Your RBI cybersecurity Direction, read whole

7 Directions, each for one licence class, in force since 31 July 2026. 5 are the same document with a different addressee; only the 2 for co-operative banks and NBFCs are graded. Pick yours below — the address bar keeps the answer, so it can go straight into a board pack.

  • 7RBI Directions, each for one licence
  • 5share one eight-chapter shape
  • 2graded — UCB levels, NBFC layers
  • 2non-RBI regimes: SEBI and IRDAI

Your instrument

Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

RBI/DoS/2026-27/437 · issued 2026-07-31 · in force on issuance

Read on rbi.org.in →

Primary (Urban) Co-operative Banks, graded into Levels I to IV by their digital depth and interconnectedness to the payment systems landscape (paragraph 4) — irrespective of asset size (paragraph 10).

Which level are you?

Set by the digital services you offer and how you connect to the payment system — not by asset size.

I
2 ch
II
3 ch
III
4 ch
IV
5 ch
Level ILevel IILevel IIILevel IV
Level I
Every UCB
Level II
Sub-member + UPI/IMPS/CTS or net banking
Level III
Direct member, own switch, or SWIFT
Level IV
Switch + SWIFT, or hosts its own DC

Pick your level above and the rest of this page fills in.

Read from the regulator’s own notification on 2026-10-05 by Raj, LupusCreed. General information, not legal advice — confirm applicability with your compliance function and counsel. Cost bands are indicative, not quotes. If we have read something wrongly, write to info@thetechbag.com.

Questions people ask

The Directions, answered

Short answers, each backed by the sources on this page.

Are the commercial, small finance and payments bank cybersecurity Directions different?

Barely. They — and the AIFI and CIC Directions — run the same eight chapters in the same order. The differences are few: only commercial banks have the foreign-bank comply-or-explain route, and AIFIs and CICs have no ATM Switch provider flow-down.

Which chapters of the NBFC cybersecurity Direction apply to my NBFC?

The NBFC Direction has 6 chapters, and its bands do not stack. Every NBFC takes Chapters I, II and VI; then Chapter III if it is in the Base Layer below ₹500 crore (or a CIC), Chapter IV if it is in the Base Layer at ₹500 crore or more, or Chapter V if it is in the Middle Layer or above.

Has the SEBI CSCRF compliance deadline passed?

Every CSCRF implementation deadline has passed. MIIs and QRTAs had to comply from 1 January 2025 (with forbearance to 31 March 2025) and KRAs from 1 April 2025; every other regulated entity by 31 August 2025, after two extensions (SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96). What recurs now is the cyber audit: from FY 2025-26 it follows CSCRF and runs on the financial year, starting after the period ends, with the report due within one month of completing the audit and findings closed within three months of submitting it.

What do IRDAI's 2026 cybersecurity guidelines require of insurers?

The IRDAI Information and Cyber Security Guidelines, 2026 grade insurers and intermediaries into three categories by gross insurance revenue. Incidents go to CERT-In within six hours with a copy to IRDAI; internet-facing systems get VA and PT every six months from a CERT-In empanelled auditor; the CISO must not report to the head of IT; and insurers file an annual assurance audit with IRDAI.

Where can I read the Directions themselves?

Every Direction in the explorer links to its own notification on rbi.org.in, with its reference number. All 7 were read in full, most recently on 5 October 2026.