Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/437
The record
| Reference | RBI/DoS/2026-27/437 |
|---|---|
| Issued by | Reserve Bank of India (RBI) |
| Instrument type | Directions |
| Date of issue | 31 July 2026 |
| Status | In force |
| Binds | Primary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949, graded into Levels I to IV by the digital services they offer. |
| Dates it sets | In effect on issue. The instrument sets no further dates. |
What it says
- Binds Primary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949.
- Grades each bank into Level I to IV by its digital depth and its interconnectedness to the payment systems, rather than by asset size.
- Stacks the chapters cumulatively: Level I takes Chapters II and III, Level II adds IV, Level III adds V and Level IV adds VI.
- Requires a Chief Information Security Officer only from Level II, and a Cyber Security Operations Centre only at Level IV.
- Lets a bank adopt a higher level voluntarily on its Board’s own assessment, and provides no route to a lower one.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- Non-Banking Financial Companies RBI/DoS/2026-27/461 — All NBFCs, through three alternative chapters split at ₹500 crore, and Core Investment Companies.
- Commercial Banks RBI/DoS/2026-27/410 — Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks.
- Small Finance Banks RBI/DoS/2026-27/419 — Small Finance Banks, which the commercial banks Directions expressly exclude.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .