Regulation · Banking and NBFCs · India

RBI cybersecurity directions 2026: what changed and what to do

The RBI cybersecurity directions 2026 are the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions the Reserve Bank of India issued on 31 July 2026, one set per type of regulated entity. They took effect immediately, replace the 2016 cyber security framework, and require six-hour incident reporting through DAKSH.

Key takeaways

What you need to know about RBI Cybersecurity Directions

No glide pathThe Directions applied from the day they were issued.
One set per entity typeRequirements are written for each kind of regulated entity.
Board-ledThe Board, its risk committee and the IT Strategy Committee own technology risk.
Fixed cadencesVA every six months, PT every year, DR drills every half-year.
Six-hour reportingCyber incidents go to RBI via DAKSH and to CERT-In.

Who must comply with the RBI cybersecurity directions?

RBI-regulated entities, each under the Directions written for its type.

Commercial banksIncluding small finance banks and payments banks.
Urban co-operative banksUnder their own entity-specific Directions.
NBFCsApplicability depends on regulatory layer and asset size.
All-India financial institutionsSuch as development finance institutions.
Credit information companiesAnd other RBI-regulated entities covered by the set.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the Directions require

What do the RBI cybersecurity directions require?

The RBI cybersecurity directions require Board-led technology governance with a CISO, baseline cybersecurity controls, a C-SOC, six-hour incident reporting, tested business continuity, managed third parties and independent IS audits.

Board Govern

Governance

Board, RMCB, IT Strategy Committee and CISO.

In QULDEX: Approvals and reviews tracked
Baseline Protect

Baseline controls

Network, endpoint, access and crypto controls.

In QULDEX: Controls mapped to evidence
VA/PT Test

Testing cadence

VA every 6 months, PT every 12 months.

In QULDEX: Due dates on the dashboard
C-SOC Detect

Security operations

Continuous monitoring and metrics.

In QULDEX: SOC metrics tracked
DAKSH Report

Incident reporting

Within six hours, plus CERT-In.

In QULDEX: Six-hour timers
BCP/DR Recover

Continuity

DR drills for critical systems half-yearly.

In QULDEX: Drill results stored
IS audit Assure

IS audit

Independent audit with tracked findings.

In QULDEX: Findings into CAPA
Requirement explorer

Which RBI cybersecurity requirements matter most?

These 19 requirement areas carry most of the work, grouped by theme. Select any one to see what it asks for, typical evidence and the matching ISO 27001 or CERT-In reference.

2016cyber security framework
2023IT governance direction
31 Jul 2026new Directions
Same dayeffective

Showing up to 6 per group. Search, filter, or open a group to see all 19.

Governance 5

  1. BoardBoard and committee oversight

    Technology governance sits with the Board, the Risk Management Committee of the Board and the IT Strategy Committee, with senior management accountable.

    In QULDEXCommittee reviews and approvals are recorded with dates.

    Typical evidence
    Board and committee minutes
    Maps to
    ISO 27001 5.1

  2. PoliciesBoard-approved policies

    Board-approved IT, information security and cybersecurity policies, reviewed periodically.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Approved policies
    Maps to
    ISO 27001 A.5.1

  3. CISOChief Information Security Officer

    A CISO with defined responsibilities, reporting to the executive overseeing risk management.

    In QULDEXThe CISO's role, reporting line and reports are on record.

    Typical evidence
    CISO appointment
    Maps to
    ISO 27001 5.3

  4. ISCInformation Security Committee

    A committee that oversees information security and cyber risk across the entity.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Committee minutes

  5. IT riskIT and cyber risk management

    Identify, assess and treat IT and cyber risks as part of enterprise risk management.

    In QULDEXThe risk register holds IT and cyber risks with treatment owners.

    Typical evidence
    Risk register
    Maps to
    ISO 27001 6.1

Controls and testing 6

  1. BaselineBaseline cybersecurity controls

    Minimum controls for network, endpoint, application and data security.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Control evidence
    Maps to
    ISO 27001 Annex A

  2. AccessUser access management

    Least privilege, privileged access controls and periodic access reviews.

    In QULDEXAccess reviews run as recurring tasks.

    Typical evidence
    Access reviews
    Maps to
    ISO 27001 A.5.15–A.5.18

  3. CryptoCryptographic controls

    Encryption and key management for data at rest and in transit.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Crypto policy, key records
    Maps to
    ISO 27001 A.8.24

  4. VAVulnerability assessment every six monthsFixed cadence

    Run vulnerability assessments at least every six months and fix findings.

    In QULDEXScan findings become CAPA items with due dates.

    Typical evidence
    VA reports
    Maps to
    ISO 27001 A.8.8

  5. PTPenetration testing every twelve monthsFixed cadence

    Run penetration tests at least every twelve months.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    PT reports

  6. DataData protection

    Protect customer and business data across its lifecycle.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Data protection evidence
    Maps to
    DPDP Act

Operations and resilience 6

  1. C-SOCCyber Security Operations Centre

    Continuous monitoring through a C-SOC with defined use cases and metrics.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    SOC reports
    Maps to
    ISO 27001 A.8.16

  2. IncidentsIncident reporting within six hoursFixed cadence

    Report cyber incidents within six hours of detection through RBI's DAKSH platform, and notify CERT-In.

    In QULDEXIncidents carry six-hour reporting timers.

    Typical evidence
    Incident reports
    Maps to
    CERT-In Directions 2022

  3. CrisisCyber crisis management

    A cyber crisis management plan with response and recovery playbooks.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Crisis management plan

  4. BCP/DRBusiness continuity and DR drillsFixed cadence

    Business continuity and disaster recovery, with DR drills for critical systems at least half-yearly.

    In QULDEXDrill schedules and results are tracked.

    Typical evidence
    DR drill reports
    Maps to
    ISO 22301

  5. Third partiesThird-party arrangements

    Manage risks from IT outsourcing and third-party service providers, with audit and access rights.

    In QULDEXEach provider is assessed and linked to the services it supports.

    Typical evidence
    Vendor assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

  6. MetricsCybersecurity metrics and awareness

    Track cybersecurity metrics and run employee and customer awareness programmes.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Metrics, training records

Assurance 2

  1. IS auditInformation Systems Audit

    Independent IS audits of IT systems and controls, with findings tracked to closure.

    In QULDEXIS audit findings flow into CAPA.

    Typical evidence
    IS audit reports
    Maps to
    ISO 27001 9.2

  2. PaymentsDigital Payment Security Controls Directions

    A separate set of Directions issued the same day requires a board-approved policy for digital payment products and specific security controls.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and maps it to ISO 27001 and SEBI CSCRF.

    Typical evidence
    Digital payments policy

Areas summarise the 31 July 2026 Directions as published; exact paragraphs differ by entity type. Summaries are QULDEX paraphrases, not legal advice; your entity's Directions are the authority.

Compliance path

How do you comply with the RBI cybersecurity directions?

Read the Directions for your entity type, map them against your existing controls, close the gaps and evidence the new cadences. Because they applied immediately, most entities run this as a 3 to 6 month remediation programme.

  1. Identify your Directions

    Confirm which entity-specific Directions apply and to which group entities.

  2. Map against current controls

    Compare with your 2016-framework and 2023 IT governance controls to find what is new.

  3. Fix governance

    Board and committee mandates, CISO reporting line and policy approvals.

    1–2 monthsRisk register →
  4. Set up the new cadences

    VA every six months, PT every year, half-yearly DR drills and six-hour reporting through DAKSH.

  5. Third parties and digital payments

    Reassess providers and align digital payment products with the companion Directions.

  6. Assure and report

    Every 6 monthsVA and DR drills
    Every yearPT and policy review
    Every incidentReport within 6 hours

The Directions took effect on 31 July 2026. Durations are QULDEX planning ranges.

Records to keep

Which documents do the RBI directions need?

Supervisors and IS auditors will ask for these records.

DocumentAreaWhere it lives in QULDEX
Board-approved IT, IS and cybersecurity policiesPoliciesPolicy library
Board, RMCB and ITSC minutesGovernancePolicy library
CISO appointment and reportsCISOPolicy library
IT and cyber risk registerIT riskRisk register
VA and PT reports with closureVA, PTCAPA automation
C-SOC reports and metricsC-SOCEvidence vault
Incident reports to RBI and CERT-InIncidentsCAPA automation
BCP and DR drill reportsBCP/DREvidence vault
Third-party assessments and contractsThird partiesVendor register
IS audit reportsIS auditAudit workspace

Document names are QULDEX recommendations based on the Directions.

Time and cost

How long does RBI compliance take and what drives the effort?

Entities that met the 2016 framework typically need 3 to 6 months to close new gaps. Governance changes, new testing cadences and third-party reassessment drive most of it.

Where the time goes

Mapping3–6 wk
Governance1–2 mo
New cadences1–3 mo
Third parties1–3 mo
Assurance set-up3–6 wk

Bars show the upper end of each range on one scale (6 months = full width).

What changes the effort

  • Entity type: requirements differ by Directions
  • Group entities: each regulated entity needs its own evidence
  • Critical systems: each needs DR drills
  • Providers: every outsourcing arrangement is reassessed
  • Existing ISO 27001: covers much of the baseline
Readiness check · 2 minutes

How ready are you for the RBI cybersecurity directions?

Check these eight things first. Nothing you enter leaves this page.

ScopeHave you confirmed which entity-specific Directions apply to you?
BoardDo the Board, RMCB and ITSC have documented technology mandates?
CISODoes the CISO report to the executive overseeing risk management?
VADo you run vulnerability assessments at least every six months?
PTDo you run penetration tests at least every year?
DAKSHCan you report a cyber incident within six hours through DAKSH?
BCP/DRAre DR drills for critical systems run at least half-yearly?
Third partiesHave IT service providers been reassessed under the new Directions?
Crosswalk

How the RBI directions map to SEBI CSCRF, CERT-In and ISO 27001

Many groups are regulated by both RBI and SEBI, and every entity follows CERT-In. One control set mapped to all three avoids collecting evidence twice.

India cybersecurity crosswalk

RBI Directions 2026SEBI CSCRFCERT-In DirectionsISO 27001:2022Shared evidence
Board and ITSCGV.RR, GV.OV—5.1Minutes
CISOGV.RRPoint of contact5.3Appointments
VA and PTID.RA—A.8.8Test reports
C-SOCDE.CMLogs for 180 daysA.8.15–A.8.16SOC reports
6-hour incident reportingRS.MA6-hour reportingA.5.24–A.5.26Incident reports
BCP and DR drillsRC.RP—A.5.29–A.5.30Drill reports
Third partiesGV.SC—A.5.19–A.5.22Vendor assessments

Indicative mapping for planning, not legal advice. RBI vs SEBI requirements are compared in full on the blog.

Where QULDEX fits

How QULDEX runs RBI compliance from mapping to IS audit

QULDEX is RBI cybersecurity compliance and audit management software built from EGV Group's audit delivery, used by banks and NBFCs, their advisors and the IS auditors who test them. Pick your role to see who does what.

For RBI-regulated entities.

  1. ScopeConfirm your DirectionsApplicable Directions per entity
  2. GovernSet mandatesBoard and committee records
  3. ControlsClose gapsRequirements mapped to evidence
  4. CadencesRun VA, PT and drillsDue dates and results tracked
  5. IncidentsReport within six hoursSix-hour timers per incident
  6. AssureHost the IS auditControlled evidence sharing
Without one systemWith QULDEX
2016-framework checklist kept by habitControls mapped to the 2026 Directions
VA and PT dates tracked in emailCadences with due dates
Incident reports drafted under pressureSix-hour timers and templates
RBI and SEBI evidence kept twiceOne control set mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

RBI Cybersecurity Directions questions people ask

What did RBI issue on 31 July 2026?

The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, one set for each type of regulated entity, plus Digital Payment Security Controls Directions. They took effect immediately.

What happened to the 2016 cyber security framework?

The 2026 Directions replaced it, together with earlier IT governance and cybersecurity circulars, as part of RBI's consolidation of instructions.

What is the RBI cyber incident reporting timeline?

Cyber incidents must be reported within six hours of detection through RBI's DAKSH platform, with notification to CERT-In.

How often are VA and PT required?

Vulnerability assessments at least every six months and penetration tests at least every twelve months; DR drills for critical systems at least half-yearly.

Do the Directions apply to NBFCs?

Yes. NBFCs have their own Directions, with applicability depending on their regulatory layer and asset size.

Sources

References

  1. RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 31 Jul 2026 (entity-wise). rbi.org.in
  2. RBI Digital Payment Security Controls Directions, 31 Jul 2026. rbi.org.in
  3. KPMG India, RBI's technology-focused master directions, Sep 2026. kpmg.com/in
  4. CERT-In Directions under Section 70B(6), 28 Apr 2022. cert-in.org.in
  5. ISO/IEC 27001:2022. iso.org

Reviewed by

Manisha Dubey

Framework reviewer · QULDEX

Reviewed this page against RBI's 31 July 2026 Directions: governance, cadences, incident reporting and IS audit.

Page history
  • : Page first built on the 31 July 2026 Directions: requirement explorer, cadences, six-hour reporting and readiness check

Close the gaps the 2026 Directions opened

Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.

Schedule
Book a Demo