RBI Cybersecurity Directions for Credit Information Companies
In force since 31 July 2026, applying whole — no tiering, no threshold, no transition period.
RBI/DoS/2026-27/470 · DoS.CO.CSITEG.64/31.01.015/2026-27
Scope
Who this instrument reaches
The instrument applies to Credit Information Companies as defined under section 2(e) of the Credit Information Companies (Regulation) Act, 2005, with no tiering. Every paragraph applies to every CIC.
Credit Information Companies received their own instrument with no tiering, which is the right shape for a category this small and this concentrated. A CIC does not hold money and does not move it. It holds the record on which lending decisions across the entire system are made, written to by thousands of member institutions and read by thousands more — which is a different kind of systemic position, and one where an integrity failure propagates outward through every lender that queried the record.
Obligations
What the instrument requires, paragraph by paragraph
Each obligation below carries its paragraph number and its modality. A "shall" and a "may" are different duties, and vendors sell them as the same one.
Vulnerability assessment and penetration testing
¶146 · MandatoryFor critical information systems and / or those in the DMZ having a customer interface, VA at least once every six months and PT at least once in 12 months. For non-critical systems, a risk-based approach decides the requirement and the periodicity.
Anti-phishing / anti-rogue-app takedown subscription
¶143 · MandatorySubscribe to anti-phishing and anti-rogue-app services from external service providers, for identifying and taking down phishing websites and rogue applications — a duty the instrument places outside the organisation by construction.
Six-hour DAKSH report, plus CERT-In
¶177 · MandatoryReport cyber incidents within six hours of detection on the DAKSH platform, and also pro-actively notify CERT-In. The six-hour clock attaches to DAKSH only.
Red teaming exercises
¶157 · Permitted, not requiredThe CIC MAY conduct red teaming exercises to identify vulnerabilities and business risk, assess the efficacy of its defences and check mitigating controls. Permissive, not mandatory.
Testing scope
What VA and PT has to reach here
The database describes almost every borrower in the country, which makes it a target for disclosure — and the disclosure risk is not primarily at the perimeter. Enquiry access is issued to a very large number of member institutions, and a legitimate member credential abused at volume looks like business as usual. The integrity direction matters as much: an altered record changes lending outcomes for a person who has no visibility of it, and the correction workflow is itself an authorised path to change data, which makes it worth defending as carefully as the database.
The scope is the ingestion-to-disclosure pipeline in both directions:
- The credit information database and the change history behind it
- Member submission interfaces, including the bulk uploads through which lenders write records
- Lender-facing enquiry APIs and the entitlement model deciding who may pull which record
- Consumer-facing report portals, including free-annual-report delivery and the identity verification in front of it
- Dispute, correction and update workflows, which are the only sanctioned route to alter a record
- Data-sharing arrangements with permitted users and the controls attached to them
Where this differs
Six instruments, one date — and they are not interchangeable
The six Directions issued on 31 July 2026 share a drafting template, which makes it tempting to read one and assume the rest. These are the places where the instrument for Credit Information Companies departs from its siblings.
- No tiering at all (¶3) — the smallest population of the six, and every one of them gets the whole instrument.
- A CIC under these Directions is a Credit Information Company. Under the NBFC Directions the same abbreviation means Core Investment Company, which receives Chapter III and is expressly excluded from Chapter V. The two are unrelated and land on entirely different instruments.
Where this goes wrong
Two different things are abbreviated CIC
Under these Directions, a CIC is a Credit Information Company and receives the whole instrument. Under the NBFC Directions, a CIC is a Core Investment Company, receives Chapter III — three paragraphs — and is expressly carved out of Chapter V. The two categories have nothing to do with each other. A compliance memo, a vendor proposal or an internal scoping note that resolves the abbreviation the wrong way lands on the wrong instrument entirely, and the error is invisible in a document that never spells the term out.
How we help
CERT-In empanelled since 2008
The instrument makes you assess the qualification, professional expertise, credentials and competency of your testing firm and of the named personnel, at every selection and every renewal. Empanelment is how that gets evidenced, and where an empanelled auditor is engaged, CERT-In's Comprehensive Cyber Security Audit Policy Guidelines are imported into the supervisory relationship.
Read against Reserve Bank of India (CICs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued 31 July 2026 by the Department of Supervision.