Which RBI cybersecurity Direction binds you?

The Reserve Bank replaced the framework on 31 July 2026 — 628 circulars repealed, 7 Directions in their place. How much of yours applies depends on facts that are not in your balance sheet. Answer a few questions; the result lives in the address bar, so you can send it to a colleague.

  • Freeno email, no sign-up
  • ~2 mina handful of yes/no questions
  • 4UCB levels, set by digital depth
  • 3NBFC tiers, split at ₹500 crore
Step 1 · Your licence

Indicative only, and based on the published Directions as we read them. This is general information, not legal advice — confirm your classification with your compliance function and your counsel before you act on it. Every figure here is drawn from the RBI’s own notifications; if you think we have read one wrongly, tell us at info@thetechbag.com and we will correct it or explain why we disagree.

Questions people ask

Levels and layers, answered

Short answers, each backed by the sources on this page.

Can a co-operative bank move up a level without growing?

Yes. Levels follow digital depth and payment-system connections, not size. Becoming a direct member of the centralised payment systems, running your own ATM Switch or adding a SWIFT interface moves a UCB to Level III; hosting a data centre for, or supporting, other banks can make it Level IV.

What is the difference between a sub-member and a direct member?

A sub-member reaches the centralised payment systems indirectly, through a sponsor bank; a direct member connects itself. Sub-membership plus internet banking, a mobile banking app or direct CTS, IMPS or UPI membership is the Level II test; direct membership on its own is one of the Level III tests.

Which NBFCs fall in the smallest band?

Base Layer NBFCs with assets below ₹500 crore, and every Core Investment Company whatever its size. Three paragraphs, roughly two hundred words. Chapter III asks a small Base Layer NBFC to digitise and secure its primary business databases, to adopt a board-approved IT and information security policy covering nine basic standards, and to scale its systems up as the business grows.

Does the level check store my answers?

No. There is no form and no email: the answers live only in your browser's address bar, so you can copy the link to a colleague and it opens on the same result.

What if my institution is not regulated by the RBI?

SEBI-regulated entities fall under SEBI's CSCRF and insurers under IRDAI's 2026 guidelines — both are in the explorer. Whoever regulates you, the CERT-In Directions apply: within 6 hours of noticing or being brought to notice, to CERT-In — incident@cert-in.org.in.