The RBI replaced the whole framework.
Which one binds you?
Seven Directions, one per licence class, all in force the day they were issued. No transition period. How much of yours applies is decided by facts that are not on your balance sheet.
What happened
Which one binds you?
Free · no emailPick your licence class. Two taps to your instrument, your tier and what you owe.
Indicative, based on the published notifications as we read them. Confirm your classification with your compliance function before acting on it.
Which instrument binds you
7 Directions- Urban co-operative bankLevels I–IV, by digital services2026-27/437
- NBFCBy layer; Base splits at ₹500 cr2026-27/461
- Commercial bankApplies as a whole2026-27/410
- Small finance bankApplies as a whole2026-27/419
- Payments bankApplies as a whole2026-27/428
- All India financial institutionApplies as a whole2026-27/456
- Credit information companyApplies as a whole2026-27/470
7 read in full · 0 carry their reference number only
Graded by what you do, not what you are worth
A ₹300-crore bank with UPI membership sits at Level II. The staircase is set by digital depth, not by size.
- Level I
- Every UCB
- Level II
- Sub-member + UPI/IMPS/CTS or net banking
- Level III
- Direct member, own switch, or SWIFT
- Level IV
- Switch + SWIFT, or hosts its own DC
One incident. Two filings. Six hours.
The RBI wants it on DAKSH within six hours of detection. CERT-In has wanted the same incident within six hours since 2022, under a different instrument, to a different recipient. Filing one does not discharge the other.
Directions under section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022
What you actually have to do
All 11 →- Information asset inventoryL1+
- Anti-virus and endpoint protectionL1+
- Change and patch managementL1+
- User access control and privileged accessL1+
- Data leak preventionL2+
- Email security and anti-phishingL1+
- Backup, restoration and continuityL1+
- Audit logs and monitoringL1+
- Vulnerability assessment and penetration testingL2+
- Information Systems Audit functionL1+
- Vendor and outsourcing risk, and the contract flow-downL1+
3 of these cannot be bought. Penetration testing is a service, the IS Audit function is a team, and the contract flow-down is a negotiation with your existing providers.
Most of this is not yours
Base Layer under ₹500 crore? Your entire obligation is three paragraphs.
- No VA or penetration testing
- No six-hour DAKSH clock
- No security operations centre
RBI/DoS/2026-27/461 · 3 layers
Level check
Answer a few questions, get your instrument, level, chapters and calendar. Shareable and printable.
4 levelsCo-operative banks
Pick a level and the page re-renders: chapters, governance, calendar, contract clauses.
ReferenceGlossary
The terms in the Directions and in procurement conversations, defined plainly.
What we have not done
Everything here was read from the regulator’s own notification. That rule earns its keep: circulating summaries put the NBFC Base Layer threshold at ₹2,500 crore where the notification says ₹500 crore, and count six Directions where there are 7.
Think we read something wrong? Tell us →- 7/7Directions read in fullThe rest carry their reference number only
- 0Products assessedEdition I's scores measured against a repealed framework and were deleted, not carried forward
- 0IRDAI & SEBI coverageThose notifications are unread, so we show the gap rather than fill it
Where software is the answer, and where it is not
8 of the 11 controls we have mapped are answered by software. We resell those, price them in INR with GST, and implement them. The other 3 are a service, a team and a contract negotiation — and we say so rather than selling you something that does not answer the question.
Reference numbers and chapter contents read from the RBI notifications on 2026-08-26 by Raj, LupusCreed. General information, not legal advice — confirm applicability and current status with your compliance function and counsel. Regional Rural Banks have no instrument under this title; the Outsourcing Directions 2025 and the Digital Payment Security Controls Directions 2026 are separate and were not absorbed.