RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do Now
The framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.
On this page (7)
If you are looking for the RBI Cybersecurity Framework, the instrument you have in mind no longer exists. On 31 July 2026 the Reserve Bank repealed it — along with 627 other circulars — and replaced the whole supervisory rulebook with 64 consolidated Directions organised by type of regulated entity.
Cybersecurity did not get one replacement. It got six, issued the same day, one for each class of entity. This is the practical map.
What actually happened
The repeal instrument is RBI/DoS/2026-27/221. It retired 628 circulars with immediate effect. In their place, the Department of Supervision issued 64 Directions, of which six carry the cybersecurity, technology risk, resilience and assurance framework:
| Entity | Instrument |
|---|---|
| Commercial banks | RBI/DoS/2026-27/410 |
| Small finance banks | RBI/DoS/2026-27/419 |
| Payments banks | RBI/DoS/2026-27/428 |
| Urban co-operative banks | RBI/DoS/2026-27/437 |
| NBFCs | RBI/DoS/2026-27/461 |
| Credit information companies | RBI/DoS/2026-27/470 |
All six commenced on issuance. There is no transition period, no phase-in and no glide path in any of them. Anything below that you are not already doing is a gap today, not a project for the next financial year.
The commercial banks instrument runs to 233 numbered paragraphs across eight chapters. Paragraph references throughout this piece are to that document unless stated otherwise.
Who is in scope
The scoping is where most commentary is going wrong, because it is no longer uniform.
Commercial banks means banking companies other than small finance banks, payments banks and local area banks, plus corresponding new banks and the State Bank of India (para 3). Local area banks received no cybersecurity Direction at all in this batch.
Foreign banks operating through branch mode read every reference to the Board as their controlling or head office, and get a comply or explain approach across Chapters II, III, IV and VII and sixteen named paragraph groups of Chapter V (para 4). That is a relaxation subject to RBI accepting the explanation as part of the supervisory process — not an exemption. It does not extend to Chapter VI.
NBFCs are scoped by Scale Based Regulation layer. Chapter III applies to Base Layer NBFCs below ₹500 crore and to Core Investment Companies; Chapter IV to Base Layer NBFCs at ₹500 crore and above; Chapter V to Middle Layer and above, excluding CICs. A small Base Layer NBFC's entire obligation is three paragraphs — no VA/PT, no incident deadline, no security operations centre.
Urban co-operative banks are graded into four levels by digital depth and interconnectedness to the payment systems landscape, not by asset size. A Level I UCB owes Chapters II and III. A UCB that offers internet banking, has a mobile banking app, or is a direct member of CTS, IMPS or UPI moves to Level II. Level IV carries a full security operations centre. A small co-operative bank with UPI membership sits higher than its balance sheet would suggest.
One naming trap worth flagging: "CIC" means two different things across these instruments. In the NBFC Directions it is a Core Investment Company. In /470 it is a Credit Information Company. They are not the same population and they do not carry the same obligations.
What actually changed
Most of the control catalogue carried forward. A bank CISO who has been complying since 2016 will recognise the majority of Chapter V, and any guide presenting all of it as new is padding.
These are the deltas that move.
Cloud testing became mandatory. Your documented VA/PT approach now shall also apply to systems hosted in a cloud environment (para 154). The 2023 IT Governance Master Direction said it may. One word, and it is the most easily checkable change in the instrument.
The auditor is now regulated through you. Three new paragraphs, and this is the part nobody is briefing CISOs on:
- Para 156 — at selection, appointment, engagement or renewal, you must consider the qualification, professional expertise, credentials and competency of the testing firm and of the personnel it assigns.
- Para 157 — reasonable assurance for each area in scope must be stated explicitly in the VA/PT report, and that requirement must be set out when you empanel or award the contract.
- Para 158 — if a system that was tested is later compromised through a vulnerability the auditor failed to observe or flag on time, that qualifies as a deficiency in the discharge of their function, and must be weighed at renewal.
There is no counterpart to any of these in the 2016 framework or the 2023 Master Direction. Taken together they create retrospective, breach-triggered performance accountability for testing vendors.
Quarterly closure reporting. The status of closure of VA/PT observations goes to both the IT Strategy Committee and the Information Security Committee at least quarterly (para 161). That is a new artefact with a named owner.
The six-hour clock is operative. Cyber incidents must be reported within six hours of detection on DAKSH, and CERT-In must also be notified proactively (para 182). Read that carefully: the six hours attaches to the DAKSH limb. This instrument prescribes no timeline for the CERT-In limb — CERT-In's own 2022 Directions do that separately. Do not let a policy document collapse the two into a single sourced claim.
The SOC chapter got specific. A CSOC was already mandatory: para 143 says the bank "shall set up a CSOC to ensure continuous surveillance", and the 2016 framework said much the same. What changed is the detail behind it. Chapter VI (paras 212 to 223) now sets out governance and Board briefing, root-cause and containment capability, honeypots, wire-speed deep packet inspection, malware analysis and imaging, and an L1/L2/L3 staffing structure — where the 2016 equivalent was a short annex. Read para 143 carefully though: it describes Chapter VI as "an indicative, but not exhaustive, minimum baseline guidance". The duty to have a CSOC is hard; Chapter VI is the benchmark your design will be judged against rather than a second, separate mandate. Para 223 expressly permits meeting the 24x7 requirement through managed service arrangements rather than an in-house build.
The testing cadence, correctly stated
This is the number most published guidance is getting wrong, including ours until this rewrite.
For critical information systems and / or those in the DMZ having a customer interface — the scope is disjunctive, either category triggers it — vulnerability assessment at least once every six months, and penetration testing at least once in 12 months (para 151). Non-critical systems follow a risk-based approach you define and defend.
Testing also runs across the lifecycle: pre-implementation, post-implementation and after changes (para 150), performed on the production environment, with any test-environment deviation documented and approved by the Information Security Committee (para 152).
Application security assessments shall not be restricted to the OWASP Top 10 (para 85), and must run in an environment closely resembling production (para 86).
"Annual VAPT" understates the vulnerability assessment leg by a factor of two.
The red-teaming myth, and the empanelment reality
RBI does not mandate red teaming. para 162 says a bank may conduct red teaming exercises. It was permissive in the 2016 framework too. SEBI CSCRF does mandate it half-yearly for MIIs and Qualified REs; RBI does not, and the UCB and NBFC Directions do not mention red teaming at all. Any proposal telling you otherwise is worth reading twice for what else it got wrong.
CERT-In empanelment is the benchmark for RBI audit work. Several RBI instruments require it by name — the payment aggregator system audit under the PA-PG Master Direction, and the data-localisation System Audit Report — and neither was touched by this consolidation. SEBI CSCRF requires it too.
Within these Directions the mechanism is different and points the same way. Para 155 requires testing by appropriately trained and independent experts. Para 156 requires you to assess the qualification, professional expertise, credentials and competency of the firm and of the personnel assigned, at every selection and renewal — and empanelment is how banks evidence that in practice. Para 159 then provides that where you engage a CERT-In empanelled auditor, you are guided by CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, which imports a defined audit-policy regime into the supervisory relationship.
In short: empanelment is what a supervisor expects to see, and paras 156 to 158 now give you a documented reason to insist on it.
What to do in the first 90 days
Re-point your citations. Policies, audit charters, committee terms of reference and vendor contracts naming the 2016 framework or the 2023 Master Direction now reference repealed instruments.
Test the six-hour path. Detection to DAKSH in six hours is an operational drill, not a policy line. Run it, including out of hours.
Check the CISO reporting line. No reporting relationship to the Head of IT, no business targets, reporting to the Executive Director or equivalent overseeing risk (paras 27, 28). If the org chart does not match, that is a governance finding waiting to be written.
Rebuild the committee pack for the quarterly VA/PT closure report to the ITSC and the ISC.
Reopen testing contracts against paras 156 to 158 — credentials on file, per-area assurance specified in the statement of work, and an agreed position on deficiency at renewal.
Confirm the anti-phishing subscription exists. para 148 requires subscription to anti-phishing and anti-rogue-app services from external service providers for identifying and taking down phishing sites and rogue applications. An internal capability does not discharge it.
How we help
Security Brigade has been CERT-In empanelled continuously since 2008 and has taken BFSI clients through RBI inspections, post-incident remediation and pre-merger due diligence.
We run the para 151 cadence across web, mobile, API, network and cloud, test to para 85's beyond-the-Top-10 standard, and produce reports built for para 157 — explicit per-area assurance, documented methodology and scoring, named-auditor credentials for your renewal evidence, and a closure pack your ITSC and ISC can take as read. ShadowMap discharges the para 148 external-provider obligation directly.
If you want the paragraph-level view of which of the six instruments applies to you and which chapters you carry, request a scoping call.
About the author
Regulatory and Technical Research · Security Brigade
The editorial team reads the primary sources so you do not have to. Every regulatory piece here is written against the circular, Direction or standard itself and cites the paragraph, and every technical piece is reviewed by the practice lead who runs that kind of engagement.
Continue reading
All articles →ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.