RBI Cybersecurity Directions for Small Finance Banks and Payments Banks
In force since 31 July 2026, applying whole — no tiering, no threshold, no transition period.
SFBs: RBI/DoS/2026-27/419 · DoS.CO.CSITEG.13/31.01.015/2026-27 · Payments Banks: RBI/DoS/2026-27/428 · DoS.CO.CSITEG.22/31.01.015/2026-27
Scope
Who this instrument reaches
Both instruments apply to their whole population with no tiering of any kind. There is no Level, no layer and no asset threshold to work out — every paragraph applies to every Small Finance Bank and every Payments Bank from the day of issuance.
Small Finance Banks and Payments Banks received separate instruments on the same day, drafted in identical terms, and both apply whole with no tiering. That is the practical headline: there is no threshold to fall below and no self-assessment to perform. The businesses underneath the identical text are not alike — a Small Finance Bank lends into segments where a customer's phone is the entire channel, while a Payments Bank cannot lend at all and lives on deposits, payments volume and the partnerships that generate it.
Obligations
What the instrument requires, paragraph by paragraph
Each obligation below carries its paragraph number and its modality. A "shall" and a "may" are different duties, and vendors sell them as the same one.
Vulnerability assessment and penetration testing
¶150 in both · MandatoryFor critical information systems and / or those in the DMZ having a customer interface, VA at least once every six months and PT at least once in 12 months. For non-critical systems, a risk-based approach decides whether and how often. The scope test is disjunctive — either limb triggers it.
Anti-phishing / anti-rogue-app takedown subscription
¶147 in both · MandatorySubscribe to anti-phishing and anti-rogue-app services from external service providers, for identifying and taking down phishing websites and rogue applications. Both instruments require this to be bought from outside; it is not a control that can be built internally to satisfy the paragraph.
Six-hour DAKSH report, plus CERT-In
¶181 in both · MandatoryReport cyber incidents within six hours of detection on the DAKSH platform, and also pro-actively notify CERT-In. The six hours attaches to DAKSH alone; the instrument prescribes no timeline for the CERT-In limb.
Red teaming exercises
¶161 in both · Permitted, not requiredThe bank MAY conduct red teaming exercises to identify vulnerabilities and business risk, assess the efficacy of its defences and check mitigating controls by simulating an attacker's objectives and actions. This is permissive. It has been permissive in RBI cyber guidance for a decade, and nothing in 2026 changed that.
Testing scope
What VA and PT has to reach here
The agent and partner channel is where these models differ from a conventional bank and where the exposure concentrates. Transactions are initiated by people who are not employees, on devices the bank does not own, through interfaces the bank published — and the customer attributes every part of that to the bank. The second concentration is the app itself: for a large share of these customers there is no branch alternative, so an availability or integrity failure in the application is a total loss of service rather than a degraded one.
Both models put nearly the whole business on a digital channel, which is the scope:
- The core banking platform and the digital channels layered over it
- Payment rail integrations — UPI, IMPS, NEFT and RTGS — and the switch in front of them
- Business correspondent, agent and micro-ATM channels, where the operator is not your employee
- Merchant and partner integrations, including the co-branded surfaces customers see as yours
- Digital onboarding and video KYC, which is both a customer journey and a fraud target
- Card management and issuance systems, where cards are issued
Where this differs
Six instruments, one date — and they are not interchangeable
The six Directions issued on 31 July 2026 share a drafting template, which makes it tempting to read one and assume the rest. These are the places where the instrument for Small Finance Banks and Payments Banks departs from its siblings.
- The two instruments are textually identical on every obligation that matters here — the same paragraph numbers carrying the same words. They are separate instruments with separate reference numbers, and each bank is subject to its own.
- Neither instrument tiers its population. Firms arriving from the UCB Level conversation or the NBFC layer conversation look for the threshold that reduces their scope, and there is not one.
- Red teaming is expressly permitted rather than required — one of only three of the six instruments to mention it at all.
Where this goes wrong
There is no tier to find
Both instruments were issued alongside four siblings that do tier — the UCB Levels, the NBFC layers — and the reflex is to go looking for the equivalent. Time spent looking is time not spent on a programme that commenced on issuance. The other half of the same trap is scope: ¶150's test is disjunctive, so a system in the DMZ with a customer interface is in scope whether or not anyone has classified it as critical. Scoping to the critical-systems register alone under-scopes it by design.
How we help
CERT-In empanelled since 2008
The instrument makes you assess the qualification, professional expertise, credentials and competency of your testing firm and of the named personnel, at every selection and every renewal. Empanelment is how that gets evidenced, and where an empanelled auditor is engaged, CERT-In's Comprehensive Cyber Security Audit Policy Guidelines are imported into the supervisory relationship.
Read against Reserve Bank of India (SFBs / PBs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — two instruments, issued the same day, issued 31 July 2026 by the Department of Supervision.