RBI · Directions

Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

RBI/DoS/2026-27/461

In short
RBI/DoS/2026-27/461 is the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued on 31 July 2026 and in force from issue. It binds every NBFC, but only one of its three obligation chapters binds any given firm: Chapter III for Base Layer NBFCs below ₹500 crore of assets and Core Investment Companies, Chapter IV for Base Layer NBFCs at ₹500 crore and above, and Chapter V for Middle Layer and above excluding Core Investment Companies.

The record

ReferenceRBI/DoS/2026-27/461
Issued byReserve Bank of India (RBI)
Instrument typeDirections
Date of issue31 July 2026
StatusIn force
BindsAll NBFCs registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987. Three obligation chapters, drafted as alternatives rather than as a ladder: Chapter III for Base Layer NBFCs below ₹500 crore of assets and for Core Investment Companies, Chapter IV for Base Layer NBFCs at ₹500 crore and above, and Chapter V for Middle Layer and above, excluding Core Investment Companies.
Dates it setsIn effect on issue. The instrument sets no further dates.
Non-Banking Financial Companies as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds every NBFC registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987.
  • Runs to six chapters and 158 paragraphs, where the other six instruments in the family run to eight chapters and between 227 and 233.
  • Splits the obligations into three chapters drafted as alternatives — each says “applicable only for” its own class — so exactly one binds any given firm.
  • Chapter III binds Base Layer NBFCs below ₹500 crore of assets and Core Investment Companies; Chapter IV binds Base Layer NBFCs at ₹500 crore and above; Chapter V binds Middle Layer and above, excluding Core Investment Companies.
  • Sits alongside, and does not absorb, the NBFC outsourcing Directions of 28 November 2025 — though Chapter IV carries an IT services outsourcing section of its own.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The seven RBI Directions, and which one binds you