Skip to main content
RBI Directions 2026 · Credit Information Companies

RBI Cybersecurity Directions for Credit Information Companies

In force since 31 July 2026, applying whole — no tiering, no threshold, no transition period.

RBI/DoS/2026-27/470 · DoS.CO.CSITEG.64/31.01.015/2026-27

Scope

Who this instrument reaches

The instrument applies to Credit Information Companies as defined under section 2(e) of the Credit Information Companies (Regulation) Act, 2005, with no tiering. Every paragraph applies to every CIC.

Credit Information Companies received their own instrument with no tiering, which is the right shape for a category this small and this concentrated. A CIC does not hold money and does not move it. It holds the record on which lending decisions across the entire system are made, written to by thousands of member institutions and read by thousands more — which is a different kind of systemic position, and one where an integrity failure propagates outward through every lender that queried the record.

Obligations

What the instrument requires, paragraph by paragraph

Each obligation below carries its paragraph number and its modality. A "shall" and a "may" are different duties, and vendors sell them as the same one.

Vulnerability assessment and penetration testing

¶146 · Mandatory

For critical information systems and / or those in the DMZ having a customer interface, VA at least once every six months and PT at least once in 12 months. For non-critical systems, a risk-based approach decides the requirement and the periodicity.

Anti-phishing / anti-rogue-app takedown subscription

¶143 · Mandatory

Subscribe to anti-phishing and anti-rogue-app services from external service providers, for identifying and taking down phishing websites and rogue applications — a duty the instrument places outside the organisation by construction.

Six-hour DAKSH report, plus CERT-In

¶177 · Mandatory

Report cyber incidents within six hours of detection on the DAKSH platform, and also pro-actively notify CERT-In. The six-hour clock attaches to DAKSH only.

Red teaming exercises

¶157 · Permitted, not required

The CIC MAY conduct red teaming exercises to identify vulnerabilities and business risk, assess the efficacy of its defences and check mitigating controls. Permissive, not mandatory.

Testing scope

What VA and PT has to reach here

The database describes almost every borrower in the country, which makes it a target for disclosure — and the disclosure risk is not primarily at the perimeter. Enquiry access is issued to a very large number of member institutions, and a legitimate member credential abused at volume looks like business as usual. The integrity direction matters as much: an altered record changes lending outcomes for a person who has no visibility of it, and the correction workflow is itself an authorised path to change data, which makes it worth defending as carefully as the database.

The scope is the ingestion-to-disclosure pipeline in both directions:

  • The credit information database and the change history behind it
  • Member submission interfaces, including the bulk uploads through which lenders write records
  • Lender-facing enquiry APIs and the entitlement model deciding who may pull which record
  • Consumer-facing report portals, including free-annual-report delivery and the identity verification in front of it
  • Dispute, correction and update workflows, which are the only sanctioned route to alter a record
  • Data-sharing arrangements with permitted users and the controls attached to them

Where this differs

Six instruments, one date — and they are not interchangeable

The six Directions issued on 31 July 2026 share a drafting template, which makes it tempting to read one and assume the rest. These are the places where the instrument for Credit Information Companies departs from its siblings.

  • No tiering at all (¶3) — the smallest population of the six, and every one of them gets the whole instrument.
  • A CIC under these Directions is a Credit Information Company. Under the NBFC Directions the same abbreviation means Core Investment Company, which receives Chapter III and is expressly excluded from Chapter V. The two are unrelated and land on entirely different instruments.

Where this goes wrong

Two different things are abbreviated CIC

Under these Directions, a CIC is a Credit Information Company and receives the whole instrument. Under the NBFC Directions, a CIC is a Core Investment Company, receives Chapter III — three paragraphs — and is expressly carved out of Chapter V. The two categories have nothing to do with each other. A compliance memo, a vendor proposal or an internal scoping note that resolves the abbreviation the wrong way lands on the wrong instrument entirely, and the error is invisible in a document that never spells the term out.

How we help

CERT-In empanelled since 2008

The instrument makes you assess the qualification, professional expertise, credentials and competency of your testing firm and of the named personnel, at every selection and every renewal. Empanelment is how that gets evidenced, and where an empanelled auditor is engaged, CERT-In's Comprehensive Cyber Security Audit Policy Guidelines are imported into the supervisory relationship.

Read against Reserve Bank of India (CICs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued 31 July 2026 by the Department of Supervision.