPT, the security operations centre and risk-based IS audit. For a smaller Base Layer lender that has never been in scope, the first job is to read Chapter III line by line and build a short control register from it, rather than importing controls written for larger lenders. Recheck the chapter whenever assets approach the ₹500 crore threshold.

How often must regulated entities run VAPT under the 2026 Directions?

For critical information systems, vulnerability assessment is required at least once every six months and penetration testing at least once every 12 months. The commercial bank Directions apply this cadence to critical systems and to systems in the DMZ with a customer interface, and allow a risk-based approach for non-critical systems. The NBFC Directions set the same six-monthly VA and annual PT cadence in Chapter V, so it binds Middle, Upper and Top Layer NBFCs; we found no equivalent in Chapters III or IV. Both the commercial bank and NBFC texts require testing by independent information security experts or auditors, including testing on the production environment after implementation. In practice, keep a current list of critical and customer-facing systems, because the obligation follows that list. Schedule a retest after significant changes, not only on the calendar date, and keep closure evidence and retest reports ready for supervisory review.

Who should the CISO report to under the RBI Directions?

Not to the head of IT. The commercial bank Directions require a senior executive, preferably at General Manager rank or equivalent, to be designated as CISO, with the requisite technical background and a reasonable minimum term. The CISO reports directly to the Executive Director, or equivalent executive, overseeing the risk management function, and updates the board or its committee at least quarterly. Chapter V of the NBFC Directions (paras 81-82) uses the same reporting line and states that the CISO should not report directly to the head of the IT function. The reason is independence: the person assessing technology risk should not answer to the person running the technology. If your organisation chart still places security under the CTO or CIO, treat it as a board item, and record the change, its effective date and the CISO's staffing in the next IT Strategy Committee minutes.

Next step

If you need to know where your entity stands against its 2026 Directions, book a 30 minute scoping call. We will confirm which instrument applies to you and send a written scope, a timeline and a fixed price for the gap assessment.

Have a Question About This?

If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.

We reply within one business day.

All Articles
  • Regulatory Compliance: SEBI CSCRF, category by category. Illustrated cover by SecureRoot Risk Advisory.
    Regulatory Compliance17 min read

    SEBI CSCRF Compliance Guide: Categories, Audits, VAPT and SOC

    SEBI's Cybersecurity and Cyber Resilience Framework replaced the older sector circulars with one graded regime. This guide sets out which category you fall in, the deadlines after each extension, and what VAPT, cyber audit and SOC work each category owes.

    Read Article
  • SOC 2: SOC 2 Type 1 or Type 2 first?. Illustrated cover by SecureRoot Risk Advisory.
    SOC 214 min read

    SOC 2 Type 1 vs Type 2 for Indian Companies: Which to Get First

    A Type 1 report tests control design on one date; a Type 2 tests whether those controls operated across an observation period. Here is how Indian companies choose between them, and what each costs in time and money.

    Read Article
  • Penetration Testing: CERT-In Directions, in practice. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing14 min read

    CERT-In Directions Compliance in India: 6-Hour Reporting, Logs and NTP

    The CERT-In Directions of 28 April 2022 apply to almost every organisation running ICT systems for Indian users. This guide walks through each obligation, what CERT-In's own FAQs clarify, and how VAPT and log monitoring make the 6-hour clock achievable.

    Read Article