Skip to main content
CERT-In Empanelled Since 2008 — Required by name for payment aggregator system audits and the data-localisation SAR, and the credential para 156 makes your bank evidence at every selection and renewal. Security Brigade is one of India’s longest-standing CERT-In empanelled auditors.

RBI Cybersecurity Framework Compliance for Banks, NBFCs, and Cooperative Banks

The framework was repealed on 31 July 2026 and the Directions that replaced it are already in force, with no transition period. Assessment, incident response, digital forensics and BCP/DR testing against the instrument that actually applies to you, by a CERT-In empanelled auditor - continuously empanelled since 2008, across 1,000+ clients.

6,700+
Assessments
RBI-Aligned
Methodology
Since 2008
CERT-In Empanelled
Banks · NBFCs
Sectors Served

On 31 July 2026 the Reserve Bank repealed 628 circulars and issued 64 consolidated Directions in their place. Cybersecurity received six of them - one each for commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs and credit information companies - and all six commenced on issuance. For banks that means vulnerability assessment every six months and penetration testing every 12 months for critical and DMZ customer-facing systems (para 151), cyber incidents on the DAKSH platform within six hours of detection (para 182), and a CISO who does not report to the Head of IT (paras 27-28). Security Brigade has been CERT-In empanelled since 2008.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

What you are looking for

The 2016 framework was repealed. What you did under it still counts

You searched for an instrument that no longer exists. Here is what replaced it, and what happens to the audit and the board approval you already hold. Nobody has published that second part.

The RBI Cyber Security Framework was the Reserve Bank’s June 2016 circular for banks. On 31 July 2026 it was repealed, together with the 2023 IT Governance, Risk, Compliance and Assurance Master Direction and 626 other circulars, and replaced by six entity-specific Directions issued the same day by the Department of Supervision. Banks are governed by the Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, reference RBI/DoS/2026-27/410, running to 233 paragraphs across eight chapters. All six instruments commenced immediately on issuance. There is no glide path, no phased date and no transition window anywhere in any of them. What that does not mean is that your existing work evaporated. Paragraph 231 is the savings clause, and it is the paragraph to paste into your file note: action taken under the repealed instruments remains governed by those instruments, and approvals already granted are deemed granted under the 2026 Directions. Your March audit still stands. Your board approval still stands. What changes is the instrument you cite from here, and the paragraph numbers you cite from it.

The honest split

Most of it carried forward. A handful of things genuinely did not

A CISO reading a "ten things RBI now requires" listicle is reading padding. These are the obligations that moved, set against the ones that only changed their citation.

ObligationWhat the 2026 text saysStatus
VA and PT cadence Vulnerability assessment at least once every six months and penetration testing at least once in twelve months, for systems that are critical and / or sit in the DMZ with a customer interface. The scope test is disjunctive: either limb on its own brings a system in. "Annual VAPT" understates the vulnerability assessment leg by a factor of two. Carried forward: ¶151, the identical wording of the 2023 Master Direction §26(a)
Lifecycle testing Pre-implementation, post-implementation on production, and after changes. Where testing runs in a test environment instead, the deviation is documented and approved by the Information Security Committee. Carried forward: ¶¶150, 152
Auditor competency, at every renewal The bank shall have control over audit methodology, processes and the competence of auditors, and at every selection, appointment, engagement or renewal shall consider the qualification, professional expertise, credentials and competency of the firm as well as of the personnel it assigns. This is a duty on the bank, discharged with evidence about the auditor. NEW: ¶156, no counterpart in 2016 or 2023
Assurance stated explicitly Reasonable assurance for each of the areas in scope shall be provided explicitly in the VA / PT report, and that expectation shall be set when the bank empanels its own auditor panel or awards the contract. This is a report-format mandate: a list of findings, with assurance left to be inferred from their absence, is the standard Indian format and is what this paragraph stops being sufficient. NEW: ¶157
Breach-triggered auditor deficiency Where a tested system is later compromised apparently through a vulnerability that was not observed or highlighted on a timely basis in the VA / PT, that will qualify as a deficiency in the discharge of function by the auditor, to be factored in at selection and renewal. Retrospective performance liability, running backwards into work already delivered. NEW: ¶158
Cloud The documented VA / PT approach, covering scope, coverage and CVSS-type scoring, shall also apply to information systems hosted in a cloud environment. The 2023 Master Direction said "may". One word, and it is the cleanest checkable change in the instrument. NEW: ¶154, "may" became "shall"
Quarterly closure reporting Status of closure of VA / PT observations goes to both the IT Strategy Committee and the Information Security Committee, at least quarterly. A new cadence and a new artefact, and the one most likely to be discovered late. NEW: ¶161
Red teaming Red teams may be used. The word is "may", and it was "may" in the 2016 framework’s Annex 1 §18.5 as well: permissive for ten years and permissive still. Carried forward: ¶162
Worth stating plainly because the opposite is widely repeated. If a vendor tells you the 2026 Directions made red teaming compulsory, they have not read ¶162.
Anti-phishing and rogue-app takedown Subscription to anti-phishing and anti-rogue-app services from external providers. The instrument locates this outside the bank by design. An internal staff phishing simulation is a different control and does not discharge it. Carried forward: ¶148, verbatim from the 2016 Annex 1 §14.1

VA and PT cadence

What the 2026 text says
Vulnerability assessment at least once every six months and penetration testing at least once in twelve months, for systems that are critical and / or sit in the DMZ with a customer interface. The scope test is disjunctive: either limb on its own brings a system in. "Annual VAPT" understates the vulnerability assessment leg by a factor of two.
Status
Carried forward: ¶151, the identical wording of the 2023 Master Direction §26(a)

Lifecycle testing

What the 2026 text says
Pre-implementation, post-implementation on production, and after changes. Where testing runs in a test environment instead, the deviation is documented and approved by the Information Security Committee.
Status
Carried forward: ¶¶150, 152

Auditor competency, at every renewal

What the 2026 text says
The bank shall have control over audit methodology, processes and the competence of auditors, and at every selection, appointment, engagement or renewal shall consider the qualification, professional expertise, credentials and competency of the firm as well as of the personnel it assigns. This is a duty on the bank, discharged with evidence about the auditor.
Status
NEW: ¶156, no counterpart in 2016 or 2023

Assurance stated explicitly

What the 2026 text says
Reasonable assurance for each of the areas in scope shall be provided explicitly in the VA / PT report, and that expectation shall be set when the bank empanels its own auditor panel or awards the contract. This is a report-format mandate: a list of findings, with assurance left to be inferred from their absence, is the standard Indian format and is what this paragraph stops being sufficient.
Status
NEW: ¶157

Breach-triggered auditor deficiency

What the 2026 text says
Where a tested system is later compromised apparently through a vulnerability that was not observed or highlighted on a timely basis in the VA / PT, that will qualify as a deficiency in the discharge of function by the auditor, to be factored in at selection and renewal. Retrospective performance liability, running backwards into work already delivered.
Status
NEW: ¶158

Cloud

What the 2026 text says
The documented VA / PT approach, covering scope, coverage and CVSS-type scoring, shall also apply to information systems hosted in a cloud environment. The 2023 Master Direction said "may". One word, and it is the cleanest checkable change in the instrument.
Status
NEW: ¶154, "may" became "shall"

Quarterly closure reporting

What the 2026 text says
Status of closure of VA / PT observations goes to both the IT Strategy Committee and the Information Security Committee, at least quarterly. A new cadence and a new artefact, and the one most likely to be discovered late.
Status
NEW: ¶161

Red teaming

What the 2026 text says
Red teams may be used. The word is "may", and it was "may" in the 2016 framework’s Annex 1 §18.5 as well: permissive for ten years and permissive still.
Status
Carried forward: ¶162

Worth stating plainly because the opposite is widely repeated. If a vendor tells you the 2026 Directions made red teaming compulsory, they have not read ¶162.

Anti-phishing and rogue-app takedown

What the 2026 text says
Subscription to anti-phishing and anti-rogue-app services from external providers. The instrument locates this outside the bank by design. An internal staff phishing simulation is a different control and does not discharge it.
Status
Carried forward: ¶148, verbatim from the 2016 Annex 1 §14.1

The paragraphs about us

Three paragraphs regulate your auditor, not your bank

Of 233 paragraphs, three are about the firm doing the testing, and they are identical across all six instruments. They change what you have to be able to evidence about whoever you appoint.

¶156: the credential test, at every renewal

Not a one-time check at onboarding. At each selection, appointment, engagement or renewal, the bank considers the qualification, professional expertise, credentials and competency of the firm and of the named personnel assigned to the work. Empanelment is how that is evidenced, and ¶159 provides that where a CERT-In empanelled auditor is engaged, the bank is guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. Security Brigade has been CERT-In empanelled continuously since 2008.

¶157: assurance, stated not implied

Reasonable assurance for each area in scope has to appear explicitly in the report, and the requirement has to be stated at the point you empanel a panel or award the contract. Read it before you write your next RFP: it is a specification for a document, and the duty to ask for it is the bank’s, and not the auditor’s to volunteer.

¶158: the clause nobody is discussing

If a system we tested is later compromised through a vulnerability the testing did not surface in time, that counts as a deficiency by the auditor and follows them into the next selection and renewal. It is a real question to ask a prospective auditor, and the honest answer involves coverage evidence, review depth and what happens when something is missed. It is never a promise that nothing will be.

What we test

Each engagement, and the paragraph it answers

You are holding a control register with a citation column. This is the list in the only form that is useful here: keyed to the paragraph the work discharges.

The engagementThe duty it dischargesParagraph
Vulnerability assessment and penetration testing The six-monthly VA and twelve-monthly PT against critical and / or DMZ-with-customer-interface systems, and the risk-based cadence for everything else. ¶151
Pre- and post-implementation testing Testing across the lifecycle instead of once a year, including after changes, with test-environment deviations documented and ISC-approved. ¶¶150, 152
Application security testing Application testing expressly not restricted to the OWASP Top 10, covering business logic and authorisation as well as the common classes. ¶85
Source code review Source-code level audit of applications, alongside the black-box testing and not in place of it. ¶91
Cloud security assessment The documented VA / PT approach extended to cloud-hosted systems, the obligation that moved from "may" to "shall". ¶154
Anti-phishing and rogue-app takedown The external-provider subscription for phishing sites and rogue mobile applications. Delivered through ShadowMap, which is where an external takedown capability has to sit. ¶148
Quarterly closure pack The closure-status reporting the IT Strategy Committee and the Information Security Committee have to receive at least quarterly. ¶161

Vulnerability assessment and penetration testing

The duty it discharges
The six-monthly VA and twelve-monthly PT against critical and / or DMZ-with-customer-interface systems, and the risk-based cadence for everything else.
Paragraph
¶151

Pre- and post-implementation testing

The duty it discharges
Testing across the lifecycle instead of once a year, including after changes, with test-environment deviations documented and ISC-approved.
Paragraph
¶¶150, 152

Application security testing

The duty it discharges
Application testing expressly not restricted to the OWASP Top 10, covering business logic and authorisation as well as the common classes.
Paragraph
¶85

Source code review

The duty it discharges
Source-code level audit of applications, alongside the black-box testing and not in place of it.
Paragraph
¶91

Cloud security assessment

The duty it discharges
The documented VA / PT approach extended to cloud-hosted systems, the obligation that moved from "may" to "shall".
Paragraph
¶154

Anti-phishing and rogue-app takedown

The duty it discharges
The external-provider subscription for phishing sites and rogue mobile applications. Delivered through ShadowMap, which is where an external takedown capability has to sit.
Paragraph
¶148

Quarterly closure pack

The duty it discharges
The closure-status reporting the IT Strategy Committee and the Information Security Committee have to receive at least quarterly.
Paragraph
¶161

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade follows a six-phase methodology for every RBI cybersecurity compliance engagement. This methodology is consistent whether the entity is a scheduled commercial bank, an NBFC, or a cooperative bank — the scope and depth are calibrated to the specific regulatory requirements and the entity's digital footprint. Every phase is tracked through our Lemon audit management platform with evidence collection, finding assignment, remediation tracking, and closure validation built into the workflow.

Discovery
01

Scoping and Regulatory Mapping

Identify the applicable RBI circulars, map regulatory requirements to the entity's systems, applications, infrastructure, and vendors.

02

Policy and Governance Review

Review cybersecurity policy, IT governance structure, committee charters, risk assessments, and board-level reporting mechanisms.

Testing
03

Technical Assessment (VAPT and IS Audit)

Vulnerability assessment, penetration testing, application security testing, network security review, and configuration audit of critical systems.

04

Controls Validation and Evidence Review

Validate access controls, incident response, BCP/DR, vendor management, data localisation, logging, and monitoring against RBI requirements with evidence collection.

Delivery
05

Gap Assessment and Remediation Support

Risk-ranked gap report with practical remediation guidance, owner assignments, and target closure dates. Security Brigade supports your team through closure.

06

Final Report and Regulator-Ready Deliverables

Final compliance report, control mapping matrix, evidence annexures, and management presentation — ready for RBI submission and board review.

"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
CISO, Top-3 Indian Bank
Chief Information Security Officer

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

The Directions set a floor for how often testing happens, and a floor is not a ceiling. What changes when assessment runs continuously instead of to the stated cadence is a question this page raises and B-52 answers.

See the B-52 platform Built and run by Security Brigade

FAQ

What banks ask in the first call

Eight weeks into the new regime, these are the questions that actually come up, and not the ones a content plan would predict.

Contact us
Does the audit we completed in March still count?+
Yes. Paragraph 231 of the Commercial Banks Directions saves it: action taken under the repealed instruments remains governed by those instruments, and approvals already granted are deemed granted under the 2026 Directions. You do not re-run completed work. What changes is the instrument and paragraph you cite for the next cycle, and the new obligations that attach to it: explicit per-area assurance at ¶157, and quarterly closure reporting at ¶161.
Do we need a CERT-In empanelled auditor?+
There is now a documented reason to insist on it. Paragraph 156 requires the bank to assess the qualification, professional expertise, credentials and competency of the testing firm and of the personnel it assigns, at every selection, appointment, engagement and renewal. Empanelment is how that is evidenced. Paragraph 159 then provides that where a CERT-In empanelled auditor is engaged, the bank is guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. Security Brigade has been empanelled continuously since 2008.
Is annual VAPT still enough?+
Not for the vulnerability assessment leg. Paragraph 151 sets vulnerability assessment at least once every six months and penetration testing at least once in twelve months, for systems that are critical and / or in the DMZ with a customer interface. A programme built around one annual exercise meets the penetration testing cadence and misses the vulnerability assessment cadence by half. Paragraph 150 then adds testing pre-implementation, post-implementation and after changes, which an annual calendar does not describe at all.
Did the 2026 Directions make red teaming compulsory?+
No. Paragraph 162 says red teams may be used, and the 2016 framework said the same at Annex 1 §18.5, so it has been permissive for a decade and remains so. Red teaming is worth doing where it answers a question a penetration test cannot, and that is the basis to scope it on, and not a mandate that does not exist.
What is the six-hour reporting clock?+
Paragraph 182 requires cyber incidents to be reported to the Reserve Bank through DAKSH within six hours of detection. That clock attaches to the DAKSH limb. Other reporting obligations exist and run on their own instruments and their own timings, and conflating them into a single six-hour deadline is a common error in vendor material.
Is a cyber security audit the same as an IS audit?+
They are different obligations under the same instrument. Chapter VII deals with Information Systems Audit and sits separately from the VA / PT regime in Chapter V. A programme scoped only to VA / PT does not discharge the IS Audit requirement, and this is the distinction most often collapsed when a bank consolidates its assurance calendar.
Our paragraph numbers do not match the ones in this article. Why?+
Because you are probably reading a different instrument. RBI issued six on 31 July 2026, each with its own numbering: the six-monthly VA obligation is ¶151 for commercial banks, ¶150 for small finance banks and payments banks, ¶146 for credit information companies, ¶121 for NBFCs at Middle Layer and above, and ¶116 for urban co-operative banks at Level II and above. A citation lifted from a bank-facing article is the wrong number on an NBFC submission.

Ready to Achieve RBI Cybersecurity Compliance?

Talk to our compliance team to scope your RBI cybersecurity audit — banks, NBFCs, and cooperative banks.

Typically responds within 1 business day · No commitment required

Request a Scoping Call

By entity class

RBI issued six Directions on 31 July 2026, not one circular

They share a drafting template and they are not interchangeable — two of them contain no red-teaming paragraph at all, one has no anti-rogue-app takedown duty, and one drafts VA and PT differently from every sibling. Each page below states what applies to that entity class, with the paragraph numbers.

Our reading of the circulars

What the text actually requires

Aug 2026ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on YouFour of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract: 24 of them for commercial banks, 37 for urban co-operative banks. The controls land on the provider, and the bank is the one that has to put them there.Aug 2026Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys YouThe RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups. The relaxation is conditional: RBI has to accept your explanation.Aug 2026Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 CadenceA commercial bank on annual point-in-time VAPT re-scoped its programme to the RBI Directions, 2026: six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC produced for the first time.Aug 2026RBI Cybersecurity Directions for Small Finance Banks, Payments Banks and Credit Information CompaniesSmall finance banks, payments banks and credit information companies each get their own instrument, and the full baseline binds from day one. SFBs and payments banks are expressly carved out of the commercial banks Direction, so their paragraph numbers come from elsewhere.Aug 2026RBI Cybersecurity Directions for Urban Co-operative Banks: Finding Your LevelThe four Levels in RBI/DoS/2026-27/437 are set by digital depth and payment-system interconnectedness, not asset size. UPI, IMPS or CTS membership lifts a small bank to Level II, where VA/PT begins.Aug 2026RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your LayerRBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.Aug 2026Paragraph 148: The One RBI Obligation You Are Not Allowed to Satisfy In-HouseThe RBI Directions, 2026 are mostly outcome-based. Paragraph 148 also names the delivery model: anti-phishing and anti-rogue-app takedown procured as services from external service providers.Aug 2026RBI VAPT Requirements in 2026: Six Months, Twelve Months, and What "Critical and/or DMZ" MeansVulnerability assessment every six months, penetration testing every twelve. The scope is disjunctive, the cloud extension is new, and "annual VAPT", which we published ourselves until this month, understates the tested cadence by half.Aug 2026Paragraph 158: When a Breach Becomes Your Auditor's DeficiencyThree paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor. One of them is new: a later breach of a tested system becomes a recorded deficiency against the auditor, carried into renewal.Apr 2026RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do NowThe framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.