The 11 RBI cybersecurity obligations, and what answers each

Derived from the chapter sub-sections of RBI/DoS/2026-27/437, so you can check the mapping against the notification rather than take it on trust. Each links to the guide that does the shortlisting, with an indicative India cost band.

  • 11obligations, mapped to chapters
  • 8answered by software
  • 3no software answers
  • I–IVUCB levels they attach at
The matrix

What binds at each level

Information asset inventory

UCB Level I+

Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.

₹3L–₹18L

The obligation

Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.

Where it comes from

  • Chapter III §F — Inventory Management of Information Assets

What a supervisor expects to see

The inventory itself, its classification scheme, and evidence that it is maintained rather than produced once for an audit.

What answers it

DSPM & data discovery →₹3L–₹18L 200–1,000 endpoints, annual

Product families: IT asset management · Data discovery and classification. Cost is indicative, not a quote — the guide carries per-product pricing.

Anti-virus and endpoint protection

UCB Level I+

Protect endpoints against malware, and prevent unauthorised software from running on bank systems.

₹2L–₹15L

The obligation

Protect endpoints against malware, and prevent unauthorised software from running on bank systems.

Where it comes from

  • Chapter III §M — Anti-virus
  • Chapter III §I — Preventing Access of Unauthorised Software

What a supervisor expects to see

Coverage across the estate, update currency, and how exceptions are approved and reviewed.

What answers it

Endpoint protection →₹2L–₹15L 200–1,000 endpoints, annual

Product families: Endpoint protection (EPP) · Endpoint detection and response (EDR) · Application allow-listing. Cost is indicative, not a quote — the guide carries per-product pricing.

Change and patch management

UCB Level I+

Identify, track, manage and monitor the status of security patches, configure systems securely, and control changes to production systems.

₹1.5L–₹12L

The obligation

Identify, track, manage and monitor the status of security patches, configure systems securely, and control changes to production systems.

Where it comes from

  • Chapter III §N — Change and Patch Management
  • Chapter IV §F — Change and Patch Management
  • Chapter III §L — Secure Configuration

What a supervisor expects to see

Patch currency by system class, the change-approval trail, and how exceptions are tracked to closure.

What answers it

RMM & patch →₹1.5L–₹12L 200–1,000 endpoints, annual

Product families: Patch management · Unified endpoint management (UEM) · Configuration management. Cost is indicative, not a quote — the guide carries per-product pricing.

User access control and privileged access

UCB Level I+

Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.

₹5L–₹40L

The obligation

Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.

Where it comes from

  • Chapter III §O — User Access Control / Management
  • Chapter IV §H — User Access Control / Management
  • Chapter IV §I — Authentication Framework for Customers

What a supervisor expects to see

The access review trail, how privileged sessions are recorded, and joiner-mover-leaver evidence.

What answers it

Privileged access management →₹5L–₹40L by privileged account count, annual

Product families: Privileged access management (PAM) · IAM, SSO and MFA. Cost is indicative, not a quote — the guide carries per-product pricing.

Data leak prevention

UCB Level II+

Have a strategy — not merely a tool — for preventing sensitive business and customer data leaving the bank, with similar arrangements at vendor-managed facilities.

₹4L–₹30L

The obligation

Have a strategy — not merely a tool — for preventing sensitive business and customer data leaving the bank, with similar arrangements at vendor-managed facilities.

Where it comes from

  • Chapter IV §K — Data Leak Prevention Strategy

What a supervisor expects to see

The written strategy, what it classifies as sensitive, and evidence the controls fire and are acted on.

What answers it

DLP & insider risk →₹4L–₹30L 200–1,000 users, annual

Product families: DLP (endpoint, network, cloud) · Insider risk · Rights management. Cost is indicative, not a quote — the guide carries per-product pricing.

Email security and anti-phishing

UCB Level I+

Secure mail and messaging from Level I; from Level II, subscribe to anti-phishing and anti-rogue-application services that take down sites and apps impersonating the bank.

₹1L–₹10L

The obligation

Secure mail and messaging from Level I; from Level II, subscribe to anti-phishing and anti-rogue-application services that take down sites and apps impersonating the bank.

Where it comes from

  • Chapter III §P — Secure Mail and Messaging Systems
  • Chapter IV §J — Anti-Phishing

What a supervisor expects to see

Mail authentication records, what is quarantined and why, and takedown arrangements for lookalike domains.

What answers it

Email security →₹1L–₹10L 200–1,000 mailboxes, annual

Product families: Email security · Anti-phishing and brand protection · Security awareness training. Cost is indicative, not a quote — the guide carries per-product pricing.

Backup, restoration and continuity

UCB Level I+

Back up what matters, including offline, and be able to restore it; prepare a cyber crisis management plan (the Directions point to the CERT-In and NCIIPC guidance). From Level II, test the BCP and DR plans at periodic intervals.

₹3L–₹35L

The obligation

Back up what matters, including offline, and be able to restore it; prepare a cyber crisis management plan (the Directions point to the CERT-In and NCIIPC guidance). From Level II, test the BCP and DR plans at periodic intervals.

Where it comes from

  • Chapter III §T — Backup and Restoration
  • Chapter III §D — Cyber Crisis Management Plan

What a supervisor expects to see

Restore tests with dates and outcomes — not backup success reports, which prove only that data was written.

What answers it

Backup & recovery →₹3L–₹35L by protected TB, annual

Product families: Backup and recovery · Immutable and air-gapped storage · Disaster recovery. Cost is indicative, not a quote — the guide carries per-product pricing.

Audit logs and monitoring

UCB Level I+

Report every cyber incident on DAKSH within six hours of detection and notify CERT-In (Level I); from Level II, collect, protect and retain audit logs in line with business, regulatory and legal requirements. CERT-In's own Directions set its six-hour clock.

₹8L–₹90L

The obligation

Report every cyber incident on DAKSH within six hours of detection and notify CERT-In (Level I); from Level II, collect, protect and retain audit logs in line with business, regulatory and legal requirements. CERT-In's own Directions set its six-hour clock.

Where it comes from

  • Chapter IV §M — Audit Logs
  • Chapter IV §N — Incident Response and Management
  • Chapter III §V — Cyber Incident Response and Recovery Management

What a supervisor expects to see

The log retention policy and its basis, and a worked example of a real incident with its two filing timestamps.

What answers it

SIEM & log management →₹8L–₹90L ingest-driven; the licence is the small number

Product families: SIEM and log management · MDR and SOC-as-a-service · Incident response. Cost is indicative, not a quote — the guide carries per-product pricing.

Vulnerability assessment and penetration testing

UCB Level II+Not a product

Vulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.

The obligation

Vulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.

Where it comes from

  • Chapter IV §G — Periodic Testing
  • Paragraph 116

What a supervisor expects to see

The reports themselves, the testing team's qualifications, and the remediation trail.

Why software does not answer this

The penetration test is a service, carried out by professionally qualified teams (paragraph 119). A scanning platform produces findings; it does not discharge the testing obligation. TechBag does not perform penetration testing and does not resell it — many banks use a CERT-In empanelled assessor, though the Directions do not require one.

Information Systems Audit function

UCB Level I+Not a product

Constitute an IS Audit Cell as part of the Inspection and Audit Department, working to an IS audit policy the bank adopts, with reports placed before the Audit Committee of the Board.

The obligation

Constitute an IS Audit Cell as part of the Inspection and Audit Department, working to an IS audit policy the bank adopts, with reports placed before the Audit Committee of the Board.

Where it comes from

  • Chapter III §X — Information Systems Audit
  • Paragraphs 94–102

What a supervisor expects to see

The audit policy, the cell's composition and independence, and what happened to the last set of findings.

Why software does not answer this

This is a team and a reporting line, not a tool. No software satisfies it. We mention it because it appears in the same chapter as controls that are products, and a buyer working down the chapter will otherwise look for something to purchase.

Vendor and outsourcing risk, and the contract flow-down

UCB Level I+Not a product

Where the ATM Switch is run by a third-party provider, write 12 named control areas into the contract (paragraph 83) and require the provider to meet 37 baseline controls (paragraph 85) — and manage vendor and outsourcing risk generally.

The obligation

Where the ATM Switch is run by a third-party provider, write 12 named control areas into the contract (paragraph 83) and require the provider to meet 37 baseline controls (paragraph 85) — and manage vendor and outsourcing risk generally.

Where it comes from

  • Chapter III §U — Vendor / Outsourcing Risk Management
  • Paragraphs 83, 85

What a supervisor expects to see

The clauses in the executed agreements, and the correspondence where amendments were sought.

Why software does not answer this

The obligation is a contract negotiation with your existing suppliers. Software can track the exercise; it cannot perform it, and buying a TPRM platform does not put a clause into an agreement your provider has not signed.

Sub-section references read from the RBI notification on 2026-10-05 by Raj, LupusCreed. General information, not legal advice. Cost bands are indicative annual figures at Indian mid-market scale, not quotes. If we have read something wrongly, write to info@thetechbag.com.

Questions people ask

RBI cybersecurity obligations, answered

Short answers, each backed by the sources on this page.

What must every urban co-operative bank do, whatever its level?

Everything in Chapter III of the UCB Direction — 24 sub-sections from self-assessment and a separate cybersecurity policy to backup, vendor risk, incident response and an IS audit function — plus the Board's approval of technology and cybersecurity policy in Chapter II. Incidents go on DAKSH within six hours of detection at every level.

How many controls must a UCB's ATM Switch provider meet?

Where a UCB runs its ATM Switch through a third-party Application Service Provider, 12 named control areas go into the contract (paragraph 83) and the provider must meet 37 baseline controls (paragraph 85). Commercial, small finance and payments banks carry 12 plus 24; AIFIs and CICs have no such provision.

Which RBI cybersecurity obligations can't be met by buying software?

Vulnerability assessment and penetration testing, Information Systems Audit function, Vendor and outsourcing risk, and the contract flow-down. Penetration testing is a service, the IS Audit function is a team, and the contract flow-down is a negotiation with providers you already have.

How often must a bank run vulnerability assessments and penetration tests?

Under the 2026 Directions, vulnerability assessment of critical and DMZ-facing systems at least every six months and penetration testing at least once a year — from Level II for a UCB, for the Middle Layer and above for an NBFC, and for every commercial, small finance and payments bank, AIFI and CIC.

Must NBFCs write security clauses into vendor contracts?

It depends on the band. Base Layer NBFCs of ₹500 crore and above must write monitoring, data-protection, audit and RBI-access rights into outsourcing contracts (paragraph 62). The Middle Layer and above must run vendor-risk controls proportionate to risk (paragraph 117) and obtain source code or escrow for critical applications. The smallest band has no outsourcing provision.