RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your Layer
RBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.
On this page (8)
On 31 July 2026 the Reserve Bank issued six entity-specific cybersecurity Directions on a single day. The one that binds you is RBI/DoS/2026-27/461, the Reserve Bank of India (Non-Banking Financial Companies — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. It runs to 158 numbered paragraphs across six chapters and it came into force with immediate effect (para 2). No transition window, no glide path, no phased commencement anywhere in the text. The first question is not what it requires. It is which chapter it requires it of you, because the answer moves you between three paragraphs and ninety.
Which chapter applies to you
Paragraph 3 allocates the instrument by Scale Based Regulation layer. The bands are drafted with the word "only", which makes them mutually exclusive — a Middle Layer NBFC does not inherit Chapter IV on the way up, and a Base Layer NBFC crossing ₹500 crore does not add Chapter IV to Chapter III, it moves out of one and into the other.
| Your position under SBR | Chapter that applies | Operative paragraphs |
|---|---|---|
| Base Layer, asset size below ₹500 crore | Chapter III | paras 7 to 9 |
| Core Investment Companies, any size | Chapter III | paras 7 to 9 |
| Base Layer, asset size ₹500 crore and above | Chapter IV | paras 10 to 64 |
| Middle, Upper and Top Layer, excluding CICs | Chapter V | paras 65 to 154 |
Chapters I, II and VI are not carved by layer. Paragraph 3(1) applies the Directions to every NBFC registered under the RBI Act 1934, the Factoring Regulation Act 2011 and the National Housing Bank Act 1987 "unless specified otherwise", and only Chapters III, IV and V are specified otherwise. So Para 6 reaches everyone: the Board approves the technology and cybersecurity strategies and policies, and reviews them at least annually. That single paragraph is the floor for a two-person Base Layer NBFC and for a Top Layer housing finance company alike.
Chapter III: three paragraphs
If you are a Base Layer NBFC below ₹500 crore, or a Core Investment Company of any size, your obligation under this instrument is para 6 plus paras 7 to 9. That is it.
Paragraph 7 requires you to prioritise the implementation of basic IT systems to digitise and secure your primary business databases. Paragraph 8 requires a Board-approved IT/IS policy built on nine listed basics: access controls and a password policy, defined user roles, maker-checker, information security and cybersecurity controls, system-generated MIS for senior management, adequacy to file RBI returns, a Board-approved BCP with at least annual reporting, and data backup with periodic testing. Paragraph 9 says scale up as you grow.
Two things inside that deserve attention, because they are easy to miss. First, Para 8(5) reaches out of Chapter III and into Chapter IV: it imports para 31 (Digital Signature Certificates), para 33 (mobile financial services, including end-to-end encryption) and para 34 (social media risk, including account takeover and impersonation fraud). A small NBFC with a customer-facing mobile app carries para 33 in full. Second, Chapter III contains no VA/PT cadence, no six-hour incident clock, no CISO and no IS audit function. Anyone selling you a Chapter V programme on a Chapter III licence is selling you something the Reserve Bank has not asked for.
What the absence does not do is switch off everything else. CERT-In's 2022 Directions bind you as a body corporate independently of para 461, on their own six-hour clock. And a Base Layer NBFC that is also a payment aggregator remains inside the PA-PG Master Direction, which names a CERT-In empanelled auditor for the annual system and cybersecurity audit.
Chapter IV: Base Layer at ₹500 crore and above
Fifty-five paragraphs, and the shape changes. You now need an IT Strategy Committee chaired by an independent director with the CIO and CTO as members, meeting so that no more than six months elapse between meetings (para 15). A Board-approved IT policy with a designated CIO or In-Charge of IT operations, and public-facing infrastructure that handles IPv6 (para 18). A Board-approved information security policy (para 20), whose contents are fixed by para 21: asset inventory, segregation of the IT and information security functions, role-based access, background screening of privileged personnel, maker-checker and audit trails. A Board-approved cybersecurity policy (para 22) and a Cyber Crisis Management Plan addressing detection, response, recovery and containment (para 25).
Three paragraphs carry commercial weight here.
Para 23 requires a vulnerability management process to identify, manage and eliminate vulnerabilities, documented inside the cybersecurity policy. Note carefully what it does not say: Chapter IV sets no six-month VA or twelve-month PT cadence. That cadence lives in Chapter V. If you are a ₹600 crore Base Layer NBFC, your testing rhythm is yours to justify against paras 23 and 32, not a number RBI has given you.
Para 24 is where independent testing enters Chapter IV. Preparedness indicators "shall be used for comprehensive testing through independent compliance checks and audits carried out by qualified and competent professionals."
Para 28 puts cyber incidents on the DAKSH platform within six hours of detection. Chapter IV's version has one limb only — DAKSH. The CERT-In limb appears in Chapter V at para 141.
Then para 32 requires a comprehensive annual IT risk assessment placed before the CRO, CIO and Board, and explicitly serving "as an input for Information Security auditors". IS audit sits at paras 47 to 58: an ACB-approved framework (para 49), conducted by an internal team with an outside agency permitted where internal skills are inadequate (para 55), and a periodicity that "shall ideally be based on the size and operations of the NBFC but may be conducted at least once in a year" (para 56). That is permissive drafting. Do not let anyone recite it to you as an annual mandate.
Chapter V: Middle Layer and above
Ninety paragraphs, and this is the buyer the instrument is really written for.
Para 121 is the operative testing paragraph. Vulnerability assessment at least once every six months, penetration testing at least once in 12 months, for critical information systems and / or those in the DMZ having customer interface. The scope is disjunctive: either limb triggers the obligation on its own. The same paragraph extends VA/PT across the system lifecycle, including pre-implementation, post-implementation and after changes.
The paragraphs around it define the programme:
- Para 122 — VA/PT shall be conducted by appropriately trained and independent information security experts or auditors.
- Para 123 — risk-based cadence for non-critical systems.
- Para 124 — post-implementation testing on the production environment; where circumstances force a test environment, version and configuration must resemble production and any deviation is documented and approved by the Information Security Committee.
- Para 125 — time-bound remediation, sustained compliance, no recurrence of known CVEs.
- Para 126 — a documented VA/PT approach covering scope, coverage and a scoring mechanism such as CVSS, and it "shall also apply to the NBFC's information systems hosted in a cloud environment."
Application security is a hard obligation, not an aspiration. Para 105 requires you to obtain source code for all critical applications, or a source code escrow arrangement that includes product updates and programme fixes. Para 106 requires a certificate or written confirmation from the developer or vendor that the application is free of known vulnerabilities, malware and covert channels, refreshed on material changes. Your penetration test report does not discharge para 106 — that attestation has to come from the developer.
Governance is where most Middle Layer NBFCs will find a structural gap. Para 81: the CISO is a senior executive, preferably of General Manager rank, with no direct reporting relationship to the Head of IT Function and no business targets. Para 82(6): the CISO reports to the Executive Director or equivalent overseeing risk management. Para 82(7): a quarterly review of cyber risk and preparedness before the Board, RMCB or ITSC. The ITSC meets quarterly with at least three directors and an independent chairperson holding a minimum of seven years' IT experience (paras 71 to 72). The IT Steering Committee meets quarterly (para 75). The Information Security Committee is headed from the risk management vertical (para 77).
Resilience carries real numbers: DR drills at least half-yearly for critical systems (para 129), and DR testing that switches over to the alternate site for at least a full working day including beginning-of-day to end-of-day operations (para 131), with identical configurations and patch levels at DC and DR (para 137).
Para 141 is the incident clock: report to RBI within six hours of detection on DAKSH, and "also pro-actively notify" CERT-In. The six hours attaches to the DAKSH limb; the CERT-In limb in this paragraph carries no separate timeline of its own, though CERT-In's 2022 Directions set six hours independently. The note under para 141 is the one every housing finance company needs to read twice: HFCs report cyber incidents to NHB, not RBI.
Three things this instrument does not contain
Precision here is worth more than volume.
No red teaming. The phrase does not appear in /461 at all. The Commercial Banks, SFB, Payments Banks and Credit Information Company instruments each carry a permissive red-teaming paragraph using "may". The NBFC instrument does not carry one in either direction.
No anti-phishing takedown subscription. Commercial banks must subscribe to anti-phishing and anti-rogue-app services from external service providers (para 148 of /410, with siblings at SFB para 147, PB para 147, UCB para 123 and CIC para 143). There is no NBFC counterpart. What you do carry is the duty to address phishing as a threat: para 27 in Chapter IV lists email phishing, spear phishing, whaling and vishing among the attacks you must take preventive and corrective measures against, and para 98 in Chapter V adds spoofing alongside phishing.
No CSOC chapter. The Commercial Banks instrument devotes a full chapter to building and running a Cyber Security Operations Centre. In para 461 the SOC appears once, at Para 82(4), as a responsibility of the CISO's office. Security Brigade does not operate a SOC, MDR or SIEM service, and we work alongside whichever monitoring provider you appoint.
The CIC trap
"CIC" means two different things across the six instruments, and mixing them up is the fastest way to mis-scope a compliance programme. In para 461 it is Core Investment Company, which gets Chapter III and is expressly excluded from Chapter V by para 3(4). In RBI/DoS/2026-27/470 it is Credit Information Company under the CIC (Regulation) Act 2005, which gets that entire instrument with no tiering. Different populations, different instruments, different obligations.
On auditor selection
Paragraph 122 requires "appropriately trained and independent information security experts / auditors", and para 152 keeps responsibility and accountability for externally-conducted IS audit with the competent authority inside your Internal Audit function. Together they put the burden on you: Internal Audit stays accountable for work it did not perform, so you have to be able to show a supervisor why the firm you appointed — and the individuals it actually staffed the engagement with — met the para 122 standard of trained and independent. The Commercial Banks instrument writes that test out in full at para 156 of RBI/DoS/2026-27/410, requiring the credentials of the firm and of the audit personnel to be assessed at every selection, appointment, engagement and renewal. /461 leaves you to construct the same evidence without telling you how. CERT-In empanelment is how that gets evidenced, it is the standard supervisors expect for regulated-entity audit work, and it discharges more than one obligation at once: the PA-PG Master Direction names a CERT-In empanelled auditor for the annual system and cybersecurity audit, the 2018 Storage of Payment System Data directive names one for the System Audit Report, and SEBI's CSCRF names one for every regulated entity in its scope. One empanelled firm answers all of them.
Security Brigade has been CERT-In empanelled continuously since 2008, across more than 6,700 assessments for over 1,000 clients. The RBI cybersecurity framework an NBFC is measured against changed on 31 July 2026: para 155 repealed the Information Technology Framework and IT Governance instructions that preceded it, and RBI/DoS/2026-27/461 replaced them.
Your first 90 days
- Fix your layer in writing. Record your SBR classification and asset size, name the chapter that follows from para 3, and get it minuted. Every downstream decision depends on this one line.
- Refresh the Board pack (para 6). Technology and cybersecurity strategies and policies approved, with the annual review cycle diarised. This applies whichever chapter you landed in.
- Middle Layer and above: close the CISO reporting line first (para 81, 82(6)). If your CISO reports into the Head of IT, that is a structural breach visible in an org chart, and it is the first thing an inspection will find.
- Set the para 121 clock. Define your critical information systems and your DMZ estate with customer interface, then schedule VA at six months and PT at twelve, including cloud-hosted systems under para 126.
- Write the documented VA/PT approach (para 126) — scope, coverage, scoring mechanism, cloud. It is a procurement artefact as much as a compliance one.
- Stand up the six-hour path (para 141 / para 28). DAKSH credentials issued, an on-call escalation that runs at 2am, and for HFCs, the NHB route confirmed rather than assumed.
- Audit your application estate against paras 105 to 106. Source code or escrow including updates and fixes, plus the developer's written confirmation for every critical application.
- Book the half-yearly DR drill with a full working-day switchover (para 129, 131). It takes longer to arrange than to run.
If you want the paragraph-by-paragraph scoping done against your actual estate, that is a conversation worth having before your first supervisory cycle under the new instrument closes.
About the author
Security Brigade Editorial Team
Continue reading
All articles →ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.