Red teaming in Indian financial regulation.
What is actually mandated.
SEBI mandates it. RBI does not. Most published guidance on this gets it wrong, and RBI's 31 July 2026 Directions repealed the 2016 framework that much of it still cites. Here is the position with paragraph numbers, including where the honest answer is "no requirement".
The position, by regulator
Mandate, permission, or guidance.
The three are routinely conflated, usually in the direction that sells more testing. They are not the same thing, and a board paper that treats a "may" as a "shall" will not survive contact with your auditor.
SEBI
MANDATE CSCRF, standard DE.DP.S4, guideline 1Applies to: MIIs and Qualified REs
Cadence: Half-yearly
The framework’s own periodicity table lists "Red Teaming exercise (DE.DP.S4) | MIIs and Qualified REs | Half-yearly". Mid-size REs and below have no red teaming requirement.
RBI
PERMITTED Directions, 2026, paragraph 162Applies to: Commercial banks
Cadence: None specified
Permissive, and substantively a carry-forward of the 2016 framework’s Annex 1 item 18.5. RBI rewrote this framework from scratch in July 2026 and chose to leave red teaming optional.
CERT-In
GUIDANCE CISG-2025-02, §6 item xviApplies to: Any auditee
Cadence: Within the annual ICT audit
Red Team Assessment is named as one of 26 engagement types falling within the scope of a cyber security audit. The guideline expects comprehensive ICT audit coverage at least once a year; it does not single out red teaming as separately mandatory.
This table covers the instruments we have verified against primary documents. It is not a statement that no other Indian regulator addresses red teaming — insurance and pensions sit outside it, and we would rather leave a gap than assert a mandate we have not read in the original.
RBI · the correction
"May", not "shall" — and a repeal most content has missed.
On 31 July 2026 the RBI issued the Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/410), effective immediately. Paragraph 230 repealed the June 2016 Cyber Security Framework and the IT Governance instructions as they applied to commercial banks.
“The bank may conduct red teaming exercises to identify the vulnerabilities and the business risk, assess the efficacy of the defences and check the mitigating controls already in place by simulating the objectives and actions of an attacker.”
— RBI Directions, 2026, paragraph 162
What RBI does mandate is VA/PT, in the section immediately before, which uses "shall" throughout:
“For critical information systems and / or those in the DMZ having customer interface, VA shall be conducted at least once in every six months and PT at least once in 12 months.”
— paragraph 151
These Directions apply to commercial banks under section 5 of the Banking Regulation Act, 1949, and expressly exclude Small Finance Banks, Payments Banks and Local Area Banks. Foreign bank branches operate on a comply-or-explain basis.
SEBI · the mandate
Half-yearly, for MIIs and Qualified REs.
“REs shall conduct red teaming exercises as part of their cybersecurity framework on a half-yearly basis through use of red/ blue teams.”
— CSCRF, standard DE.DP.S4, guideline 1
The standard itself is broader — MIIs and Qualified REs shall conduct goal-based adversarial simulation red teaming exercise on a periodic basis — with the half-yearly cadence fixed by the guideline beneath it and confirmed in the framework's periodicity table.
CSCRF does not require you to hire us
“For red teaming exercise, a red team may consist of REs employees and/ or outside experts. Additionally, the red team shall be independent of the function being tested.”
The binding requirement is independence from the function being tested — not that the team is external. An in-house team meeting that test satisfies the control. Most REs engage externally because sustaining the capability costs more than it saves, but that is a commercial judgement, not a compliance one, and anyone telling you otherwise is selling.
Scope is narrower than it first appears. SEBI's 28 August 2025 technical clarifications introduced the Principle of Exclusivity — CSCRF applies to systems used exclusively for SEBI-regulated activities — and the Principle of Equivalence, under which controls with an equivalent in your primary regulator's framework are deemed compliant. Red teaming appears in that equivalence table.
The Microsoft 365 question
No regulator named your M365 tenant. It is still in scope.
We are asked this often enough to answer it directly: no Indian instrument requires a "Microsoft 365 red team". No circular from RBI, SEBI, IRDAI, PFRDA, CERT-In, CSIRT-Fin or NCIIPC names Microsoft 365, Office 365, Entra ID or Azure AD as a required assessment target. Indian regulators write against control objectives, not vendor products, and they do so consistently. If you have a notice claiming otherwise, ask for the instrument number and date.
But the scoping conclusion people are reaching is usually correct, just for the wrong reason. Your M365 tenant is an internet-facing, business-critical, cloud-hosted identity and collaboration platform. That is squarely inside the scope language that already binds you:
“The bank shall put in place a documented approach for conduct of VA / PT covering the scope, coverage, vulnerability scoring mechanism (e.g., Common Vulnerability Scoring System) and all other aspects. This shall also apply to the bank’s information systems hosted in a cloud environment.”
— RBI Directions, 2026, paragraph 154
Read with paragraph 151's six-monthly VA and annual PT for critical and customer-interface systems, the obligation already exists — the scoping decision is yours. The practical gap we see is that M365 exposure is an identity-plane problem, and a conventional network penetration test does not go near it: device-code phishing and OAuth token capture that need no password and complete no MFA challenge, attacker devices registered into the tenant, and mailbox access through Graph rather than through anything a perimeter scan would see.
Common questions
Answered with citations.
Does the RBI require banks to conduct red teaming?
No. The Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — RBI/DoS/2026-27/410, dated 31 July 2026 — state at paragraph 162 that a bank "may" conduct red teaming exercises. That is permissive language, and it is substantively unchanged from the June 2016 framework it replaced. The immediately preceding section on vulnerability assessment and penetration testing uses "shall" throughout, so the difference is deliberate drafting rather than an accident. Any content telling you RBI mandates red teaming is wrong.
So what does RBI actually mandate?
VA/PT. For critical information systems and those in the DMZ having a customer interface, vulnerability assessment must be conducted at least once every six months and penetration testing at least once every 12 months. The testing must be performed by appropriately trained and independent information security experts or auditors, the bank must maintain a documented approach covering scope, coverage and a vulnerability scoring mechanism, and closure status is reported quarterly to the IT Strategy Committee and the Information Security Committee.
Is the June 2016 RBI Cyber Security Framework still in force?
Not for commercial banks. Paragraph 230 of the 2026 Directions repealed the June 2016 Cyber Security Framework and the IT Governance instructions as applicable to commercial banks, with effect from 31 July 2026. A large amount of published guidance — including vendor and consultant material — still cites the 2016 circular as the live obligation. If you are reading something that does, check its date.
Do the 2026 RBI Directions apply to every bank?
No. They apply to commercial banks as defined under section 5 of the Banking Regulation Act, 1949, and expressly exclude Small Finance Banks, Payments Banks and Local Area Banks. Branches of foreign banks operate on a comply-or-explain basis. If you are an SFB, Payments Bank, NBFC or urban co-operative bank, your obligations sit in different instruments and you should not assume these paragraphs apply to you.
Does SEBI CSCRF require us to hire an external red team?
No, and this is worth being clear about even though we sell the service. CSCRF DE.DP.S4 guideline 3 states that a red team "may consist of REs employees and/ or outside experts" and that the red team "shall be independent of the function being tested." The binding requirement is independence from the tested function, not externality. An in-house team that genuinely meets that independence test satisfies the control. Most REs engage externally because building and retaining that capability internally costs more than it saves — but that is a commercial decision, not a compliance one.
How often must SEBI-regulated entities red team?
Half-yearly, for MIIs and Qualified REs. That comes from CSCRF standard DE.DP.S4 guideline 1 and is corroborated by the framework’s own periodicity table. Results go to the IT Committee and the Governing Board, lessons learned are submitted to SEBI within three months, and remediation status is monitored by the IT Committee. Mid-size REs and below have no red teaming requirement, though BAS/CART tooling may be recommended by the IT Committee as a proportionate control.
Does India have a threat-led penetration testing (TLPT) regime like TIBER-EU?
No. There is no Indian equivalent of TIBER-EU, CBEST or Hong Kong’s iCAST, and the phrase "threat-led penetration testing" does not appear in any Indian regulatory instrument. Content describing India’s "emerging threat-led testing guidance" is describing something that does not exist. Goal-based adversarial simulation under CSCRF DE.DP is the closest analogue, and it is not a TLPT framework.
Has any Indian regulator required a Microsoft 365 red team specifically?
No. No instrument from RBI, SEBI, IRDAI, PFRDA, CERT-In, CSIRT-Fin or NCIIPC names Microsoft 365, Office 365, Entra ID or Azure AD as a required assessment target. Indian regulators write requirements against control objectives, not named vendor products, and they consistently do so. If you have received a notice saying otherwise, ask the sender for the instrument number and date before scoping any work against it. What is genuinely true is that an internet-facing, business-critical, cloud-hosted identity and collaboration platform sits squarely inside the scope language that already exists.
Regulatory positions verified against primary sources on 4 August 2026. RBI's Directions were issued four days before that date, and CERT-In revises advisory pages in place — if you are reading this much later, check the instruments before relying on it.
Not sure what applies to you?
Tell us your entity type and we will map the actual obligations — including the ones that do not require us.