RBI Cybersecurity Directions for NBFCs
In force since 31 July 2026. Which chapters reach you is decided by your Scale Based Regulation layer, at ¶3.
RBI/DoS/2026-27/461 · DoS.CO.CSITEG.55/31.01.015/2026-27
Scope
Who this instrument reaches
Every NBFC registered with RBI under the RBI Act 1934, the Factoring Regulation Act 2011 or the NHB Act 1987 is in scope — but which chapter reaches you is set by your Scale Based Regulation layer, and the three chapters are very different in size.
The NBFC Directions are the only one of the six to split their own population three ways, and the split is by Scale Based Regulation layer rather than by anything about the technology. The consequence is stark at the bottom: the largest group of NBFCs in the country receives three paragraphs, while a Middle Layer NBFC receives a chapter running to more than a hundred. Nothing in the layer test asks what you have built.
| Applies | Criteria | Chapters |
|---|---|---|
| Chapter III only | NBFCs in the Base Layer with asset size below ₹500 crore, and Core Investment Companies | Chapter III (¶¶7–9) |
| Chapter IV only | NBFCs in the Base Layer with asset size of ₹500 crore and above | Chapter IV (¶¶10–64) |
| Chapter V only | NBFCs in the Middle, Upper and Top Layers — expressly excluding Core Investment Companies | Chapter V (¶65 onwards) |
Source: Reserve Bank of India (NBFCs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, ¶3.
Obligations
What the instrument requires, paragraph by paragraph
Each obligation below carries its paragraph number and its modality. A "shall" and a "may" are different duties, and vendors sell them as the same one.
Vulnerability assessment and penetration testing
¶121 · Mandatory Middle Layer and aboveVA at least once every six months and PT at least once in 12 months, for critical information systems and / or those in the DMZ having a customer interface — either category triggers it. VA / PT also across the lifecycle: pre-implementation, post-implementation and after changes.
Six-hour incident reporting
¶28 · Mandatory Base Layer, ₹500 crore and aboveReport cyber incidents on the DAKSH platform within six hours of detection. This limb stands alone at this layer — the instrument attaches no separate notification duty here.
Six-hour DAKSH report, plus CERT-In
¶141 · Mandatory Middle Layer and aboveReport cyber incidents to RBI within six hours of detection on DAKSH, and also pro-actively notify CERT-In. The six hours attaches to DAKSH; no timeline is prescribed for the CERT-In limb. Housing Finance Companies report to NHB, not RBI.
Preventive and corrective measures against named threats
¶27 · Mandatory Base Layer, ₹500 crore and aboveAddress denial of service and DDoS, ransomware, destructive malware, business email fraud including spam, email phishing, spear phishing, whaling and vishing, drive-by downloads, browser gateway fraud, ghost administrator exploits, identity fraud, memory update fraud and password-related fraud.
Annual review of security infrastructure and policy
¶98 · Mandatory Middle Layer and aboveReview security infrastructure and security policies at least annually, factoring in your own experience and emerging threats, and take steps to tackle phishing and spoofing attacks and mitigate their effects.
Anti-phishing / anti-rogue-app takedown subscription
no counterpart · No counterpart in this instrumentThe NBFC instrument carries no counterpart to the takedown-subscription duty its siblings impose. Phishing is addressed as a threat to be countered (¶27, ¶98); what is absent is the duty to subscribe to an external takedown service. That is a difference in what is mandated, not in whether the exposure exists.
Red teaming
no counterpart · No counterpart in this instrumentThe NBFC instrument contains no red-teaming paragraph at all — not a permissive one, not a mandatory one. Any vendor telling an NBFC that RBI now requires red teaming is describing a different instrument.
Testing scope
What VA and PT has to reach here
A digital lending operation concentrates the most sensitive categories of personal data — identity, income, bank statements, bureau history — in systems built for acquisition speed. The layer test does not see any of that. A Base Layer NBFC below the threshold can run a nationally distributed app on the same rails as a Middle Layer competitor and receive three paragraphs of obligation, and its borrowers cannot tell the difference and neither can an attacker.
What that means in practice is that the testable surface does not scale with the layer:
- Loan origination and loan management platforms, and the customer journey in front of them
- Digital lending applications published in your name, including those built and operated by a lending service provider
- Co-lending and partner APIs, where another regulated entity's systems reach directly into yours
- Collections, repayment and mandate infrastructure — NACH, UPI autopay and the instruction paths behind them
- Credit bureau and account aggregator interfaces
- Customer data stores holding KYC documents, income evidence and bureau pulls
Where this differs
Six instruments, one date — and they are not interchangeable
The six Directions issued on 31 July 2026 share a drafting template, which makes it tempting to read one and assume the rest. These are the places where the instrument for NBFCs departs from its siblings.
- Three chapters, three populations. A Base Layer NBFC below ₹500 crore receives Chapter III — three paragraphs — with no VA / PT paragraph, no incident deadline and no security operations requirement. That is the largest tier of the largest population in the sector.
- "CIC" here means Core Investment Company, which takes Chapter III and is expressly excluded from Chapter V. In the Credit Information Companies Directions the same three letters mean something entirely different and attract the whole instrument.
- Housing Finance Companies report cyber incidents to NHB rather than RBI (¶141) — the only such redirection across the six instruments.
Where this goes wrong
The layer decides your chapter, not your exposure
Reading the applicable chapter as the specification for a security programme is the mistake this instrument invites. Chapter III is what RBI requires of a small Base Layer NBFC. It is not what a co-lending partner requires in its contract, not what a bank requires before it will fund you, not what the Digital Personal Data Protection regime asks of a borrower data store, and not what a compromised lending app costs. Firms that scope to the chapter discover the gap during diligence, at the point where it is most expensive.
How we help
CERT-In empanelled since 2008
The instrument makes you assess the qualification, professional expertise, credentials and competency of your testing firm and of the named personnel, at every selection and every renewal. Empanelment is how that gets evidenced, and where an empanelled auditor is engaged, CERT-In's Comprehensive Cyber Security Audit Policy Guidelines are imported into the supervisory relationship.
Read against Reserve Bank of India (NBFCs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued 31 July 2026 by the Department of Supervision.