RBI · Directions

Reserve Bank of India (Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

RBI/DoS/2026-27/419

In short
RBI/DoS/2026-27/419 is the Reserve Bank of India (Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued on 31 July 2026 and in force from issue. Small Finance Banks are expressly excluded from the Commercial Banks Directions of the same date because this instrument covers them instead, so a Small Finance Bank citing RBI/DoS/2026-27/410 is citing the wrong reference.

The record

ReferenceRBI/DoS/2026-27/419
Issued byReserve Bank of India (RBI)
Instrument typeDirections
Date of issue31 July 2026
StatusIn force
BindsSmall Finance Banks.
Dates it setsIn effect on issue. The instrument sets no further dates.
Small Finance Banks as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds Small Finance Banks, and only Small Finance Banks.
  • Issued on 31 July 2026 as one of seven parallel Directions, each addressed to a different class of regulated entity.
  • Repeals its predecessors through the same covering circular as the other six.
  • In force on issue, with no transition period stated.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • Commercial Banks RBI/DoS/2026-27/410Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks.
  • Payments Banks RBI/DoS/2026-27/428Payments Banks, which the commercial banks Directions expressly exclude.
  • Urban Co-operative Banks RBI/DoS/2026-27/437Primary Co-operative Banks, graded into Levels I to IV by the digital services they offer.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The seven RBI Directions, and which one binds you