On 31 July 2026 the Reserve Bank of India issued seven sets of Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions — one for each class of regulated entity — and they came into force immediately.

Not a consultation. Not a transition period. In force on issue.

Seven directions, one framework

Entity classCircular reference
Commercial BanksRBI/DoS/2026-27/410
Small Finance BanksRBI/DoS/2026-27/419
Payments BanksRBI/DoS/2026-27/428
Urban Co-operative BanksRBI/DoS/2026-27/437
All India Financial InstitutionsRBI/DoS/2026-27/456
NBFCsRBI/DoS/2026-27/461
Credit Information CompaniesRBI/DoS/2026-27/470

Each repeals the earlier cyber and IT-governance instructions for its class. Regional Rural Banks have no instrument in this framework; Local Area Banks received a separate one.

Splitting the framework by entity class rather than issuing one circular is the design choice worth noticing. It lets the RBI scale obligations to size — NBFC duties track the scale-based layers from Base to Top, and urban co-operative banks are graded across four levels by the digital services they offer, with higher levels stacking requirements. An entity may voluntarily adopt stricter measures. It may not downgrade.

Six hours, twice

A cyber incident must be reported to the RBI within six hours of detection, through DAKSH, the RBI's supervisory platform.

CERT-In has required six-hour reporting under the IT Act since 2022. Both obligations apply. Two regulators, one clock, two separate submissions.

Six hours from detection is a demanding number in practice, because detection is rarely a moment. It is an analyst raising an eyebrow at 2am, a ticket, an escalation, and somewhere in that sequence a clock started that nobody was watching. The compliance question is not whether you can write a report in six hours. It is whether your organisation can agree, quickly and in writing, when it knew.

That is a process problem, not a technology one, and it is the requirement most likely to be missed.

What the directions require

Governance. The board approves IT, cybersecurity and business continuity strategies annually. The IT Strategy Committee needs at least three directors and an independent chair with a minimum of seven years managing information systems. A senior CISO reports directly to the executive overseeing risk management. The cybersecurity policy must be distinct from the IT policy — not a chapter inside it.

Operations. An information asset inventory with criticality classification. Secure configuration and patch management. Multi-factor authentication for privileged users and critical systems. Data loss prevention across endpoints, transit and storage. A Cyber Security Operations Centre with round-the-clock monitoring and SIEM-based log correlation. Cryptography standards, secure software development, source code escrow, and IPv6 readiness.

Testing. Vulnerability assessment at least half-yearly. Penetration testing of critical systems at least annually, by independent assessors. Disaster recovery drills half-yearly, with recovery objectives set close to zero.

Third-party rules run on a separate track: the 2026 framework's provisions apply to IT and cybersecurity arrangements outside the scope of the RBI's Managing Risks in Outsourcing Directions (RBI/DOR/2025-26/171, 28 November 2025). Both apply concurrently.

Credit information companies are in scope

This is the line Indian readers should stop on.

We wrote about the four-year gap between what banks could see in your credit record and what you could. Credit information companies hold the financial history of most working adults in the country and have no customer relationship with any of them — you cannot take your business elsewhere.

They now have their own cyber direction with the same six-hour reporting clock, the same board obligations and the same testing cadence as a bank. Given what a CIC holds, that is overdue rather than aggressive.

Read the circulars, not the summaries

A caution about this piece and every other one you will read on the subject.

The RBI's own text is the authority, and the reference numbers are in the table above. This article is assembled from independent readings that agree on the specifics; the RBI's website does not serve automated requests, so we have not machine-verified the primary text line by line. For anything you intend to act on — particularly the exact scope for foreign banks and the level-by-level requirements for co-operative banks — read the circular for your entity class.

That is the correct posture for regulatory reporting generally. Secondary summaries are a map, and this one included.

What is not established

  • Penalties. Not specified in the material available to us.
  • The comply-or-explain scope for foreign banks on selected chapters.
  • What is expected of Regional Rural Banks, which have no instrument in this framework.
  • Specific SOC and SIEM operational standards — round-the-clock monitoring is required, but the bar is not elaborated.
  • How the RBI and CERT-In obligations interact where a single incident triggers both.