RBI Cybersecurity Framework Compliance for Banks, NBFCs, and Cooperative Banks
The framework was repealed on 31 July 2026 and the Directions that replaced it are already in force, with no transition period. Assessment, incident response, digital forensics and BCP/DR testing against the instrument that actually applies to you, by a CERT-In empanelled auditor - continuously empanelled since 2008, across 1,000+ clients.
On 31 July 2026 the Reserve Bank repealed 628 circulars and issued 64 consolidated Directions in their place. Cybersecurity received six of them - one each for commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs and credit information companies - and all six commenced on issuance. For banks that means vulnerability assessment every six months and penetration testing every 12 months for critical and DMZ customer-facing systems (para 151), cyber incidents on the DAKSH platform within six hours of detection (para 182), and a CISO who does not report to the Head of IT (paras 27-28). Security Brigade has been CERT-In empanelled since 2008.
Trusted by India's leading enterprises
What you are looking for
The 2016 framework was repealed. What you did under it still counts
You searched for an instrument that no longer exists. Here is what replaced it, and what happens to the audit and the board approval you already hold. Nobody has published that second part.
The RBI Cyber Security Framework was the Reserve Bank’s June 2016 circular for banks. On 31 July 2026 it was repealed, together with the 2023 IT Governance, Risk, Compliance and Assurance Master Direction and 626 other circulars, and replaced by six entity-specific Directions issued the same day by the Department of Supervision. Banks are governed by the Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, reference RBI/DoS/2026-27/410, running to 233 paragraphs across eight chapters. All six instruments commenced immediately on issuance. There is no glide path, no phased date and no transition window anywhere in any of them. What that does not mean is that your existing work evaporated. Paragraph 231 is the savings clause, and it is the paragraph to paste into your file note: action taken under the repealed instruments remains governed by those instruments, and approvals already granted are deemed granted under the 2026 Directions. Your March audit still stands. Your board approval still stands. What changes is the instrument you cite from here, and the paragraph numbers you cite from it.
The honest split
Most of it carried forward. A handful of things genuinely did not
A CISO reading a "ten things RBI now requires" listicle is reading padding. These are the obligations that moved, set against the ones that only changed their citation.
| Obligation | What the 2026 text says | Status |
|---|---|---|
| VA and PT cadence | Vulnerability assessment at least once every six months and penetration testing at least once in twelve months, for systems that are critical and / or sit in the DMZ with a customer interface. The scope test is disjunctive: either limb on its own brings a system in. "Annual VAPT" understates the vulnerability assessment leg by a factor of two. | Carried forward: ¶151, the identical wording of the 2023 Master Direction §26(a) |
| Lifecycle testing | Pre-implementation, post-implementation on production, and after changes. Where testing runs in a test environment instead, the deviation is documented and approved by the Information Security Committee. | Carried forward: ¶¶150, 152 |
| Auditor competency, at every renewal | The bank shall have control over audit methodology, processes and the competence of auditors, and at every selection, appointment, engagement or renewal shall consider the qualification, professional expertise, credentials and competency of the firm as well as of the personnel it assigns. This is a duty on the bank, discharged with evidence about the auditor. | NEW: ¶156, no counterpart in 2016 or 2023 |
| Assurance stated explicitly | Reasonable assurance for each of the areas in scope shall be provided explicitly in the VA / PT report, and that expectation shall be set when the bank empanels its own auditor panel or awards the contract. This is a report-format mandate: a list of findings, with assurance left to be inferred from their absence, is the standard Indian format and is what this paragraph stops being sufficient. | NEW: ¶157 |
| Breach-triggered auditor deficiency | Where a tested system is later compromised apparently through a vulnerability that was not observed or highlighted on a timely basis in the VA / PT, that will qualify as a deficiency in the discharge of function by the auditor, to be factored in at selection and renewal. Retrospective performance liability, running backwards into work already delivered. | NEW: ¶158 |
| Cloud | The documented VA / PT approach, covering scope, coverage and CVSS-type scoring, shall also apply to information systems hosted in a cloud environment. The 2023 Master Direction said "may". One word, and it is the cleanest checkable change in the instrument. | NEW: ¶154, "may" became "shall" |
| Quarterly closure reporting | Status of closure of VA / PT observations goes to both the IT Strategy Committee and the Information Security Committee, at least quarterly. A new cadence and a new artefact, and the one most likely to be discovered late. | NEW: ¶161 |
| Red teaming | Red teams may be used. The word is "may", and it was "may" in the 2016 framework’s Annex 1 §18.5 as well: permissive for ten years and permissive still. | Carried forward: ¶162 |
| Worth stating plainly because the opposite is widely repeated. If a vendor tells you the 2026 Directions made red teaming compulsory, they have not read ¶162. | ||
| Anti-phishing and rogue-app takedown | Subscription to anti-phishing and anti-rogue-app services from external providers. The instrument locates this outside the bank by design. An internal staff phishing simulation is a different control and does not discharge it. | Carried forward: ¶148, verbatim from the 2016 Annex 1 §14.1 |
VA and PT cadence
- What the 2026 text says
- Vulnerability assessment at least once every six months and penetration testing at least once in twelve months, for systems that are critical and / or sit in the DMZ with a customer interface. The scope test is disjunctive: either limb on its own brings a system in. "Annual VAPT" understates the vulnerability assessment leg by a factor of two.
- Status
- Carried forward: ¶151, the identical wording of the 2023 Master Direction §26(a)
Lifecycle testing
- What the 2026 text says
- Pre-implementation, post-implementation on production, and after changes. Where testing runs in a test environment instead, the deviation is documented and approved by the Information Security Committee.
- Status
- Carried forward: ¶¶150, 152
Auditor competency, at every renewal
- What the 2026 text says
- The bank shall have control over audit methodology, processes and the competence of auditors, and at every selection, appointment, engagement or renewal shall consider the qualification, professional expertise, credentials and competency of the firm as well as of the personnel it assigns. This is a duty on the bank, discharged with evidence about the auditor.
- Status
- NEW: ¶156, no counterpart in 2016 or 2023
Assurance stated explicitly
- What the 2026 text says
- Reasonable assurance for each of the areas in scope shall be provided explicitly in the VA / PT report, and that expectation shall be set when the bank empanels its own auditor panel or awards the contract. This is a report-format mandate: a list of findings, with assurance left to be inferred from their absence, is the standard Indian format and is what this paragraph stops being sufficient.
- Status
- NEW: ¶157
Breach-triggered auditor deficiency
- What the 2026 text says
- Where a tested system is later compromised apparently through a vulnerability that was not observed or highlighted on a timely basis in the VA / PT, that will qualify as a deficiency in the discharge of function by the auditor, to be factored in at selection and renewal. Retrospective performance liability, running backwards into work already delivered.
- Status
- NEW: ¶158
Cloud
- What the 2026 text says
- The documented VA / PT approach, covering scope, coverage and CVSS-type scoring, shall also apply to information systems hosted in a cloud environment. The 2023 Master Direction said "may". One word, and it is the cleanest checkable change in the instrument.
- Status
- NEW: ¶154, "may" became "shall"
Quarterly closure reporting
- What the 2026 text says
- Status of closure of VA / PT observations goes to both the IT Strategy Committee and the Information Security Committee, at least quarterly. A new cadence and a new artefact, and the one most likely to be discovered late.
- Status
- NEW: ¶161
Red teaming
- What the 2026 text says
- Red teams may be used. The word is "may", and it was "may" in the 2016 framework’s Annex 1 §18.5 as well: permissive for ten years and permissive still.
- Status
- Carried forward: ¶162
Worth stating plainly because the opposite is widely repeated. If a vendor tells you the 2026 Directions made red teaming compulsory, they have not read ¶162.
Anti-phishing and rogue-app takedown
- What the 2026 text says
- Subscription to anti-phishing and anti-rogue-app services from external providers. The instrument locates this outside the bank by design. An internal staff phishing simulation is a different control and does not discharge it.
- Status
- Carried forward: ¶148, verbatim from the 2016 Annex 1 §14.1
The paragraphs about us
Three paragraphs regulate your auditor, not your bank
Of 233 paragraphs, three are about the firm doing the testing, and they are identical across all six instruments. They change what you have to be able to evidence about whoever you appoint.
¶156: the credential test, at every renewal
Not a one-time check at onboarding. At each selection, appointment, engagement or renewal, the bank considers the qualification, professional expertise, credentials and competency of the firm and of the named personnel assigned to the work. Empanelment is how that is evidenced, and ¶159 provides that where a CERT-In empanelled auditor is engaged, the bank is guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. Security Brigade has been CERT-In empanelled continuously since 2008.
¶157: assurance, stated not implied
Reasonable assurance for each area in scope has to appear explicitly in the report, and the requirement has to be stated at the point you empanel a panel or award the contract. Read it before you write your next RFP: it is a specification for a document, and the duty to ask for it is the bank’s, and not the auditor’s to volunteer.
¶158: the clause nobody is discussing
If a system we tested is later compromised through a vulnerability the testing did not surface in time, that counts as a deficiency by the auditor and follows them into the next selection and renewal. It is a real question to ask a prospective auditor, and the honest answer involves coverage evidence, review depth and what happens when something is missed. It is never a promise that nothing will be.
What we test
Each engagement, and the paragraph it answers
You are holding a control register with a citation column. This is the list in the only form that is useful here: keyed to the paragraph the work discharges.
| The engagement | The duty it discharges | Paragraph |
|---|---|---|
| Vulnerability assessment and penetration testing | The six-monthly VA and twelve-monthly PT against critical and / or DMZ-with-customer-interface systems, and the risk-based cadence for everything else. | ¶151 |
| Pre- and post-implementation testing | Testing across the lifecycle instead of once a year, including after changes, with test-environment deviations documented and ISC-approved. | ¶¶150, 152 |
| Application security testing | Application testing expressly not restricted to the OWASP Top 10, covering business logic and authorisation as well as the common classes. | ¶85 |
| Source code review | Source-code level audit of applications, alongside the black-box testing and not in place of it. | ¶91 |
| Cloud security assessment | The documented VA / PT approach extended to cloud-hosted systems, the obligation that moved from "may" to "shall". | ¶154 |
| Anti-phishing and rogue-app takedown | The external-provider subscription for phishing sites and rogue mobile applications. Delivered through ShadowMap, which is where an external takedown capability has to sit. | ¶148 |
| Quarterly closure pack | The closure-status reporting the IT Strategy Committee and the Information Security Committee have to receive at least quarterly. | ¶161 |
Vulnerability assessment and penetration testing
- The duty it discharges
- The six-monthly VA and twelve-monthly PT against critical and / or DMZ-with-customer-interface systems, and the risk-based cadence for everything else.
- Paragraph
- ¶151
Pre- and post-implementation testing
- The duty it discharges
- Testing across the lifecycle instead of once a year, including after changes, with test-environment deviations documented and ISC-approved.
- Paragraph
- ¶¶150, 152
- The duty it discharges
- Application testing expressly not restricted to the OWASP Top 10, covering business logic and authorisation as well as the common classes.
- Paragraph
- ¶85
- The duty it discharges
- Source-code level audit of applications, alongside the black-box testing and not in place of it.
- Paragraph
- ¶91
- The duty it discharges
- The documented VA / PT approach extended to cloud-hosted systems, the obligation that moved from "may" to "shall".
- Paragraph
- ¶154
Anti-phishing and rogue-app takedown
- The duty it discharges
- The external-provider subscription for phishing sites and rogue mobile applications. Delivered through ShadowMap, which is where an external takedown capability has to sit.
- Paragraph
- ¶148
Quarterly closure pack
- The duty it discharges
- The closure-status reporting the IT Strategy Committee and the Information Security Committee have to receive at least quarterly.
- Paragraph
- ¶161
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade follows a six-phase methodology for every RBI cybersecurity compliance engagement. This methodology is consistent whether the entity is a scheduled commercial bank, an NBFC, or a cooperative bank — the scope and depth are calibrated to the specific regulatory requirements and the entity's digital footprint. Every phase is tracked through our Lemon audit management platform with evidence collection, finding assignment, remediation tracking, and closure validation built into the workflow.
Scoping and Regulatory Mapping
Identify the applicable RBI circulars, map regulatory requirements to the entity's systems, applications, infrastructure, and vendors.
Policy and Governance Review
Review cybersecurity policy, IT governance structure, committee charters, risk assessments, and board-level reporting mechanisms.
Technical Assessment (VAPT and IS Audit)
Vulnerability assessment, penetration testing, application security testing, network security review, and configuration audit of critical systems.
Controls Validation and Evidence Review
Validate access controls, incident response, BCP/DR, vendor management, data localisation, logging, and monitoring against RBI requirements with evidence collection.
Gap Assessment and Remediation Support
Risk-ranked gap report with practical remediation guidance, owner assignments, and target closure dates. Security Brigade supports your team through closure.
Final Report and Regulator-Ready Deliverables
Final compliance report, control mapping matrix, evidence annexures, and management presentation — ready for RBI submission and board review.
"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Attack Surface
Continuous discovery of internet-facing assets: sub-domains, APIs, cloud resources, open ports, SSL certificates, technology stack.
Audits are point-in-time. ShadowMap watches your boundary daily.
Explore on ShadowMapCART · Continuous Automated Red-Teaming
Automated vulnerability detection and validation on your live attack surface — exploit context delivered, not just scanner noise.
Annual audits prove a moment. CART proves resilience continuously.
Explore on ShadowMapThe platform underneath
The instrument sets the cadence. B-52 is what runs at it.
The Directions set a floor for how often testing happens, and a floor is not a ceiling. What changes when assessment runs continuously instead of to the stated cadence is a question this page raises and B-52 answers.
FAQ
What banks ask in the first call
Eight weeks into the new regime, these are the questions that actually come up, and not the ones a content plan would predict.
Contact usDoes the audit we completed in March still count?
Do we need a CERT-In empanelled auditor?
Is annual VAPT still enough?
Did the 2026 Directions make red teaming compulsory?
What is the six-hour reporting clock?
Is a cyber security audit the same as an IS audit?
Our paragraph numbers do not match the ones in this article. Why?
Ready to Achieve RBI Cybersecurity Compliance?
Talk to our compliance team to scope your RBI cybersecurity audit — banks, NBFCs, and cooperative banks.
Typically responds within 1 business day · No commitment required
By entity class
RBI issued six Directions on 31 July 2026, not one circular
They share a drafting template and they are not interchangeable — two of them contain no red-teaming paragraph at all, one has no anti-rogue-app takedown duty, and one drafts VA and PT differently from every sibling. Each page below states what applies to that entity class, with the paragraph numbers.
Our reading of the circulars