Skip to main content
CERT-In Empanelled Since 2008 — Required by name for payment aggregator system audits and the data-localisation SAR, and the credential para 156 makes your bank evidence at every selection and renewal. Security Brigade is one of India’s longest-standing CERT-In empanelled auditors.

RBI Cybersecurity Framework Compliance for Banks, NBFCs, and Cooperative Banks

The framework was repealed on 31 July 2026 and the Directions that replaced it are already in force, with no transition period. Structured assessments against the instrument that actually applies to you, by a CERT-In empanelled auditor - continuously empanelled since 2008, across 1,000+ clients.

370+
BFSI Engagements
RBI-Aligned
Methodology
Since 2008
CERT-In Empanelled
Banks · NBFCs
Sectors Served

On 31 July 2026 the Reserve Bank repealed 628 circulars and issued 64 consolidated Directions in their place. Cybersecurity received six of them - one each for commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs and credit information companies - and all six commenced on issuance. For banks that means vulnerability assessment every six months and penetration testing every 12 months for critical and DMZ customer-facing systems (para 151), cyber incidents on the DAKSH platform within six hours of detection (para 182), and a CISO who does not report to the Head of IT (paras 27-28). Security Brigade delivers the full spectrum against the current instrument: VAPT, information systems audit, cybersecurity policy review, access control validation, incident response readiness, BCP/DR testing and vendor risk management - one engagement, CERT-In empanelled since 2008.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora
STEP 01

Assess

Comprehensive gap assessment against the applicable RBI cybersecurity framework — covering systems, policies, controls, architecture, data flows, and vendor dependencies.

STEP 02

Remediate

Practical, prioritised remediation roadmap with owner assignments and target dates. Security Brigade supports your team through closure with revalidation testing.

STEP 03

Certify

Final compliance report, evidence pack, and audit attestation delivered in regulator-ready format by a CERT-In empanelled auditor — ready for RBI submission.

What Is the RBI Cybersecurity Framework?

The RBI Cybersecurity Framework was the Reserve Bank’s 2016 circular setting baseline cybersecurity requirements for banks. It was repealed on 31 July 2026, together with the 2023 Master Direction on IT Governance, and replaced by six entity-specific Directions - the RBI (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 and its siblings for small finance banks,…

RBI Cybersecurity Framework for Banks (Scheduled Commercial Banks)

Cybersecurity, technology risk and assurance requirements for scheduled commercial banks under the RBI Directions, 2026 (RBI/DoS/2026-27/410, 31 July 2026), which replaced the June 2016 Cyber Security Framework.

Board-Approved Cyber Security Policy

Distinct from IT policy — requires board-level ownership and annual review of cybersecurity strategy and risk appetite.

VAPT by CERT-In Empanelled Auditor

VA at least six-monthly and PT at least annually for critical and DMZ customer-interface systems, by independent, appropriately trained auditors, with quarterly closure reporting.

Security Operations Centre (SOC)

Real-time monitoring, log analysis, and threat detection capability covering critical banking infrastructure.

Incident Response and Reporting

Established IR procedures with mandatory incident reporting to RBI and CERT-In within prescribed timelines.

Access Control and Privilege Management

Role-based access, privileged access management, maker-checker controls, and periodic access reviews.

BCP/DR and Vendor Risk Management

Business continuity planning, disaster recovery drills, and security assessment of third-party and outsourced service providers.

Methodology

6 stages. Audit-ready results.

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade follows a six-phase methodology for every RBI cybersecurity compliance engagement. This methodology is consistent whether the entity is a scheduled commercial bank, an NBFC, or a cooperative bank — the scope and depth are calibrated to the specific regulatory requirements and the entity's digital footprint. Every phase is tracked through our Lemon audit management platform with evidence collection, finding assignment, remediation tracking, and closure validation built into the workflow.

Discovery
01

Scoping and Regulatory Mapping

Identify the applicable RBI circulars, map regulatory requirements to the entity's systems, applications, infrastructure, and vendors.

02

Policy and Governance Review

Review cybersecurity policy, IT governance structure, committee charters, risk assessments, and board-level reporting mechanisms.

Testing
03

Technical Assessment (VAPT and IS Audit)

Vulnerability assessment, penetration testing, application security testing, network security review, and configuration audit of critical systems.

04

Controls Validation and Evidence Review

Validate access controls, incident response, BCP/DR, vendor management, data localization, logging, and monitoring against RBI requirements with evidence collection.

Delivery
05

Gap Assessment and Remediation Support

Risk-ranked gap report with practical remediation guidance, owner assignments, and target closure dates. Security Brigade supports your team through closure.

06

Final Report and Regulator-Ready Deliverables

Final compliance report, control mapping matrix, evidence annexures, and management presentation — ready for RBI submission and board review.

"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
CISO, Top-3 Indian Bank
Chief Information Security Officer

Read more client stories →

The Platform

Powered by Lemon

Most firms rely on individual tester skill. We built a platform that makes quality structural — informed by 6,700+ previous assessments.

lemon.securitybrigade.com/project/PRJ-2847
D
C
F
R
T
PROJECT PRJ-2847
Coverage Validation — acmecorp.com
94% covered
Endpoints
247 / 263
Parameters
1,847
Auth Flows
12 / 12
JS Routes
38 / 41
AI flagged 3 undiscovered endpoints
/api/v2/admin/export, /api/v2/billing/webhook, /internal/healthcheck
L1 Complete
L2 In Review
L3 Pending

Lemon Audit Management Platform

End-to-end compliance workflow: evidence collection, finding management, remediation tracking, revalidation, and regulator-ready reporting.

B-52 AI-Powered Audit Engine

90 to 95 percent vulnerability coverage, zero false positives, attack chain mapping, and compliance-mapped findings for the VAPT component.

ShadowMap External Risk Monitoring

Discovers internet-facing assets, leaked credentials, dark web exposure, and vendor risks before the assessment begins.

Compliance-Ready

Audit-ready reporting for every framework

As a CERT-In empanelled firm, our reports are accepted by Indian regulators and meet global framework requirements.

Vulnerability Assessment and Penetration Testing
Web, mobile, API, network, and cloud VAPT covering all RBI-mandated security testing requirements.
Information Systems Audit
Comprehensive IS audit covering IT governance, application controls, general computing controls, and regulatory compliance.
Cybersecurity Policy Review
Review and gap assessment of board-approved cybersecurity policy against RBI circular requirements.
Access Control and Privilege Management
Assessment of RBAC, PAM, maker-checker, MFA, and access review processes across critical systems.
Incident Response Readiness
Review of IR procedures, escalation protocols, and regulatory reporting workflows. Tabletop drills available.
BCP/DR Testing and Validation
Business continuity plan review and disaster recovery drill assessment with evidence documentation.
Vendor Risk Assessment
Security assessment of third-party vendors, outsourced IT, CBS providers, and cloud service providers.
Phishing Simulation and Security Awareness
Adversary-grade spear phishing simulations that satisfy RBI mandates for phishing resilience testing.

Industries

1,000+ clients across verticals

Two decades of engagements across regulated and consumer-scale sectors.

BFSIICICI Bank, HDFC, Yes Bank, UTI MF, Edelweiss
Fintech & PaymentsPhonePe, Amazon Pay, Groww, BillDesk
ManufacturingMahindra, Asian Paints, L&T, Hindalco
Retail & ConsumerSwiggy, Sephora, Pernod Ricard, Jubilant
Aviation & LogisticsEtihad Airways, DHL Express, Shadowfax
HealthcareCloudNine, Pharmeasy, Wave Health

Quality Assurance

L1/L2/L3 Quality Review for Every Compliance Audit

Every RBI cybersecurity compliance report passes through three tiers of review before delivery.

RBI compliance reports carry regulatory weight — they are submitted to the regulator, presented to the board, and form the basis of supervisory assessments. Security Brigade applies a three-tier quality review to every compliance engagement to ensure findings are accurate, evidence is complete, recommendations are practical, and the report meets regulator submission standards. This review process is why our reports consistently pass regulatory scrutiny without rework.

L1: Analyst Review

The assessment team validates every finding with proof of exploitation, verifies evidence completeness, and maps findings to RBI requirements.

L2: Senior Auditor Review

A senior auditor reviews methodology coverage, validates risk ratings, checks for missed scope areas, and ensures remediation guidance is actionable.

L3: Approval and Sign-Off

Final review by engagement leadership — regulatory alignment, report structure, executive summary quality, and compliance attestation integrity before delivery.

Deliverables

What you get

Reports for two audiences — executives who need the risk picture, and developers who need to fix the issues. With code-level guidance, not vague advice.

Final System Audit Report (SAR)

Regulator-submission-ready report with scope, methodology, systems reviewed, audit period, observations, compliance status, and conclusion.

RBI Control Mapping Matrix

Each RBI requirement mapped to evidence, compliance status, observations, and auditor assessment.

VAPT and Technical Assessment Reports

Detailed vulnerability findings with proof of exploitation, CVSS scores, CWE mapping, and developer-level remediation guidance.

Gap Assessment and Remediation Roadmap

Risk-ranked gap analysis with owner assignments, severity ratings, target dates, and closure tracking.

Architecture and Data-Flow Annexure

System architecture, data-flow diagrams, storage locations, third-party integrations, and backup/DR documentation.

Executive Summary and Board Presentation

Management presentation covering compliance posture, key risks, remediation status, and recommendations for board and audit committee.

Closure Validation Report

Post-remediation revalidation confirming that identified gaps are closed and controls are operating as required.

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

Common questions

Can't find what you're looking for? Talk to our team.

Contact us
Who needs to comply with the RBI cybersecurity framework?+
Every RBI-regulated entity is covered, but not by the same instrument and not to the same depth. The six Directions issued on 31 July 2026 split by entity type: commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs and credit information companies each have their own. Within them the obligations are tiered. NBFCs are scoped by Scale Based Regulation layer - a Base Layer NBFC below Rs 500 crore carries Chapter III only, while Middle Layer and above carry the full baseline. UCBs are graded into four levels by digital depth and payment-system interconnectedness, so a small co-operative bank with UPI membership sits higher than its size suggests. Local area banks received no cybersecurity Direction in this batch. Payment aggregators and prepaid instrument issuers remain under their own Master Directions, which were not part of this consolidation.
Is a CERT-In empanelled auditor mandatory for RBI cybersecurity audits?+
Yes - and under the 2026 Directions there is now a documented reason to insist on it. CERT-In empanelment is required by name for the payment aggregator system audit under the PA-PG Master Direction and for the data-localisation System Audit Report, and SEBI CSCRF requires it as well. Within the RBI (Commercial Banks) Directions, 2026, para 156 requires the bank to assess the qualification, professional expertise, credentials and competency of the testing firm and of the personnel it assigns, at every selection, appointment, engagement and renewal - and empanelment is how that is evidenced. Para 159 then provides that where a CERT-In empanelled auditor is engaged, the bank is guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines, which brings a defined audit-policy regime into the supervisory relationship. Security Brigade has been CERT-In empanelled continuously since 2008.
What is the difference between RBI cybersecurity audit and RBI IS audit?+
The RBI cybersecurity audit focuses specifically on cybersecurity controls — VAPT, SOC, incident response, threat management, and cyber resilience. The IS (Information Systems) audit is broader, covering IT governance, application controls, general computing controls, data integrity, and IT risk management. Most RBI-regulated entities require both, and Security Brigade delivers them as a combined engagement to reduce duplication and cost.
How often must RBI cybersecurity audits be conducted?+
For critical information systems and those in the DMZ with a customer interface, the RBI Directions, 2026 require vulnerability assessment at least once every six months and penetration testing at least once in 12 months (para 151). Non-critical systems follow a risk-based approach the entity defines and defends. Testing also runs across the lifecycle - pre-implementation, post-implementation and after changes (para 150) - and is performed on the production environment, with any test-environment deviation documented and approved by the Information Security Committee (para 152). The status of closure of VA/PT observations goes to both the IT Strategy Committee and the Information Security Committee at least quarterly (para 161). On IS audit, the Directions require an IS Audit Policy approved by the Audit Committee of the Board and reviewed at least annually, with risk-based audit planning (paras 225, 228), rather than prescribing a fixed audit frequency. For payment aggregators, the PA Master Direction separately requires an annual system audit including cybersecurity audit. "Annual VAPT" understates the vulnerability assessment leg by a factor of two.
What penalties does RBI impose for cybersecurity non-compliance?+
RBI can impose monetary penalties, mandate corrective action plans, restrict business operations, suspend new product launches, and in severe cases direct board-level changes or supersede the board of cooperative banks. Penalties vary by entity type and severity of non-compliance. Beyond regulatory penalties, non-compliant entities face amplified scrutiny during cybersecurity incidents, which can result in additional regulatory action and reputational damage.
Does the RBI cybersecurity framework apply to NBFCs and fintechs?+
Yes, but by layer rather than uniformly. The RBI (NBFC) Directions, 2026 apply Chapter III to Base Layer NBFCs below Rs 500 crore in asset size and to Core Investment Companies, Chapter IV to Base Layer NBFCs at Rs 500 crore and above, and Chapter V to Middle Layer, Upper Layer and Top Layer NBFCs excluding Core Investment Companies. The VA/PT cadence and six-hour incident reporting sit in the Middle Layer and above tier. Housing finance companies report incidents to NHB rather than RBI. Fintechs operating under an NBFC licence are scoped by their layer; those operating under a payment aggregator licence remain under the PA-PG Master Direction, which was not part of this consolidation and which does require an annual system audit by a CERT-In empanelled auditor.
What does an RBI cybersecurity audit cover for cooperative banks?+
It depends on the bank’s level. The RBI (UCB) Directions, 2026 grade every UCB into one of four levels by digital depth and interconnectedness to the payment systems landscape rather than by asset size. Level I - every UCB, whatever it offers - carries board-approved policies and IT governance. Level II adds the baseline for UCBs that are CPS sub-members offering internet banking, a mobile banking app, or direct CTS, IMPS or UPI membership. Level III adds requirements for direct CPS members and banks running their own ATM switch or SWIFT. Level IV carries the full baseline including a Cyber Security Operations Centre. Across the applicable levels an audit covers board-approved cybersecurity policy, designated security leadership, VA/PT of core banking and digital channels, access controls, network security, log management, incident response and DAKSH reporting, BCP/DR, and vendor risk - including the contractual controls a UCB must impose on its ATM switch provider and the VA/PT it must obtain through a shared core banking provider (para 117).
How long does an RBI cybersecurity compliance engagement take?+
A typical RBI cybersecurity compliance engagement takes 6 to 8 weeks from scoping to final report delivery. This includes regulatory mapping, policy review, technical assessment (VAPT and IS audit), controls validation, gap assessment, remediation support, and final regulator-ready reporting. Timelines can vary based on entity size, number of applications in scope, and remediation requirements. Security Brigade tracks every milestone through the Lemon platform for full transparency.
Can Security Brigade handle both VAPT and IS audit under one RBI engagement?+
Yes, Security Brigade delivers VAPT and IS audit as a combined engagement for RBI-regulated entities. This integrated approach eliminates duplication, reduces coordination overhead, and produces a single coherent report that covers both cybersecurity testing and information systems governance. Most of our banking and NBFC clients prefer the combined engagement because it simplifies vendor management and accelerates compliance timelines.
What makes Security Brigade different from Big-4 firms for RBI audits?+
Security Brigade combines genuine cybersecurity depth with compliance expertise — we validate real systems including applications, APIs, infrastructure, and databases, not just review documents. Our CERT-In empanelment since 2008, proprietary platforms (Lemon for audit management, B-52 for AI-powered testing), and deep BFSI experience across 1,000+ clients means you get a regulator-ready report backed by real technical validation, with faster remediation support and senior attention that larger firms cannot match.

Ready to Achieve RBI Cybersecurity Compliance?

Talk to our compliance team to scope your RBI cybersecurity audit — banks, NBFCs, and cooperative banks.

Typically responds within 1 business day · No commitment required

Request a Scoping Call