Skip to main content
RBI Directions 2026 · Urban Co-operative Banks

RBI Cybersecurity Directions for Urban Co-operative Banks

In force since 31 July 2026. Which chapters reach you is decided by your Level, at ¶4.

RBI/DoS/2026-27/437 · DoS.CO.CSITEG.31/31.01.015/2026-27

Scope

Who this instrument reaches

A UCB is placed in one of four Levels by its digital depth and its interconnectedness to the payment systems landscape, and the Level decides which chapters apply. The categorisation is self-assessed (¶10), and nothing in it turns on asset size.

The UCB Directions are the only instrument of the six that tiers its population by capability, and the Level test asks what you offer rather than what you are worth. Internet banking, a mobile app, direct membership of CTS, IMPS or UPI, an ATM Switch, a SWIFT interface, a data centre serving other banks — each of these is a rung. A bank that has grown digitally without growing its balance sheet climbs; one that has done the reverse does not.

Level Criteria Chapters
Level I Every UCB, whatever digital services or products it offers Chapters II and III
Level II A sub-member of Centralised Payment Systems that also offers internet banking (view or transaction based), or mobile banking through a smartphone application, or is a direct member of CTS, IMPS or UPI Chapters II, III and IV
Level III A direct member of Centralised Payment Systems, or a UCB with its own ATM Switch, or one with a SWIFT interface Chapters II, III, IV and V
Level IV A direct or sub-member of CPS that has both its own ATM Switch and a SWIFT interface, or that hosts a data centre or provides software support to other banks — directly or through a wholly owned subsidiary Chapters II, III, IV, V and VI

Source: Reserve Bank of India (UCBs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, ¶4.

Obligations

What the instrument requires, paragraph by paragraph

Each obligation below carries its paragraph number and its modality. A "shall" and a "may" are different duties, and vendors sell them as the same one.

Vulnerability assessment and penetration testing

¶116 · Mandatory Level II and above

VA / PT periodically for internet-facing web and mobile applications, servers and network components throughout their lifecycle — pre-implementation, post-implementation and after changes. VA of critical applications and those on the DMZ at least once every six months. PT at least once in a year.

Testing a shared CBS through the ASP

¶117 · Mandatory Level II and above

A UCB whose Core Banking System sits on the shared infrastructure of an Application Service Provider shall get the CBS application, including the infrastructure hosting it, subjected to VA / PT through that CBS-ASP. The duty is yours; the access is theirs.

Anti-phishing / anti-rogue-app takedown subscription

¶123 · Mandatory Level II and above

Subscribe to anti-phishing and anti-rogue-application services from external service providers, for identifying and taking down phishing websites and rogue applications. This is an obligation the instrument requires you to satisfy externally — it cannot be discharged in-house.

Incident notification to CERT-In

¶87 · Mandatory All Levels

Put in place an effective mechanism to report cyber incidents in a timely manner and take appropriate action to mitigate them, and pro-actively notify CERT-In. This limb carries no fixed clock.

Six-hour DAKSH report

¶88 · Mandatory All Levels

Report cyber incidents within six hours of detection on the DAKSH platform. The UCB instrument splits the two limbs across separate paragraphs, and the six hours attaches only to this one.

Red teaming

no counterpart · No counterpart in this instrument

The UCB instrument contains no red-teaming paragraph at all. Three of the six 2026 Directions permit red teaming with "may"; this is not one of them, and there is nothing here to permit or require it.

Testing scope

What VA and PT has to reach here

Co-operative banks carry the same payment-rail connectivity as much larger institutions with a fraction of the in-house technology function, and the shared-infrastructure model means the systems that matter most are frequently operated by somebody else. That is not a weakness in itself — it is a concentration. When one Application Service Provider serves a large number of banks, its security posture is the sector's, and the instrument responds by making each bank contractually responsible for imposing controls on it.

The systems that decide your Level are the same ones that decide your scope:

  • The Core Banking System, whether run in-house or on a shared Application Service Provider platform
  • Internet banking, in view-only or transactional form — either one is a Level trigger
  • The mobile banking application, as a published artefact as well as a service
  • CTS, IMPS and UPI membership interfaces, direct or through a sponsor
  • The ATM Switch, where owned, and the SWIFT interface where present
  • The branch network, its endpoints and the links connecting them to the core

Where this differs

Six instruments, one date — and they are not interchangeable

The six Directions issued on 31 July 2026 share a drafting template, which makes it tempting to read one and assume the rest. These are the places where the instrument for Urban Co-operative Banks departs from its siblings.

  • VA / PT is drafted differently here from every sibling. The others set a six-month VA and a twelve-month PT against one scope — critical and / or DMZ-with-customer-interface. UCB ¶116 sets the six-month VA against critical applications and those on the DMZ, and states the PT obligation separately as "at least once in a year" with no scope qualifier attached to it.
  • The two incident limbs live in two paragraphs, ¶87 and ¶88, rather than in one sentence. Both apply from Level I.
  • A Level I UCB carries no VA / PT obligation of its own — and can still be contractually obliged to impose VA / PT and a security operations centre on its ATM Switch ASP.

Where this goes wrong

Level is a product decision made by a product owner

Launching a mobile banking app or taking direct UPI membership moves a bank up a Level, and both are commercial decisions taken for commercial reasons on a commercial timetable. The compliance consequence arrives with them, immediately, because the instrument commenced on issuance and has no glide path. There is also a naming hazard worth being deliberate about: the four Levels here are not the asset-size Tiers used elsewhere in UCB regulation, and trade coverage has already conflated the two. Confirm your Level against ¶4 rather than against a Tier you already know.

How we help

CERT-In empanelled since 2008

The instrument makes you assess the qualification, professional expertise, credentials and competency of your testing firm and of the named personnel, at every selection and every renewal. Empanelment is how that gets evidenced, and where an empanelled auditor is engaged, CERT-In's Comprehensive Cyber Security Audit Policy Guidelines are imported into the supervisory relationship.

Read against Reserve Bank of India (UCBs — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued 31 July 2026 by the Department of Supervision.