Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/410
The record
| Reference | RBI/DoS/2026-27/410 |
|---|---|
| Issued by | Reserve Bank of India (RBI) |
| Instrument type | Directions |
| Date of issue | 31 July 2026 |
| Status | In force |
| Binds | Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters. |
| Dates it sets | In effect on issue. The instrument sets no further dates. |
What it says
- Binds banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with the corresponding new banks and the State Bank of India.
- Foreign banks operating in India through branches follow a comply-or-explain approach on selected chapters rather than the full set.
- Repeals its predecessors through a covering circular issued the same day, which is a separate document from the Directions themselves.
- Carries no transition period. The Directions took effect on issue, which is the feature most often assumed away.
- Leaves the outsourcing regime standing: the third-party paragraphs here apply only to IT and cyber arrangements falling outside the 2025 outsourcing Directions.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- Small Finance Banks RBI/DoS/2026-27/419 — Small Finance Banks, which the commercial banks Directions expressly exclude.
- Payments Banks RBI/DoS/2026-27/428 — Payments Banks, which the commercial banks Directions expressly exclude.
- Urban Co-operative Banks RBI/DoS/2026-27/437 — Primary Co-operative Banks, graded into Levels I to IV by the digital services they offer.
- Non-Banking Financial Companies RBI/DoS/2026-27/461 — All NBFCs, through three alternative chapters split at ₹500 crore, and Core Investment Companies.
- RBI outsourcing Directions, 2025 RBI/DOR/2025-26/171 — Commercial banks — a separate outsourcing track the 2026 Directions preserve rather than absorb.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .