# RBI cybersecurity Directions 2026 and BFSI compliance in India — the TechBag guide

> For Indian banks, urban co-operative banks, NBFCs, small finance and payments banks, all India financial institutions, credit information companies, SEBI-regulated entities and insurers. Every fact is read from the regulator's own notification and carries its verification date. Last reviewed 2026-10-05. General information, not legal advice.

Web version: https://www.thetechbag.com/industries/bfsi · Which Direction binds you (free check): https://www.thetechbag.com/industries/bfsi/level-check · Explorer by licence: https://www.thetechbag.com/industries/bfsi/explorer · Obligations: https://www.thetechbag.com/industries/bfsi/obligations · Glossary: https://www.thetechbag.com/industries/bfsi/glossary

## What changed on 31 July 2026

The Reserve Bank repealed 628 supervisory circulars — consolidated or obsolete — and issued 64 consolidated Directions. Seven of the 64 cover cybersecurity, each for one licence class; Local Area Banks, Regional Rural Banks, rural co-operative banks and asset reconstruction companies have none in this set. All took effect immediately: the Directions contain no transition period, phase-in or glide path.

- Repeal notification: DoS.CO.PPG.66/11.01.005/2026-27, issued 2026-07-31. Source: https://rbi.org.in/scripts/NotificationUser.aspx?Id=13663&Mode=0 (verified 2026-10-05).
- 628 circulars repealed; 64 Directions issued; 7 of them cover cybersecurity.

## The 7 cybersecurity Directions — each for one licence class

### Commercial Banks — RBI/DoS/2026-27/410

**Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Commercial Banks — banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, the corresponding new banks, and the State Bank of India (paragraph 3). Foreign banks operating in branch mode follow 'comply or explain' for Chapters II, III, IV and VII and selected paragraphs of Chapter V, subject to the RBI examining and accepting a reasonably justifiable explanation (paragraph 4).

Replaces: Cyber Security Framework in Banks (2016); Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023), as applicable to commercial banks.

Source: https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13643 (verified 2026-10-05).

### Small Finance Banks — RBI/DoS/2026-27/419

**Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Small Finance Banks. The Directions apply as a whole — unlike the UCB and NBFC instruments, there is no internal grading by size or by digital services.

Replaces: The existing directions, instructions and guidelines on cybersecurity and IT governance as applicable to Small Finance Banks (paragraph 229).

Source: https://www.rbi.org.in/scripts/NotificationUser.aspx?Id=13634 (verified 2026-10-05).

### Payments Banks — RBI/DoS/2026-27/428

**Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Payments Banks. The Directions apply as a whole — there is no internal grading.

Replaces: The existing directions, instructions and guidelines on cybersecurity and IT governance as applicable to Payments Banks (paragraph 229).

Source: https://www.rbi.org.in/scripts/NotificationUser.aspx?Id=13625&Mode=0 (verified 2026-10-05).

### Urban Co-operative Banks — RBI/DoS/2026-27/437

**Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Primary (Urban) Co-operative Banks, graded into Levels I to IV by their digital depth and interconnectedness to the payment systems landscape (paragraph 4) — irrespective of asset size (paragraph 10).

Replaces: Comprehensive Cyber Security Framework for Primary (Urban) Cooperative Banks (UCBs) – A Graded Approach (2019); Basic Cyber Security Framework for Primary (Urban) Cooperative Banks (UCBs) (2018).

Source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=13616&Mode=0 (verified 2026-10-05).

### All India Financial Institutions — RBI/DoS/2026-27/456

**Reserve Bank of India (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Export-Import Bank of India, NABARD, SIDBI, National Housing Bank and NaBFID, named individually in the notification (paragraph 3). No internal grading. This is the Direction most often missing from secondary summaries of the family.

Replaces: The existing directions, instructions and guidelines on cybersecurity and IT governance as applicable to All-India Financial Institutions (paragraph 224).

Source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=13597&Mode=0 (verified 2026-10-05).

### NBFCs — RBI/DoS/2026-27/461

**Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: All NBFCs registered with the RBI under the RBI Act 1934, the Factoring Regulation Act 2011 or the National Housing Bank Act 1987 — so housing finance companies and factors too (paragraph 3(1)). Chapters attach by scale-based layer and, within the Base Layer, by an asset-size test at ₹500 crore. Core Investment Companies are treated with the smallest Base Layer NBFCs.

Replaces: Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023), as applicable to NBFCs; Master Direction – Information Technology Framework for the NBFC Sector (2017).

Source: https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13592 (verified 2026-10-05).

### Credit Information Companies — RBI/DoS/2026-27/470

**Reserve Bank of India (Credit Information Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.** Issued 2026-07-31, in force on issuance.

Who it binds: Credit Information Companies as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005 (paragraph 3). No internal grading.

Replaces: The existing directions, instructions and guidelines on cybersecurity and IT governance as applicable to Credit Information Companies (paragraph 224).

Source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=13583&Mode=0 (verified 2026-10-05).

## Two shapes, not seven

5 of the 7 Directions (Commercial Banks, Small Finance Banks, Payments Banks, All India Financial Institutions, Credit Information Companies) are the same document with a different addressee — the same eight chapters in the same order, near-identical paragraph ranges. Understand one and you have understood 5. Only 2 are graded: the urban co-operative bank Direction (Levels I–IV) and the NBFC Direction (scale-based layers).

## Urban co-operative banks: the level is set by digital depth, not size

- **Level I.** Every UCB, whatever digital services it offers. There is no floor below this. Chapters: II — Role of the Board; III — Level I baseline requirements.
- **Level II.** A sub-member of Centralised Payment Systems (RTGS and NEFT) that ALSO does at least one of: offers internet banking (view or transaction based); offers mobile banking through an app; or is a direct member of CTS, IMPS or UPI. Both halves must be true. Chapters: II — Role of the Board; III — Level I baseline requirements; IV — Level II baseline requirements.
- **Level III.** Meets at least one of: direct membership of centralised payment systems; operates its own ATM Switch; or maintains a SWIFT interface. Chapters: II — Role of the Board; III — Level I baseline requirements; IV — Level II baseline requirements; V — Level III baseline requirements.
- **Level IV.** A direct or sub-member of Centralised Payment Systems that ALSO either has its own ATM Switch and a SWIFT interface, or hosts a data centre or provides software support to other banks — on its own or through wholly owned subsidiaries. Chapters: II — Role of the Board; III — Level I baseline requirements; IV — Level II baseline requirements; V — Level III baseline requirements; VI — Level IV baseline requirements.

Check your level: https://www.thetechbag.com/industries/bfsi/level-check?licence=ucb

### What each UCB chapter contains (sub-section headings, verbatim)

- **Chapter II — Role of the Board** (paragraphs 7–9; from Level I): A. Board Approved Policies; B. Committees of the Board (paragraphs 8–9 — Level IV).
- **Chapter III — Level I baseline cybersecurity and resilience requirements** (paragraphs 10–102; from Level I): A. Self-Assessment; B. Cybersecurity Policy; C. Information Technology Architecture; D. Cyber Crisis Management Plan; E. Role of the Board of Directors and Senior Management; F. Inventory Management of Information Assets; G. Protection of Customer / Payment Information; H. Cryptographic Controls; I. Preventing Access of Unauthorised Software; J. Environmental Controls; K. Network Management and Security; L. Secure Configuration; M. Anti-virus; N. Change and Patch Management; O. User Access Control / Management; P. Secure Mail and Messaging Systems; Q. Removable Media; R. User / Employee / Management / Board Awareness; S. Customer Education and Awareness; T. Backup and Restoration; U. Vendor / Outsourcing Risk Management; V. Cyber Incident Response and Recovery Management; W. Deployment of New Application / System; X. Information Systems Audit.
- **Chapter IV — Level II baseline cybersecurity and resilience requirements** (paragraphs 103–133; from Level II): A. Information Technology Resource Planning; B. Chief Information Security Officer or Equivalent Official; C. Network Management and Security; D. Secure Configuration; E. Application Security Life Cycle; F. Change and Patch Management; G. Periodic Testing; H. User Access Control / Management; I. Authentication Framework for Customers; J. Anti-Phishing; K. Data Leak Prevention Strategy; L. Database Integrity; M. Audit Logs; N. Incident Response and Management.
- **Chapter V — Level III baseline cybersecurity and resilience requirements** (paragraphs 134–158; from Level III): A. Network Management and Security; B. Secure Configuration; C. Application Security Life Cycle; D. User Access Control; E. Advanced Real-time Threat Defence and Management; F. Maintenance, Monitoring, and Analysis of Audit Logs; G. Incident Response and Management; H. User / Employee / Management Awareness; I. Risk-based Transaction Monitoring System (direct CPS members with own ATM Switch or SWIFT).
- **Chapter VI — Level IV baseline cybersecurity and resilience requirements** (paragraphs 159–179; from Level IV): A. Cyber Security Operations Centre; B. Participation in Cyber Drills; C. Incident Response and Management; D. Metrics; E. Forensics; F. Information Technology Strategy and Policy; G. Information Technology and Information Systems Governance Framework.

## NBFCs: the scale-based layers

- **Base Layer, under ₹500 crore (and all CICs).** An NBFC in the Base Layer with asset size below ₹500 crore. Core Investment Companies sit here too, whatever their size. Chapters: II — Role of the Board; III — Requirements for NBFCs (Base Layer with asset size below ₹500 crore) and Core Investment Companies.
- **Base Layer, ₹500 crore and above.** An NBFC in the Base Layer with asset size of ₹500 crore or more. Chapters: II — Role of the Board; IV — Requirements for NBFCs (Base Layer with asset size ₹500 crore and above).
- **Middle, Upper and Top Layer.** An NBFC in the Middle, Upper or Top Layer of the scale-based regulatory framework. Core Investment Companies are excluded from this band. Chapters: II — Role of the Board; V — Requirements for NBFCs (Middle Layer and above excluding CICs).

The NBFC Direction has six chapters, and its bands do not stack — each takes Chapters I, II and VI plus its own:

- Chapter I — Preliminary (paragraphs 1–5)
- Chapter II — Role of the Board (paragraphs 6)
- Chapter III — Requirements for NBFCs (Base Layer with asset size below ₹500 crore) and Core Investment Companies (paragraphs 7–9)
- Chapter IV — Requirements for NBFCs (Base Layer with asset size ₹500 crore and above) (paragraphs 10–64)
- Chapter V — Requirements for NBFCs (Middle Layer and above excluding CICs) (paragraphs 65–154)
- Chapter VI — Repeal and Other Provisions (paragraphs 155–158)

**The small-NBFC floor.** Three paragraphs, roughly two hundred words. Chapter III asks a small Base Layer NBFC to digitise and secure its primary business databases, to adopt a board-approved IT and information security policy covering nine basic standards, and to scale its systems up as the business grows. If your NBFC is in the Base Layer below ₹500 crore, most of what is written about the 2026 framework does not apply to you. Read Chapter II (the Board's annual review, paragraph 6) and Chapter III — which also pulls in paragraphs 31, 33 and 34 of Chapter IV.

- No periodic vulnerability assessment or penetration testing — those appear only in Chapter V (paragraph 121).
- No six-hour DAKSH incident reporting deadline — that appears in Chapters IV and V.
- No security operations centre — that appears only in Chapter V.

Its Board-approved IT and information security policy covers nine basic standards (paragraph 8):

- Physical and logical access controls, and a well-defined password policy
- Well-defined user roles
- Maker-checker, to reduce error and misuse
- Robust information security and cybersecurity controls
- Digital signature certificates, mobile financial services and social media (paragraphs 31, 33 and 34 of Chapter IV)
- System-generated reports for senior management on the financial position
- Adequacy to file regulatory returns with the RBI
- A Board-approved BCP policy, with reports to the Board at least once a year
- Data backups, with periodic testing

## Two six-hour clocks, not one

- **Report cyber incidents on DAKSH (and proactively notify CERT-In)** — Within 6 hours of detection. Recipient: Reserve Bank of India — daksh.rbi.org.in.
- **Report cyber incidents to CERT-In** — Within 6 hours of noticing or being brought to notice. Recipient: CERT-In — incident@cert-in.org.in. Basis: Directions under section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022.

Runs in parallel with the RBI's DAKSH clock. Same incident, same six hours, different recipient, different instrument. Filing on DAKSH does not discharge this.

## Recurring obligations — urban co-operative banks

| Obligation | How often | To whom | Levels | Note |
|---|---|---|---|---|
| Report cyber incidents on DAKSH | Within 6 hours of detection | Reserve Bank of India — daksh.rbi.org.in | I, II, III, IV | Paragraph 88. Paragraph 87 also requires proactively notifying CERT-In — and CERT-In's own six-hour clock (below) is separate. Filing on DAKSH does not discharge it. |
| Vulnerability assessment — critical applications and those on the DMZ | At least once every 6 months | Internal — findings tracked by the IS / IS Audit team and senior management (para 119) | II, III, IV | Paragraph 116. Attaches from Level II. |
| Penetration testing — internet-facing web and mobile applications, servers and network components | At least once a year | Internal — by professionally qualified teams (para 119) | II, III, IV | Paragraph 116. Attaches from Level II. |
| Application security testing of web and mobile applications | Before go-live, and after every major change | Internal — no filing to the RBI | II, III, IV | Paragraph 115. Event-driven rather than calendar-driven. |
| Test the BCP and DR plans | At periodic intervals | Internal — no filing to the RBI | II, III, IV | Paragraph 133, Chapter IV — attaches from Level II. The UCB Directions do not fix a period. (The NBFC Directions require half-yearly DR drills, but only for the Middle Layer and above.) |

## Recurring obligations — NBFCs

| Obligation | How often | To whom | Bands | Note |
|---|---|---|---|---|
| Report cyber incidents on DAKSH | Within 6 hours of detection | Reserve Bank of India — daksh.rbi.org.in (housing finance companies report to NHB) | base-large, middle-plus | Chapter IV paragraph 28 and Chapter V paragraph 141, which also requires proactively notifying CERT-In. Housing finance companies continue to report to NHB, not the RBI (note to paragraph 141). There is NO such obligation in Chapter III. |
| Vulnerability assessment — critical information systems and those in the DMZ with a customer interface | At least once every 6 months | Internal — no filing to the RBI | middle-plus | Paragraph 121, Chapter V. Not required of Base Layer NBFCs at any size. |
| Penetration testing — critical information systems and those in the DMZ with a customer interface | At least once every 12 months | Internal — by trained, independent experts or auditors (para 122) | middle-plus | Paragraph 121, Chapter V. |
| Disaster recovery drills for critical information systems | At least half-yearly | Internal — no filing to the RBI | middle-plus | Paragraph 129, Chapter V. Other systems as per the NBFC's own risk assessment. |
| Test the business continuity plan | At least annually, and whenever significant IT or business changes occur | Results to the CIO and the Board | base-large | Paragraph 59(4), Chapter IV — using worst-case scenarios. |
| Board review of technology and cybersecurity strategies and policies | At least annually | The Board | base-small, base-large, middle-plus | Paragraph 6, Chapter II — binds every NBFC, including the smallest. |
| Business continuity reports to the Board, and tested backups | At least once a year (BCP reports); backups tested periodically | The Board | base-small | Paragraph 8(8) and 8(9), Chapter III. |

## Recurring obligations — the common-shape Directions

| Obligation | How often | To whom |
|---|---|---|
| Report cyber incidents on DAKSH (and proactively notify CERT-In) | Within 6 hours of detection | Reserve Bank of India — daksh.rbi.org.in |
| Vulnerability assessment — critical systems and DMZ systems with a customer interface | At least once every 6 months | Internal — no filing to the RBI |
| Penetration testing — critical systems and DMZ systems with a customer interface | At least once every 12 months | Internal — no filing to the RBI |
| Disaster recovery drills — critical systems | At least half-yearly | Internal — no filing to the RBI |

## The 11 obligations, and what answers each

Derived from the chapter sub-sections of RBI/DoS/2026-27/437. 8 are answered by a category of software; 3 are not. Cost bands are indicative annual figures at Indian mid-market scale, not quotes. Web version with every card: https://www.thetechbag.com/industries/bfsi/obligations

### Information asset inventory (UCB Level I and above)

- **The obligation:** Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.
- **Where it comes from:** Chapter III §F — Inventory Management of Information Assets
- **What a supervisor expects to see:** The inventory itself, its classification scheme, and evidence that it is maintained rather than produced once for an audit.
- **What answers it:** DSPM & data discovery — https://www.thetechbag.com/browse/data-security-privacy/dspm
- **Indicative cost:** ₹3L–₹18L (200–1,000 endpoints, annual)
- **Product families:** IT asset management, Data discovery and classification
- Link: https://www.thetechbag.com/industries/bfsi/obligations#asset-inventory

### Anti-virus and endpoint protection (UCB Level I and above)

- **The obligation:** Protect endpoints against malware, and prevent unauthorised software from running on bank systems.
- **Where it comes from:** Chapter III §M — Anti-virus; Chapter III §I — Preventing Access of Unauthorised Software
- **What a supervisor expects to see:** Coverage across the estate, update currency, and how exceptions are approved and reviewed.
- **What answers it:** Endpoint protection — https://www.thetechbag.com/browse/security/endpoint-protection
- **Indicative cost:** ₹2L–₹15L (200–1,000 endpoints, annual)
- **Product families:** Endpoint protection (EPP), Endpoint detection and response (EDR), Application allow-listing
- Link: https://www.thetechbag.com/industries/bfsi/obligations#endpoint-protection

### Change and patch management (UCB Level I and above)

- **The obligation:** Identify, track, manage and monitor the status of security patches, configure systems securely, and control changes to production systems.
- **Where it comes from:** Chapter III §N — Change and Patch Management; Chapter IV §F — Change and Patch Management; Chapter III §L — Secure Configuration
- **What a supervisor expects to see:** Patch currency by system class, the change-approval trail, and how exceptions are tracked to closure.
- **What answers it:** RMM & patch — https://www.thetechbag.com/browse/endpoint-management/rmm-patch
- **Indicative cost:** ₹1.5L–₹12L (200–1,000 endpoints, annual)
- **Product families:** Patch management, Unified endpoint management (UEM), Configuration management
- Link: https://www.thetechbag.com/industries/bfsi/obligations#patch-management

### User access control and privileged access (UCB Level I and above)

- **The obligation:** Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.
- **Where it comes from:** Chapter III §O — User Access Control / Management; Chapter IV §H — User Access Control / Management; Chapter IV §I — Authentication Framework for Customers
- **What a supervisor expects to see:** The access review trail, how privileged sessions are recorded, and joiner-mover-leaver evidence.
- **What answers it:** Privileged access management — https://www.thetechbag.com/browse/identity-access/privileged-access-management
- **Indicative cost:** ₹5L–₹40L (by privileged account count, annual)
- **Product families:** Privileged access management (PAM), IAM, SSO and MFA
- Link: https://www.thetechbag.com/industries/bfsi/obligations#privileged-access

### Data leak prevention (UCB Level II and above)

- **The obligation:** Have a strategy — not merely a tool — for preventing sensitive business and customer data leaving the bank, with similar arrangements at vendor-managed facilities.
- **Where it comes from:** Chapter IV §K — Data Leak Prevention Strategy
- **What a supervisor expects to see:** The written strategy, what it classifies as sensitive, and evidence the controls fire and are acted on.
- **What answers it:** DLP & insider risk — https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk
- **Indicative cost:** ₹4L–₹30L (200–1,000 users, annual)
- **Product families:** DLP (endpoint, network, cloud), Insider risk, Rights management
- Link: https://www.thetechbag.com/industries/bfsi/obligations#data-loss-prevention

### Email security and anti-phishing (UCB Level I and above)

- **The obligation:** Secure mail and messaging from Level I; from Level II, subscribe to anti-phishing and anti-rogue-application services that take down sites and apps impersonating the bank.
- **Where it comes from:** Chapter III §P — Secure Mail and Messaging Systems; Chapter IV §J — Anti-Phishing
- **What a supervisor expects to see:** Mail authentication records, what is quarantined and why, and takedown arrangements for lookalike domains.
- **What answers it:** Email security — https://www.thetechbag.com/browse/security/email-security
- **Indicative cost:** ₹1L–₹10L (200–1,000 mailboxes, annual)
- **Product families:** Email security, Anti-phishing and brand protection, Security awareness training
- Link: https://www.thetechbag.com/industries/bfsi/obligations#email-security

### Backup, restoration and continuity (UCB Level I and above)

- **The obligation:** Back up what matters, including offline, and be able to restore it; prepare a cyber crisis management plan (the Directions point to the CERT-In and NCIIPC guidance). From Level II, test the BCP and DR plans at periodic intervals.
- **Where it comes from:** Chapter III §T — Backup and Restoration; Chapter III §D — Cyber Crisis Management Plan
- **What a supervisor expects to see:** Restore tests with dates and outcomes — not backup success reports, which prove only that data was written.
- **What answers it:** Backup & recovery — https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery
- **Indicative cost:** ₹3L–₹35L (by protected TB, annual)
- **Product families:** Backup and recovery, Immutable and air-gapped storage, Disaster recovery
- Link: https://www.thetechbag.com/industries/bfsi/obligations#business-continuity

### Audit logs and monitoring (UCB Level I and above)

- **The obligation:** Report every cyber incident on DAKSH within six hours of detection and notify CERT-In (Level I); from Level II, collect, protect and retain audit logs in line with business, regulatory and legal requirements. CERT-In's own Directions set its six-hour clock.
- **Where it comes from:** Chapter IV §M — Audit Logs; Chapter IV §N — Incident Response and Management; Chapter III §V — Cyber Incident Response and Recovery Management
- **What a supervisor expects to see:** The log retention policy and its basis, and a worked example of a real incident with its two filing timestamps.
- **What answers it:** SIEM & log management — https://www.thetechbag.com/browse/security/siem-log-management
- **Indicative cost:** ₹8L–₹90L (ingest-driven; the licence is the small number)
- **Product families:** SIEM and log management, MDR and SOC-as-a-service, Incident response
- Link: https://www.thetechbag.com/industries/bfsi/obligations#security-operations

### Vulnerability assessment and penetration testing (UCB Level II and above)

- **The obligation:** Vulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.
- **Where it comes from:** Chapter IV §G — Periodic Testing; Paragraph 116
- **What a supervisor expects to see:** The reports themselves, the testing team's qualifications, and the remediation trail.
- **Not a product.** The penetration test is a service, carried out by professionally qualified teams (paragraph 119). A scanning platform produces findings; it does not discharge the testing obligation. TechBag does not perform penetration testing and does not resell it — many banks use a CERT-In empanelled assessor, though the Directions do not require one.
- Link: https://www.thetechbag.com/industries/bfsi/obligations#vapt

### Information Systems Audit function (UCB Level I and above)

- **The obligation:** Constitute an IS Audit Cell as part of the Inspection and Audit Department, working to an IS audit policy the bank adopts, with reports placed before the Audit Committee of the Board.
- **Where it comes from:** Chapter III §X — Information Systems Audit; Paragraphs 94–102
- **What a supervisor expects to see:** The audit policy, the cell's composition and independence, and what happened to the last set of findings.
- **Not a product.** This is a team and a reporting line, not a tool. No software satisfies it. We mention it because it appears in the same chapter as controls that are products, and a buyer working down the chapter will otherwise look for something to purchase.
- Link: https://www.thetechbag.com/industries/bfsi/obligations#is-audit

### Vendor and outsourcing risk, and the contract flow-down (UCB Level I and above)

- **The obligation:** Where the ATM Switch is run by a third-party provider, write 12 named control areas into the contract (paragraph 83) and require the provider to meet 37 baseline controls (paragraph 85) — and manage vendor and outsourcing risk generally.
- **Where it comes from:** Chapter III §U — Vendor / Outsourcing Risk Management; Paragraphs 83, 85
- **What a supervisor expects to see:** The clauses in the executed agreements, and the correspondence where amendments were sought.
- **Not a product.** The obligation is a contract negotiation with your existing suppliers. Software can track the exercise; it cannot perform it, and buying a TPRM platform does not put a clause into an agreement your provider has not signed.
- Link: https://www.thetechbag.com/industries/bfsi/obligations#third-party-risk

## Your vendor contracts carry the controls

A UCB that manages its ATM Switch ecosystem through a third-party Application Service Provider must write named cybersecurity controls into that contract, and require the provider to meet 37 baseline controls — including where the provider runs other payment-system services. The duty rests on the bank: if the clauses are not in the agreement, it is the bank that is short, not the supplier.

- 12 controls at paragraph 83 — ATM Switch Application Service Providers.
- 37 controls at paragraph 85 — ATM Switch Application Service Providers, as baseline cybersecurity controls.

For the commercial, small finance and payments bank Directions: The named controls must be factored into the contract signed with the third-party Switch ASP, which must also meet 24 baseline controls, and the bank must share the RBI's instructions with it. The obligation sits on the bank: if the clause is not in the agreement, it is the bank that is short. 12 named controls plus 24 baseline controls. The AIFI and CIC Directions have no ATM Switch provider flow-down.

For NBFCs, by band:

- **base-small** (paragraphs —): Chapter III has no outsourcing or third-party provision. Your obligations here come only from the separate outsourcing Directions, where they apply.
- **base-large** (paragraphs 60–64): Before any outsourcing, assess its risks, contractual threats and regulatory obligations (paragraph 60). The contract must be a written agreement vetted by legal counsel and must provide for: Continuous monitoring and assessment of the service provider, so corrective action can be taken immediately; The provider's systems and procedures to protect the data and applications outsourced; Access to all books, records and information on the outsourced activity — including audit trails and logs of administrative activity; The NBFC's right to audit the provider, by internal or external auditors, and to obtain copies of any audit or review reports; Access for the RBI, or persons it authorises, to documents and records held by the provider.
- **middle-plus** (paragraphs 104–106, 117): Vendor risk assessment and controls proportionate to risk and materiality, for third-party arrangements outside the NBFC outsourcing Directions (paragraph 117) — to: Mitigate concentration risk; Eliminate or address any conflict of interests; Mitigate risks of a single point of failure; Comply with legal and regulatory requirements and standards that protect customer data; Provide high availability, for uninterrupted customer service; Manage supply-chain risks effectively; Enforce software maintenance and support through formal agreements; obtain source code for critical applications or put it in escrow; and get a vendor's written confirmation that an application is free of known vulnerabilities, malware and covert channels after every material change (paragraphs 104–106).

## Governance you must be able to evidence

- **A cybersecurity policy separate from the IT policy.** A cybersecurity policy approved by the Board or Administrator (paragraph 11), distinct from the bank's IT / information security policy (paragraph 12) — so cyber risk is addressed on its own terms, not as a chapter of the IT policy. (UCB Directions, paragraphs 11–12. Binds every level.)
- **Board approval of technology and cybersecurity strategy.** The Board approves the strategies and policies related to the technology and cybersecurity frameworks. Under the NBFC Directions it must also review them at least annually. (UCB Directions, paragraph 7 (every level); NBFC Directions, paragraph 6 (every NBFC).)
- **IT Strategy Committee — a composition test.** NBFCs in the Middle Layer and above: at least three directors, with 'substantial IT expertise' defined as a minimum of seven years managing information systems or leading technology and cybersecurity initiatives (paragraph 71) — the seven years is the test. Base Layer NBFCs of ₹500 crore and above have a lighter committee: an independent director as chair, the CIO and CTO as members, and no more than six months between meetings (paragraph 15). For UCBs the committee is optional at Level IV (paragraph 8: at least two directors, one a professional director), with at least one member of five years' standing (paragraph 173). (NBFC Directions, paragraphs 15 and 71; UCB Directions, paragraphs 8 and 173.)
- **CISO reporting line.** NBFCs in the Middle Layer and above: the CISO reports directly to the Executive Director or equivalent overseeing risk management (paragraph 82(6)), has no direct reporting relationship with the Head of IT and carries no business targets (paragraph 81); Base Layer NBFCs have no CISO requirement. UCBs: from Level II an official must be identified for the role, who need not carry the CISO title (paragraph 104); at Level IV the CISO reports to the top executive overseeing risk management, or in their absence the MD and CEO, with no direct reporting relationship with the CIO or CTO and no business targets (paragraph 175). (NBFC Directions, paragraphs 81–82; UCB Directions, paragraphs 104 and 175.)
- **Information Systems Audit function.** An IS Audit Cell as part of the Inspection and Audit Department (paragraph 94), working to an IS audit policy the bank adopts (paragraph 97), proportionate to its level of operations. Reports are placed before the Audit Committee of the Board and compliance is tracked (paragraph 100). (UCB Directions, paragraphs 94–102. Binds every level, including Level I.)
- **Cyber Security Operations Centre.** A CSOC providing real-time or near-real-time visibility of security posture, monitoring and escalating incidents, and running incident management and forensic analysis. For the bank itself this is a Level IV obligation — but a third-party ATM Switch provider must set up a CSOC at any level (paragraph 85(36)). (UCB Directions, Chapter VI, paragraphs 159–161 (Level IV); paragraph 85(36) for ATM Switch providers.)

## SEBI-regulated entities: CSCRF

SEBI's Cybersecurity and Cyber Resilience Framework, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, issued 2024-08-20. Source: https://www.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html (verified 2026-10-05).

**Categorisation.** The category of REs shall be decided at the beginning of the financial year based on the data of the previous financial year. Once the category of RE is decided, RE shall remain in the same category throughout the financial year irrespective of any changes in the parameters during the financial year. The category shall be validated by the respective reporting authority at the time of compliance submission.

**Where compliance stands.** Every CSCRF implementation deadline has passed. MIIs and QRTAs had to comply from 1 January 2025 (with forbearance to 31 March 2025) and KRAs from 1 April 2025; every other regulated entity by 31 August 2025, after two extensions (SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96). What recurs now is the cyber audit: from FY 2025-26 it follows CSCRF and runs on the financial year, starting after the period ends, with the report due within one month of completing the audit and findings closed within three months of submitting it.

**SEBI's own incident clock.** Report cyber incidents to SEBI at mkt_incidents@sebi.gov.in within 6 hours, and on the SEBI incident reporting portal (siportal.sebi.gov.in, FIRE format since August 2026) within 24 hours — alongside CERT-In's own six-hour clock.

**Cyber audit periodicity:**

- MIIs and Qualified REs: At least twice a year
- Mid-size and Small-size REs providing internet-based or algo trading: Twice a year
- Qualified Stock Brokers: Half-yearly, whatever their category
- All other REs: At least once a year
- Self-certification REs: Exempt from the periodic audit by a CERT-In empanelled auditor; submit a self-certification signed by the MD, CEO, Board, partners or proprietor

**Every CSCRF circular since August 2024:**

- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (2024-08-20) — The framework, with a glide path of 1 January 2025 and 1 April 2025. https://www.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 (2024-12-31) — Forbearance to 31 March 2025 for the 1 January requirements; KRAs and DPs moved to 1 April 2025; the data-localisation standard put in abeyance. https://www.sebi.gov.in/legal/circulars/dec-2024/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_90401.html
- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (2025-03-28) — Extended to 30 June 2025 for every RE except MIIs, KRAs and QRTAs. https://www.sebi.gov.in/legal/circulars/mar-2025/extension-towards-adoption-and-implementation-of-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93146.html
- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (2025-04-30) — Revised the categorisation thresholds (stock brokers, AIFs, DPs, IAs, KRAs); cyber audits from FY 2025-26 follow CSCRF. https://www.sebi.gov.in/legal/circulars/apr-2025/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93734.html
- CSCRF FAQs (2025-06-11) — Periodicities run on the financial year; the audit starts after the audit period ends; Qualified Stock Brokers audit half-yearly. https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96 (2025-06-30) — Extended to 31 August 2025 for every RE except MIIs, KRAs and QRTAs — the last compliance date. https://www.sebi.gov.in/legal/circulars/jun-2025/extension-towards-adoption-and-implementation-of-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_94902.html
- SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (2025-08-28) — Technical clarifications; portfolio managers and merchant bankers re-categorised; data localisation still in abeyance; no timeline change. https://www.sebi.gov.in/legal/circulars/aug-2025/technical-clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_96329.html
- HO/(449)2026-ITD-5_DIV1/I/19448/2026 (2026-08-24) — Incident reporting moved to the FSB's FIRE format on siportal.sebi.gov.in; the six-hour and 24-hour rule restated. https://www.sebi.gov.in/legal/circulars/aug-2026/alignment-of-sebi-s-cyber-incident-reporting-portal-with-fire-format_103915.html

| Entity | Measure | Self-certification | Small-size | Mid-size | Qualified | MII | Excluded |
|---|---|---|---|---|---|---|---|
| Alternative Investment Fund (AIF) and VCF managers | Sum of corpus of all AIFs, VCFs and their schemes managed by the manager | ₹3,000 crore and below | More than ₹3,000 crore and less than ₹10,000 crore | ₹10,000 crore and above | — | — | — |
| Stock broker | Total registered clients, and clientele trading volume a year — the higher category applies | More than 1,000 and up to 10,000 clients, or more than ₹1,000 and up to ₹10,000 crore volume | More than 10,000 and up to 1 lakh clients, or more than ₹10,000 and up to ₹1,00,000 crore volume | More than 1 lakh and up to 10 lakh clients, or more than ₹1,00,000 and up to ₹10,00,000 crore volume | More than 10 lakh clients, or more than ₹10,00,000 crore volume | — | Under 1,000 registered clients and under ₹1,000 crore clientele trading volume a year |
| Mutual Fund / Asset Management Company | Assets under management | — | Less than ₹10,000 crore | ₹10,000 crore and above but less than ₹1 lakh crore | ₹1 lakh crore and above | — | — |
| Portfolio Manager | Assets under management | ₹3,000 crore and below | More than ₹3,000 crore and less than ₹10,000 crore | ₹10,000 crore and above | — | — | — |
| Custodian | Assets under custody | — | Less than ₹1 lakh crore | ₹1 lakh crore and above but less than ₹10 lakh crore | ₹10 lakh crore and above | — | — |
| Depository Participant | Whether also a stock broker | — | — | — | DPs other than stock brokers — banks, NBFCs, mutual funds, RTAs, financial institutions, custodians, clearing corporations, public financial institutions, state finance corporations | — | — |
| Registrar and Share Transfer Agent (RTA) | Folios | — | 10,000 and above but less than 1 crore folios | 1 crore and above but less than 2 crore folios | — | Qualified RTAs (QRTAs) are treated as MIIs | Under 10,000 folios |
| Merchant Banker | Activity in the period | — | All active merchant bankers (any merchant banking activity in the relevant period) | — | — | — | Inactive merchant bankers |
| Investment Adviser / Research Analyst | Other SEBI registrations | — | — | — | — | — | Not registered with SEBI in any other capacity |
| KYC Registration Agency (KRA) | Assigned outright | — | — | — | All KRAs — re-categorised from MIIs to Qualified REs (CIR/2025/60) | — | — |
| Banker to an Issue / SCSB | Assigned outright | — | — | — | — | — | Submits a certificate of compliance with the RBI's cybersecurity guidelines instead |
| Credit Rating Agency | Assigned outright | All CRAs | — | — | — | — | — |
| Collective Investment Scheme | Assigned outright | All CIS | — | — | — | — | — |
| Debenture Trustee | Recent issuer activity | All remaining debenture trustees | — | — | — | — | Has not added a new issuer of listed debt as a client in the last three financial years |
| Foreign Portfolio Investor | — | — | — | — | — | — | Excluded from submission of compliance with CSCRF |
| Foreign Venture Capital Investor | — | — | — | — | — | — | Excluded from submission of compliance with CSCRF |
| REIT / InvIT | — | — | — | — | — | — | Excluded from submission of compliance with CSCRF |
| Qualified Depository Participant | — | — | — | — | — | — | Excluded from CSCRF compliance |
| Limited Purpose Clearing Corporation | — | — | — | — | — | — | Excluded from submission of compliance with CSCRF |

## Insurers and intermediaries: IRDAI

IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026), issued 2026-04-06. Source: https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-10-05).

IRDAI issued revised Information and Cyber Security Guidelines on 6 April 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026), revising the 2023 edition. They bind all insurers including foreign reinsurance branches, all insurance intermediaries — brokers, corporate agents, web aggregators, TPAs, IMFs, insurance repositories, corporate surveyors and others — and the Insurance Information Bureau, with compliance from the current financial year. Individual agents, micro-insurance agents, POSPs and individual surveyors are outside them, but insurers must make them follow a minimum framework.

**Categories, by gross insurance revenue:**

- Cat-1: ₹50 crore and above — and every intermediary using ISNP, and every web aggregator
- Cat-2: ₹5 crore and above, below ₹50 crore
- Cat-3: Below ₹5 crore — annual rather than six-monthly VAPT, and a shared SOC

**What it requires:**

- **Incident reporting** (§2.10, 3.6(3)): Report cyber incidents to CERT-In within 6 hours of noticing them, with a copy to IRDAI and other concerned regulators. There is no separate IRDAI clock.
- **CISO** (§1.6(1), §1.6(3)): A senior official designated CISO, appointed by the Board, reporting to the top executive overseeing risk or else the CEO — with no direct reporting line to the Head of IT and no business targets. The CISO runs a 24x7 SOC and convenes the ISRMC.
- **Committees** (§1.5(II), §1.6(1), §1.6(13)–(16)): The Information Security Risk Management Committee meets at least quarterly (it was twice a year) and assures the Board's Risk Management Committee quarterly; a new IT Steering Committee meets quarterly; one or more independent external experts sit on the RMC. The Board receives quarterly information-security inputs.
- **VA and PT** (§2.16, 3.5.1): VA and grey- or white-box PT of internet-facing systems every six months, and VAPT of critical internal systems at least yearly, by a CERT-In empanelled auditor. High-risk gaps closed within 30 days.
- **Annual audit** (§1.10, Annexures III–IV): An independent assurance audit every year. Insurers file the auditor's report, with the Board's comments, with IRDAI within 90 days of the year end or 30 days of the audit, whichever is earlier; intermediaries submit theirs to their insurers.
- **Logs** (§2.16, 3.1(12), (14)): ICT logs kept for a rolling 180 days within India, available to IRDAI, CERT-In, CSIRT-Fin and law enforcement.
- **Cloud and suppliers** (§2.19, §2.14): Cloud only from MeitY-empanelled providers with valid STQC audit status, under an NDA, with no vendor lock-in; a suspected breach notified within 4 hours. Vendors may not sub-outsource without prior written permission, and contracts carry a right to audit.

Read from the Guidelines (version 2.0, April 2026) on irdai.gov.in. The covering circular and Annexure A were read in full; in section 2 we read the passages on the areas above, not every line of all twenty-four domains.

## The dates

- **2022-04-28** — CERT-In six-hour reporting Directions (CERT-In). https://www.thetechbag.com/industries/bfsi#clocks
- **2024-08-20** — SEBI issues the CSCRF circular (SEBI). https://www.thetechbag.com/industries/bfsi/explorer?licence=sebi
- **2025-08-31** — CSCRF compliance deadline for every SEBI RE except MIIs, KRAs and QRTAs (SEBI). https://www.thetechbag.com/industries/bfsi/explorer?licence=sebi
- **2025-11-13** — DPDP Rules notified (DPDP). https://www.thetechbag.com/industries/it-ites/obligations#dpdp
- **2025-11-28** — RBI Managing Risks in Outsourcing Directions (RBI). https://www.thetechbag.com/industries/it-ites/obligations#rbi-outsourcing
- **2026-04-06** — IRDAI issues revised Information and Cyber Security Guidelines (IRDAI). https://www.thetechbag.com/industries/bfsi/explorer?licence=irdai
- **2026-04-10** — Existing outsourcing contracts must comply (RBI). https://www.thetechbag.com/industries/it-ites/obligations#rbi-outsourcing
- **2026-07-31** — 628 circulars repealed; 7 cybersecurity Directions in force (RBI). https://www.thetechbag.com/industries/bfsi#reset
- **2026-08-24** — SEBI incident reporting moves to the FIRE format (SEBI). https://www.thetechbag.com/industries/bfsi/explorer?licence=sebi
- **2026-11-13** — DPDP Consent Managers begin (DPDP). https://www.thetechbag.com/industries/it-ites/obligations#dpdp
- **2027-05-13** — DPDP operational duties apply (DPDP). https://www.thetechbag.com/industries/it-ites/obligations#dpdp

## Frequently asked questions

### What changed for Indian financial institutions on 31 July 2026?

The Reserve Bank repealed 628 supervisory circulars — consolidated or obsolete — and issued 64 consolidated Directions. Seven of the 64 cover cybersecurity, each for one licence class; Local Area Banks, Regional Rural Banks, rural co-operative banks and asset reconstruction companies have none in this set. All took effect immediately: the Directions contain no transition period, phase-in or glide path.

### How many cybersecurity Directions did the RBI issue?

7, each for one licence class, all in force on issuance. Secondary summaries often count six, omitting the All India Financial Institutions Direction. Local Area Banks, Regional Rural Banks, rural co-operative banks and asset reconstruction companies have none in this set.

### How is a co-operative bank's level decided?

By its digital depth and how it connects to the payment systems — not by asset size. A small bank that is a sub-member of the centralised payment systems and offers internet or mobile banking, or is a direct member of CTS, IMPS or UPI, sits at Level II or above.

### Do small NBFCs need a security operations centre?

No. Three paragraphs, roughly two hundred words. Chapter III asks a small Base Layer NBFC to digitise and secure its primary business databases, to adopt a board-approved IT and information security policy covering nine basic standards, and to scale its systems up as the business grows. No periodic vulnerability assessment or penetration testing — those appear only in Chapter V (paragraph 121). No six-hour DAKSH incident reporting deadline — that appears in Chapters IV and V. No security operations centre — that appears only in Chapter V.

### Does reporting an incident to the RBI on DAKSH also satisfy CERT-In?

No. The RBI wants the incident on DAKSH within six hours of detection. CERT-In wants it within six hours too, under Directions under section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022. Runs in parallel with the RBI's DAKSH clock. Same incident, same six hours, different recipient, different instrument. Filing on DAKSH does not discharge this.

### If our IT vendor detects the incident first, when does our six-hour RBI clock start?

At the vendor's detection. The RBI's Managing Risks in Outsourcing Directions 2025 (paragraph 56 of the commercial-bank version) require the service provider to report to the bank without undue delay, so that the bank can report to the RBI within six hours of detection by the service provider.

### When is the SEBI CSCRF compliance deadline?

Every CSCRF implementation deadline has passed. MIIs and QRTAs had to comply from 1 January 2025 (with forbearance to 31 March 2025) and KRAs from 1 April 2025; every other regulated entity by 31 August 2025, after two extensions (SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96). What recurs now is the cyber audit: from FY 2025-26 it follows CSCRF and runs on the financial year, starting after the period ends, with the report due within one month of completing the audit and findings closed within three months of submitting it.

### Which IRDAI cybersecurity guidelines apply now?

The IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026), issued on 6 April 2026, revising the 2023 edition and applying from the current financial year. Insurers and intermediaries are graded into three categories by gross insurance revenue. Incidents go to CERT-In within six hours with a copy to IRDAI; internet-facing systems get VA and PT every six months from a CERT-In empanelled auditor; and insurers file an annual assurance audit with IRDAI.

## Questions about the obligations

### What must every urban co-operative bank do, whatever its level?

Everything in Chapter III of the UCB Direction — 24 sub-sections from self-assessment and a separate cybersecurity policy to backup, vendor risk, incident response and an IS audit function — plus the Board's approval of technology and cybersecurity policy in Chapter II. Incidents go on DAKSH within six hours of detection at every level.

### How many controls must a UCB's ATM Switch provider meet?

Where a UCB runs its ATM Switch through a third-party Application Service Provider, 12 named control areas go into the contract (paragraph 83) and the provider must meet 37 baseline controls (paragraph 85). Commercial, small finance and payments banks carry 12 plus 24; AIFIs and CICs have no such provision.

### Which RBI cybersecurity obligations can't be met by buying software?

Vulnerability assessment and penetration testing, Information Systems Audit function, Vendor and outsourcing risk, and the contract flow-down. Penetration testing is a service, the IS Audit function is a team, and the contract flow-down is a negotiation with providers you already have.

### How often must a bank run vulnerability assessments and penetration tests?

Under the 2026 Directions, vulnerability assessment of critical and DMZ-facing systems at least every six months and penetration testing at least once a year — from Level II for a UCB, for the Middle Layer and above for an NBFC, and for every commercial, small finance and payments bank, AIFI and CIC.

### Must NBFCs write security clauses into vendor contracts?

It depends on the band. Base Layer NBFCs of ₹500 crore and above must write monitoring, data-protection, audit and RBI-access rights into outsourcing contracts (paragraph 62). The Middle Layer and above must run vendor-risk controls proportionate to risk (paragraph 117) and obtain source code or escrow for critical applications. The smallest band has no outsourcing provision.

## Questions about the Directions

### Are the commercial, small finance and payments bank cybersecurity Directions different?

Barely. They — and the AIFI and CIC Directions — run the same eight chapters in the same order. The differences are few: only commercial banks have the foreign-bank comply-or-explain route, and AIFIs and CICs have no ATM Switch provider flow-down.

### Which chapters of the NBFC cybersecurity Direction apply to my NBFC?

The NBFC Direction has 6 chapters, and its bands do not stack. Every NBFC takes Chapters I, II and VI; then Chapter III if it is in the Base Layer below ₹500 crore (or a CIC), Chapter IV if it is in the Base Layer at ₹500 crore or more, or Chapter V if it is in the Middle Layer or above.

### Has the SEBI CSCRF compliance deadline passed?

Every CSCRF implementation deadline has passed. MIIs and QRTAs had to comply from 1 January 2025 (with forbearance to 31 March 2025) and KRAs from 1 April 2025; every other regulated entity by 31 August 2025, after two extensions (SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96). What recurs now is the cyber audit: from FY 2025-26 it follows CSCRF and runs on the financial year, starting after the period ends, with the report due within one month of completing the audit and findings closed within three months of submitting it.

### What do IRDAI's 2026 cybersecurity guidelines require of insurers?

The IRDAI Information and Cyber Security Guidelines, 2026 grade insurers and intermediaries into three categories by gross insurance revenue. Incidents go to CERT-In within six hours with a copy to IRDAI; internet-facing systems get VA and PT every six months from a CERT-In empanelled auditor; the CISO must not report to the head of IT; and insurers file an annual assurance audit with IRDAI.

### Where can I read the Directions themselves?

Every Direction in the explorer links to its own notification on rbi.org.in, with its reference number. All 7 were read in full, most recently on 5 October 2026.

## Questions about levels and layers

### Can a co-operative bank move up a level without growing?

Yes. Levels follow digital depth and payment-system connections, not size. Becoming a direct member of the centralised payment systems, running your own ATM Switch or adding a SWIFT interface moves a UCB to Level III; hosting a data centre for, or supporting, other banks can make it Level IV.

### What is the difference between a sub-member and a direct member?

A sub-member reaches the centralised payment systems indirectly, through a sponsor bank; a direct member connects itself. Sub-membership plus internet banking, a mobile banking app or direct CTS, IMPS or UPI membership is the Level II test; direct membership on its own is one of the Level III tests.

### Which NBFCs fall in the smallest band?

Base Layer NBFCs with assets below ₹500 crore, and every Core Investment Company whatever its size. Three paragraphs, roughly two hundred words. Chapter III asks a small Base Layer NBFC to digitise and secure its primary business databases, to adopt a board-approved IT and information security policy covering nine basic standards, and to scale its systems up as the business grows.

### Does the level check store my answers?

No. There is no form and no email: the answers live only in your browser's address bar, so you can copy the link to a colleague and it opens on the same result.

### What if my institution is not regulated by the RBI?

SEBI-regulated entities fall under SEBI's CSCRF and insurers under IRDAI's 2026 guidelines — both are in the explorer. Whoever regulates you, the CERT-In Directions apply: within 6 hours of noticing or being brought to notice, to CERT-In — incident@cert-in.org.in.

## Terms people ask about

### What does “DAKSH” mean?

The Reserve Bank's Advanced Supervisory Monitoring System, at daksh.rbi.org.in, through which regulated entities file cyber incident reports. Cyber incidents must be reported on DAKSH within six hours of detection. This does not discharge the separate CERT-In obligation, which runs on its own six-hour clock to a different recipient.

### What does “CSOC” mean?

Cyber Security Operations Centre — round-the-clock monitoring, detection, escalation and forensic analysis of security events. The same words mean very different things depending on your instrument. Under the common eight-chapter shape the CSOC is its own chapter binding every entity. Under the UCB Direction it is a Level IV obligation only — Levels I to III do not owe one.

### What does “Contract Flow-Down” mean?

The requirement to impose named cybersecurity controls on a service provider through the contract itself. For a UCB with a third-party ATM Switch this is 12 control areas at paragraph 83 plus 37 baseline controls at paragraph 85; for commercial, small finance and payments banks it is 12 plus 24. The AIFI and CIC Directions have no such provision. The most under-covered obligation in the family, and the one most likely to be forwarded inside a bank. It sits in Chapter III, so it binds every UCB from Level I that outsources its switch — and existing switch contracts almost certainly do not carry these clauses. If the clause is not in the agreement, it is the bank that is short, not the provider.

### What does “UCB Level” mean?

The four-level grading in the UCB Direction. Level I binds every UCB; Level II adds Chapter IV; Level III adds Chapter V; Level IV adds Chapter VI. Higher levels carry everything beneath them. Graded by digital services and payment-system interconnectedness, NOT by asset size. This is counter-intuitive and it is the single fact most small banks get wrong about their own obligations.

### What does “Base Layer” mean?

The lowest layer of the scale-based framework for NBFCs. The 2026 Direction splits it at ₹500 crore of assets: below that a Base Layer NBFC gets Chapter III, at or above it gets Chapter IV. ₹500 crore, not ₹2,500 crore — a widely syndicated summary reports the higher figure, a five-fold error that would put a whole band of NBFCs in the wrong chapter. A Base Layer NBFC under ₹500 crore owes Chapter III's three paragraphs, the Board's annual review in Chapter II, and three paragraphs of Chapter IV it pulls in — but no VA or PT, no six-hour DAKSH clock and no security operations centre.

### What does “Qualified RE” mean?

The second-highest CSCRF band. There is no single threshold: each entity type is graded on its own measure — a stock broker above 10 lakh registered clients or ₹10,00,000 crore of yearly clientele volume, a mutual fund at ₹1 lakh crore of AUM, a custodian at ₹10 lakh crore of assets under custody. KRAs are Qualified REs outright. The '10 lakh clients' figure is the stock-broker test since SEBI's April 2025 revision — not a universal threshold. AIF and portfolio-manager bands have no Qualified tier at all.

---

Published by TechBag (https://www.thetechbag.com). If we have read something wrongly, write to info@thetechbag.com. Generated from the data that renders https://www.thetechbag.com/industries/bfsi.
