The 11 RBI cybersecurity obligations, and what answers each
Derived from the chapter sub-sections of RBI/DoS/2026-27/437, so you can check the mapping against the notification rather than take it on trust. Each links to the guide that does the shortlisting, with an indicative India cost band.
- 11obligations, mapped to chapters
- 8answered by software
- 3no software answers
- I–IVUCB levels they attach at
What binds at each level
- Information asset inventory
- Anti-virus and endpoint protection
- Change and patch management
- User access control and privileged access
- Data leak prevention
- Email security and anti-phishing
- Backup, restoration and continuity
- Audit logs and monitoring
- Vulnerability assessment and penetration testingNot a product
- Information Systems Audit functionNot a product
- Vendor and outsourcing risk, and the contract flow-downNot a product
Filled: binds at that level. Red: binds, but no software answers it. Mapped from the chapter sub-sections of the UCB Direction; the other licence classes apply as a whole or by layer.
Information asset inventory
UCB Level I+Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.
₹3L–₹18L
Information asset inventory
UCB Level I+Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.
₹3L–₹18L
The obligation
Where it comes from
- Chapter III §F — Inventory Management of Information Assets
What a supervisor expects to see
What answers it
Product families: IT asset management · Data discovery and classification. Cost is indicative, not a quote — the guide carries per-product pricing.
Anti-virus and endpoint protection
UCB Level I+Protect endpoints against malware, and prevent unauthorised software from running on bank systems.
₹2L–₹15L
Anti-virus and endpoint protection
UCB Level I+Protect endpoints against malware, and prevent unauthorised software from running on bank systems.
₹2L–₹15L
The obligation
Where it comes from
- Chapter III §M — Anti-virus
- Chapter III §I — Preventing Access of Unauthorised Software
What a supervisor expects to see
What answers it
Product families: Endpoint protection (EPP) · Endpoint detection and response (EDR) · Application allow-listing. Cost is indicative, not a quote — the guide carries per-product pricing.
Change and patch management
UCB Level I+Identify, track, manage and monitor the status of security patches, configure systems securely, and control changes to production systems.
₹1.5L–₹12L
Change and patch management
UCB Level I+Identify, track, manage and monitor the status of security patches, configure systems securely, and control changes to production systems.
₹1.5L–₹12L
The obligation
Where it comes from
- Chapter III §N — Change and Patch Management
- Chapter IV §F — Change and Patch Management
- Chapter III §L — Secure Configuration
What a supervisor expects to see
What answers it
Product families: Patch management · Unified endpoint management (UEM) · Configuration management. Cost is indicative, not a quote — the guide carries per-product pricing.
User access control and privileged access
UCB Level I+Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.
₹5L–₹40L
User access control and privileged access
UCB Level I+Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.
₹5L–₹40L
The obligation
Where it comes from
- Chapter III §O — User Access Control / Management
- Chapter IV §H — User Access Control / Management
- Chapter IV §I — Authentication Framework for Customers
What a supervisor expects to see
What answers it
Product families: Privileged access management (PAM) · IAM, SSO and MFA. Cost is indicative, not a quote — the guide carries per-product pricing.
Data leak prevention
UCB Level II+Have a strategy — not merely a tool — for preventing sensitive business and customer data leaving the bank, with similar arrangements at vendor-managed facilities.
₹4L–₹30L
Data leak prevention
UCB Level II+Have a strategy — not merely a tool — for preventing sensitive business and customer data leaving the bank, with similar arrangements at vendor-managed facilities.
₹4L–₹30L
The obligation
Where it comes from
- Chapter IV §K — Data Leak Prevention Strategy
What a supervisor expects to see
What answers it
Product families: DLP (endpoint, network, cloud) · Insider risk · Rights management. Cost is indicative, not a quote — the guide carries per-product pricing.
Email security and anti-phishing
UCB Level I+Secure mail and messaging from Level I; from Level II, subscribe to anti-phishing and anti-rogue-application services that take down sites and apps impersonating the bank.
₹1L–₹10L
Email security and anti-phishing
UCB Level I+Secure mail and messaging from Level I; from Level II, subscribe to anti-phishing and anti-rogue-application services that take down sites and apps impersonating the bank.
₹1L–₹10L
The obligation
Where it comes from
- Chapter III §P — Secure Mail and Messaging Systems
- Chapter IV §J — Anti-Phishing
What a supervisor expects to see
What answers it
Product families: Email security · Anti-phishing and brand protection · Security awareness training. Cost is indicative, not a quote — the guide carries per-product pricing.
Backup, restoration and continuity
UCB Level I+Back up what matters, including offline, and be able to restore it; prepare a cyber crisis management plan (the Directions point to the CERT-In and NCIIPC guidance). From Level II, test the BCP and DR plans at periodic intervals.
₹3L–₹35L
Backup, restoration and continuity
UCB Level I+Back up what matters, including offline, and be able to restore it; prepare a cyber crisis management plan (the Directions point to the CERT-In and NCIIPC guidance). From Level II, test the BCP and DR plans at periodic intervals.
₹3L–₹35L
The obligation
Where it comes from
- Chapter III §T — Backup and Restoration
- Chapter III §D — Cyber Crisis Management Plan
What a supervisor expects to see
What answers it
Product families: Backup and recovery · Immutable and air-gapped storage · Disaster recovery. Cost is indicative, not a quote — the guide carries per-product pricing.
Audit logs and monitoring
UCB Level I+Report every cyber incident on DAKSH within six hours of detection and notify CERT-In (Level I); from Level II, collect, protect and retain audit logs in line with business, regulatory and legal requirements. CERT-In's own Directions set its six-hour clock.
₹8L–₹90L
Audit logs and monitoring
UCB Level I+Report every cyber incident on DAKSH within six hours of detection and notify CERT-In (Level I); from Level II, collect, protect and retain audit logs in line with business, regulatory and legal requirements. CERT-In's own Directions set its six-hour clock.
₹8L–₹90L
The obligation
Where it comes from
- Chapter IV §M — Audit Logs
- Chapter IV §N — Incident Response and Management
- Chapter III §V — Cyber Incident Response and Recovery Management
What a supervisor expects to see
What answers it
Product families: SIEM and log management · MDR and SOC-as-a-service · Incident response. Cost is indicative, not a quote — the guide carries per-product pricing.
Vulnerability assessment and penetration testing
UCB Level II+Not a productVulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.
Vulnerability assessment and penetration testing
UCB Level II+Not a productVulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.
The obligation
Where it comes from
- Chapter IV §G — Periodic Testing
- Paragraph 116
What a supervisor expects to see
Why software does not answer this
The penetration test is a service, carried out by professionally qualified teams (paragraph 119). A scanning platform produces findings; it does not discharge the testing obligation. TechBag does not perform penetration testing and does not resell it — many banks use a CERT-In empanelled assessor, though the Directions do not require one.
Information Systems Audit function
UCB Level I+Not a productConstitute an IS Audit Cell as part of the Inspection and Audit Department, working to an IS audit policy the bank adopts, with reports placed before the Audit Committee of the Board.
Information Systems Audit function
UCB Level I+Not a productConstitute an IS Audit Cell as part of the Inspection and Audit Department, working to an IS audit policy the bank adopts, with reports placed before the Audit Committee of the Board.
The obligation
Where it comes from
- Chapter III §X — Information Systems Audit
- Paragraphs 94–102
What a supervisor expects to see
Why software does not answer this
This is a team and a reporting line, not a tool. No software satisfies it. We mention it because it appears in the same chapter as controls that are products, and a buyer working down the chapter will otherwise look for something to purchase.
Vendor and outsourcing risk, and the contract flow-down
UCB Level I+Not a productWhere the ATM Switch is run by a third-party provider, write 12 named control areas into the contract (paragraph 83) and require the provider to meet 37 baseline controls (paragraph 85) — and manage vendor and outsourcing risk generally.
Vendor and outsourcing risk, and the contract flow-down
UCB Level I+Not a productWhere the ATM Switch is run by a third-party provider, write 12 named control areas into the contract (paragraph 83) and require the provider to meet 37 baseline controls (paragraph 85) — and manage vendor and outsourcing risk generally.
The obligation
Where it comes from
- Chapter III §U — Vendor / Outsourcing Risk Management
- Paragraphs 83, 85
What a supervisor expects to see
Why software does not answer this
The obligation is a contract negotiation with your existing suppliers. Software can track the exercise; it cannot perform it, and buying a TPRM platform does not put a clause into an agreement your provider has not signed.
Sub-section references read from the RBI notification on 2026-10-05 by Raj, LupusCreed. General information, not legal advice. Cost bands are indicative annual figures at Indian mid-market scale, not quotes. If we have read something wrongly, write to info@thetechbag.com.
RBI cybersecurity obligations, answered
Short answers, each backed by the sources on this page.
What must every urban co-operative bank do, whatever its level?
Everything in Chapter III of the UCB Direction — 24 sub-sections from self-assessment and a separate cybersecurity policy to backup, vendor risk, incident response and an IS audit function — plus the Board's approval of technology and cybersecurity policy in Chapter II. Incidents go on DAKSH within six hours of detection at every level.
How many controls must a UCB's ATM Switch provider meet?
Where a UCB runs its ATM Switch through a third-party Application Service Provider, 12 named control areas go into the contract (paragraph 83) and the provider must meet 37 baseline controls (paragraph 85). Commercial, small finance and payments banks carry 12 plus 24; AIFIs and CICs have no such provision.
Which RBI cybersecurity obligations can't be met by buying software?
Vulnerability assessment and penetration testing, Information Systems Audit function, Vendor and outsourcing risk, and the contract flow-down. Penetration testing is a service, the IS Audit function is a team, and the contract flow-down is a negotiation with providers you already have.
How often must a bank run vulnerability assessments and penetration tests?
Under the 2026 Directions, vulnerability assessment of critical and DMZ-facing systems at least every six months and penetration testing at least once a year — from Level II for a UCB, for the Middle Layer and above for an NBFC, and for every commercial, small finance and payments bank, AIFI and CIC.
Must NBFCs write security clauses into vendor contracts?
It depends on the band. Base Layer NBFCs of ₹500 crore and above must write monitoring, data-protection, audit and RBI-access rights into outsourcing contracts (paragraph 62). The Middle Layer and above must run vendor-risk controls proportionate to risk (paragraph 117) and obtain source code or escrow for critical applications. The smallest band has no outsourcing provision.