Six RBI Directions, one date.
Which one applies to you.
On 31 July 2026 RBI repealed 628 circulars and issued 64 consolidated Directions. Cybersecurity got six of them — one per class of regulated entity — and all six commenced on issuance. They are not the same document. Scoping, cadence anchors and, for NBFCs and co-operative banks, which chapters bind at all, differ between them.
The six instruments
Side by side, with paragraph numbers.
Coverage so far treats this as one framework. It is six, and the differences decide what your board actually has to approve. Every cell below was read out of the instrument named in its row.
| Entity | Instrument | VA | PT | Red teaming | Anti-phishing takedown | Incident reporting |
|---|---|---|---|---|---|---|
| Commercial Banks Banking companies other than SFBs, payments banks and local area banks, plus corresponding new banks and SBI | RBI/DoS/2026-27/410 Whole instrument. Foreign branch-mode banks get comply-or-explain. | Every 6 months Para 151 | Every 12 months Para 151 | Discretionary Para 162 says “may” | Required Para 148 | 6 hours, on DAKSH Para 182 |
| Small Finance Banks All SFBs | RBI/DoS/2026-27/419 Whole instrument, no tiering. | Every 6 months Para 150 | Every 12 months Para 150 | Discretionary Para 161 says “may” | Required Para 147 | 6 hours, on DAKSH Para 181 |
| Payments Banks All payments banks | RBI/DoS/2026-27/428 Whole instrument, no tiering. | Every 6 months Para 150 | Every 12 months Para 150 | Discretionary Para 161 says “may” | Required Para 147 | 6 hours, on DAKSH Para 181 |
| Urban Co-operative Banks Primary co-operative banks under s.5(ccv) read with s.56, BR Act 1949 | RBI/DoS/2026-27/437 Four Levels by digital depth. Chapters bind by Level. | Every 6 months Para 116, Level II+ | At least once a year Para 116, Level II+ | Not mentioned Absent from the instrument | Required Para 123 | 6 hours, on DAKSH Para 88 |
| NBFCs NBFCs registered under the RBI Act, Factoring Regulation Act or NHB Act | RBI/DoS/2026-27/461 By Scale Based Regulation layer. Chapters bind by layer. | Every 6 months Para 121, Middle Layer+ | Every 12 months Para 121, Middle Layer+ | Not mentioned Absent from the instrument | No takedown duty No counterpart | 6 hours, on DAKSH Para 141, or 28 for Base Layer |
| Credit Information Companies CICs under s.2(e), CIC (Regulation) Act 2005 | RBI/DoS/2026-27/470 Whole instrument, no tiering. | Every 6 months Para 146 | Every 12 months Para 146 | Discretionary Para 157 says “may” | Required Para 143 | 6 hours, on DAKSH Para 177 |
Cadences apply to critical information systems and / or those in the DMZ with a customer interface — the scope is disjunctive, so either category triggers the obligation. Non-critical systems follow a risk-based approach you define and defend.
NBFCs
Your layer decides your chapter.
The NBFC Directions do not apply uniformly. Paragraph 3 assigns each chapter to a Scale Based Regulation band, and the bands are mutually exclusive — you take one chapter, not all of them.
Base Layer, under ₹500 crore
Chapter III onlyThree paragraphs. No VA/PT cadence, no incident deadline, no security operations centre. Core Investment Companies sit here too.
Base Layer, ₹500 crore and above
Chapter IV onlyIT governance, IT policy, information security, IT operations, IS audit, BCP/DR and IT services outsourcing. Six-hour incident reporting arrives here at paragraph 28.
Middle, Upper and Top Layer
Chapter V onlyThe full baseline — IT governance, risk management, baseline cybersecurity and IS audit. VA/PT cadence at paragraph 121. Core Investment Companies are expressly excluded from this chapter.
Urban co-operative banks
Four Levels, set by digital depth.
Not by asset size. Paragraph 4 grades each UCB by how deep its digital services run and how directly it connects to the payment systems landscape. A small bank with UPI membership sits higher than its balance sheet suggests, and the obligations are cumulative as you climb.
Level I
Chapters II–IIIEvery UCB, whatever digital services it offers.
Level II
+ Chapter IVSub-member of Centralised Payment Systems and offering internet banking, a mobile banking app, or direct membership of CTS, IMPS or UPI. VA/PT starts here.
Level III
+ Chapter VDirect CPS member, running its own ATM Switch, or on SWIFT.
Level IV
+ Chapter VICarries a full Cyber Security Operations Centre, cyber drills, metrics and forensics.
Shared core banking. Paragraph 117 requires a UCB running its CBS on an Application Service Provider's shared infrastructure to have that application and the infrastructure hosting it subjected to VA/PT through the CBS-ASP. Paragraphs 83 to 86 separately require a list of named baseline controls to be imposed on ATM Switch providers by contract — which means a Level I UCB can be obliged to demand controls of its provider that it does not carry itself.
Three things to get right
Where the published summaries go wrong.
"CIC" means two different things.
In the NBFC Directions it is a Core Investment Company — Chapter III, and expressly excluded from Chapter V. In /470 it is a Credit Information Company, taking the whole instrument. Different populations, different obligations, same three letters.
Red teaming is still not mandated.
Paragraph 162 says a bank "may". It said the same in 2016. The UCB and NBFC instruments do not mention red teaming at all. SEBI CSCRF is the Indian framework that mandates it — half-yearly, for MIIs and Qualified REs. A proposal that tells you RBI requires it is worth re-reading for what else it got wrong.
"Annual VAPT" halves the tested cadence.
Penetration testing is the twelve-month leg. Vulnerability assessment is six-monthly in every instrument that carries a cadence. A programme built on an annual cycle is out of compliance for half of each year on the VA side.
Where we fit
CERT-In empanelled since 2008.
Paragraph 156 requires you to assess the qualification, professional expertise, credentials and competency of your testing firm and of the personnel it assigns, at every selection and renewal. Empanelment is how that gets evidenced, and paragraph 159 brings CERT-In's Comprehensive Cyber Security Audit Policy Guidelines into your supervisory relationship when an empanelled auditor is engaged.
The statutory cadence
Six-monthly VA and annual PT across web, mobile, API, network and cloud — tested on production as paragraph 152 requires, across the lifecycle as paragraph 150 does.
Reports built for paragraph 157
Explicit reasonable assurance stated per area in scope, documented methodology and scoring, and a closure pack your ITSC and ISC can take as read under paragraph 161.
The paragraph 148 obligation
Anti-phishing and anti-rogue-app takedown must come from an external provider. ShadowMap discharges it directly, with brand and app-store surveillance alongside.
Questions
Frequently asked
How many RBI cybersecurity Directions were issued on 31 July 2026?
Six, one per class of regulated entity: commercial banks (RBI/DoS/2026-27/410), small finance banks (/419), payments banks (/428), urban co-operative banks (/437), NBFCs (/461) and credit information companies (/470). They sit inside a much larger consolidation — RBI/DoS/2026-27/221 repealed 628 circulars and issued 64 consolidated Directions the same day. Local area banks received no cybersecurity Direction in the batch.
When do the RBI Directions, 2026 come into force?
Immediately on issuance. All six say so in their own second paragraph, and a sweep of all six for transition language returns no deferred compliance dates. There is no glide path, no phase-in and no comment period. Any obligation you are not already meeting is a gap today rather than a project for the next financial year.
Which RBI Direction applies to an NBFC?
RBI/DoS/2026-27/461, but which chapters bind depends on your Scale Based Regulation layer. Chapter III applies to Base Layer NBFCs below ₹500 crore in asset size and to Core Investment Companies. Chapter IV applies to Base Layer NBFCs at ₹500 crore and above. Chapter V applies to Middle, Upper and Top Layer NBFCs, excluding Core Investment Companies. The VA/PT cadence at paragraph 121 and the six-hour incident reporting at paragraph 141 sit in the Middle Layer and above tier. Housing finance companies report incidents to NHB rather than RBI.
How are urban co-operative banks tiered under the 2026 Directions?
By digital depth and interconnectedness to the payment systems landscape, into four Levels at paragraph 4 — not by asset size. Level I is every UCB and carries Chapters II and III. Level II adds Chapter IV for UCBs that are CPS sub-members offering internet banking, a mobile banking app, or direct CTS, IMPS or UPI membership. Level III adds Chapter V for direct CPS members, own-ATM-Switch operators and SWIFT users. Level IV adds Chapter VI, including a Cyber Security Operations Centre. A small UCB with UPI membership therefore sits higher than its balance sheet suggests. Note that some trade coverage has described UCBs using the asset-size "Tier" taxonomy used elsewhere in UCB regulation; that is a different scheme and does not govern here.
Do the RBI Directions, 2026 mandate red teaming?
No. The commercial banks instrument says at paragraph 162 that a bank "may" conduct red teaming exercises — permissive, and permissive in the 2016 framework before it. The small finance bank and payments bank instruments carry the same permissive wording at their own paragraph 161, and the credit information company instrument at paragraph 157. The UCB and NBFC Directions do not mention red teaming at all. SEBI CSCRF is the Indian instrument that does mandate it, half-yearly, for MIIs and Qualified REs.
What is the six-hour reporting requirement under the RBI Directions, 2026?
Cyber incidents must be reported within six hours of detection on DAKSH, RBI’s Advanced Supervisory Monitoring System, and CERT-In must also be notified proactively (paragraph 182 for commercial banks). Read the two limbs separately: the six-hour clock in this instrument attaches to DAKSH. CERT-In’s own 2022 Directions set a six-hour requirement independently, so both clocks exist — but they come from different instruments, and a policy document should cite them separately.
Does "CIC" mean the same thing across the RBI Directions, 2026?
No, and this catches people. In the NBFC Directions (/461) a CIC is a Core Investment Company — it takes Chapter III and is expressly excluded from Chapter V. In /470 a CIC is a Credit Information Company, of which there are four, and it takes the whole instrument. They are different populations with different obligations.