Regulation · Banking and NBFCs · India
The RBI cybersecurity directions 2026 are the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions the Reserve Bank of India issued on 31 July 2026, one set per type of regulated entity. They took effect immediately, replace the 2016 cyber security framework, and require six-hour incident reporting through DAKSH.
RBI-regulated entities, each under the Directions written for its type.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The RBI cybersecurity directions require Board-led technology governance with a CISO, baseline cybersecurity controls, a C-SOC, six-hour incident reporting, tested business continuity, managed third parties and independent IS audits.
Board, RMCB, IT Strategy Committee and CISO.
In QULDEX: Approvals and reviews trackedNetwork, endpoint, access and crypto controls.
In QULDEX: Controls mapped to evidenceVA every 6 months, PT every 12 months.
In QULDEX: Due dates on the dashboardContinuous monitoring and metrics.
In QULDEX: SOC metrics trackedWithin six hours, plus CERT-In.
In QULDEX: Six-hour timersDR drills for critical systems half-yearly.
In QULDEX: Drill results storedIndependent audit with tracked findings.
In QULDEX: Findings into CAPAThese 19 requirement areas carry most of the work, grouped by theme. Select any one to see what it asks for, typical evidence and the matching ISO 27001 or CERT-In reference.
Showing up to 6 per group. Search, filter, or open a group to see all 19.
BoardBoard and committee oversightTechnology governance sits with the Board, the Risk Management Committee of the Board and the IT Strategy Committee, with senior management accountable.
In QULDEXCommittee reviews and approvals are recorded with dates.
PoliciesBoard-approved policiesBoard-approved IT, information security and cybersecurity policies, reviewed periodically.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
CISOChief Information Security OfficerA CISO with defined responsibilities, reporting to the executive overseeing risk management.
In QULDEXThe CISO's role, reporting line and reports are on record.
ISCInformation Security CommitteeA committee that oversees information security and cyber risk across the entity.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
IT riskIT and cyber risk managementIdentify, assess and treat IT and cyber risks as part of enterprise risk management.
In QULDEXThe risk register holds IT and cyber risks with treatment owners.
BaselineBaseline cybersecurity controlsMinimum controls for network, endpoint, application and data security.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
AccessUser access managementLeast privilege, privileged access controls and periodic access reviews.
In QULDEXAccess reviews run as recurring tasks.
CryptoCryptographic controlsEncryption and key management for data at rest and in transit.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
VAVulnerability assessment every six monthsFixed cadenceRun vulnerability assessments at least every six months and fix findings.
In QULDEXScan findings become CAPA items with due dates.
PTPenetration testing every twelve monthsFixed cadenceRun penetration tests at least every twelve months.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
DataData protectionProtect customer and business data across its lifecycle.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
C-SOCCyber Security Operations CentreContinuous monitoring through a C-SOC with defined use cases and metrics.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
IncidentsIncident reporting within six hoursFixed cadenceReport cyber incidents within six hours of detection through RBI's DAKSH platform, and notify CERT-In.
In QULDEXIncidents carry six-hour reporting timers.
CrisisCyber crisis managementA cyber crisis management plan with response and recovery playbooks.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
BCP/DRBusiness continuity and DR drillsFixed cadenceBusiness continuity and disaster recovery, with DR drills for critical systems at least half-yearly.
In QULDEXDrill schedules and results are tracked.
Third partiesThird-party arrangementsManage risks from IT outsourcing and third-party service providers, with audit and access rights.
In QULDEXEach provider is assessed and linked to the services it supports.
MetricsCybersecurity metrics and awarenessTrack cybersecurity metrics and run employee and customer awareness programmes.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
IS auditInformation Systems AuditIndependent IS audits of IT systems and controls, with findings tracked to closure.
In QULDEXIS audit findings flow into CAPA.
PaymentsDigital Payment Security Controls DirectionsA separate set of Directions issued the same day requires a board-approved policy for digital payment products and specific security controls.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.
Nothing matches that search.
Areas summarise the 31 July 2026 Directions as published; exact paragraphs differ by entity type. Summaries are QULDEX paraphrases, not legal advice; your entity's Directions are the authority.
Read the Directions for your entity type, map them against your existing controls, close the gaps and evidence the new cadences. Because they applied immediately, most entities run this as a 3 to 6 month remediation programme.
Confirm which entity-specific Directions apply and to which group entities.
Compare with your 2016-framework and 2023 IT governance controls to find what is new.
Board and committee mandates, CISO reporting line and policy approvals.
VA every six months, PT every year, half-yearly DR drills and six-hour reporting through DAKSH.
Reassess providers and align digital payment products with the companion Directions.
The Directions took effect on 31 July 2026. Durations are QULDEX planning ranges.
Supervisors and IS auditors will ask for these records.
| Document | Area | Where it lives in QULDEX |
|---|---|---|
| Board-approved IT, IS and cybersecurity policies | Policies | Policy library |
| Board, RMCB and ITSC minutes | Governance | Policy library |
| CISO appointment and reports | CISO | Policy library |
| IT and cyber risk register | IT risk | Risk register |
| VA and PT reports with closure | VA, PT | CAPA automation |
| C-SOC reports and metrics | C-SOC | Evidence vault |
| Incident reports to RBI and CERT-In | Incidents | CAPA automation |
| BCP and DR drill reports | BCP/DR | Evidence vault |
| Third-party assessments and contracts | Third parties | Vendor register |
| IS audit reports | IS audit | Audit workspace |
Document names are QULDEX recommendations based on the Directions.
Entities that met the 2016 framework typically need 3 to 6 months to close new gaps. Governance changes, new testing cadences and third-party reassessment drive most of it.
Bars show the upper end of each range on one scale (6 months = full width).
Check these eight things first. Nothing you enter leaves this page.
Many groups are regulated by both RBI and SEBI, and every entity follows CERT-In. One control set mapped to all three avoids collecting evidence twice.
| RBI Directions 2026 | SEBI CSCRF | CERT-In Directions | ISO 27001:2022 | Shared evidence |
|---|---|---|---|---|
| Board and ITSC | GV.RR, GV.OV | — | 5.1 | Minutes |
| CISO | GV.RR | Point of contact | 5.3 | Appointments |
| VA and PT | ID.RA | — | A.8.8 | Test reports |
| C-SOC | DE.CM | Logs for 180 days | A.8.15–A.8.16 | SOC reports |
| 6-hour incident reporting | RS.MA | 6-hour reporting | A.5.24–A.5.26 | Incident reports |
| BCP and DR drills | RC.RP | — | A.5.29–A.5.30 | Drill reports |
| Third parties | GV.SC | — | A.5.19–A.5.22 | Vendor assessments |
Indicative mapping for planning, not legal advice. RBI vs SEBI requirements are compared in full on the blog.
QULDEX is RBI cybersecurity compliance and audit management software built from EGV Group's audit delivery, used by banks and NBFCs, their advisors and the IS auditors who test them. Pick your role to see who does what.
For RBI-regulated entities.
For RBI compliance consultants and internal audit.
For independent information systems auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, one set for each type of regulated entity, plus Digital Payment Security Controls Directions. They took effect immediately.
The 2026 Directions replaced it, together with earlier IT governance and cybersecurity circulars, as part of RBI's consolidation of instructions.
Cyber incidents must be reported within six hours of detection through RBI's DAKSH platform, with notification to CERT-In.
Vulnerability assessments at least every six months and penetration tests at least every twelve months; DR drills for critical systems at least half-yearly.
Yes. NBFCs have their own Directions, with applicability depending on their regulatory layer and asset size.
What changed and how supervisors are applying it.
blog.quldex.comDPDP, CERT-In, RBI and SEBI coverage.
blog.quldex.comA file-naming scheme IS auditors can follow.
blog.quldex.comHow many samples auditors look at.
Reviewed by
Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.