Regulation

Cyber security regulations in India: which one applies to you

Six regulators, and two rules that bind every Indian entity whatever its sector. Which instruments apply to you — RBI, SEBI, IRDAI, IFSCA, CERT-In, DPDP.

In short
A regulated Indian entity answers to its sector regulator and to two rules that bind everyone. The RBI reset its framework on 31 July 2026 with seven Directions, one per entity class; SEBI runs CSCRF; IRDAI reissued its Guidelines on 6 April 2026. CERT-In requires six-hour incident reporting, and the DPDP Rules phase in to 13 May 2027.

Almost every summary of Indian cyber regulation is written from one instrument outwards, which is useful only if you already know which instrument binds you. This page runs the other way: what exists, who each thing binds, and where to read the text. The detailed pages sit one click away.

Every instrument, in one table

InstrumentIssuedWho it binds
Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/410
31 July 2026Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.
Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
20 August 2024SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.
IRDAI Information and Cyber Security Guidelines, 2026
IRDAI/GA&HR/CIR/MISC/51/4/2026
6 April 2026All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs
IFSCA-CSD0MSC/13/2025-DCS
10 March 2025Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended.
Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025
RBI/DOR/2025-26/171
28 November 2025Commercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered.
CERT-In Directions under sub-section (6) of section 70B of the Information Technology Act, 2000
No. 20(3)/2022-CERT-In
28 April 2022Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them.
Digital Personal Data Protection Rules, 2025
G.S.R. 846(E)
13 November 2025Data Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027.
Principal instruments as at August 2026. Reference numbers and dates read from each regulator's own notification. Applicability varies — confirm your own scope with counsel.

The RBI row names the commercial banks instrument because it is the one most readers arrive looking for. It is one of seven issued the same day — the others cover small finance banks, payments banks, urban co-operative banks, the all India financial institutions, NBFCs and credit information companies. All seven, with reference numbers sets out which is which.

Find yourself

The fastest route from an entity type to the instrument that governs it. Where an organisation holds more than one registration — a bank with a depository participant licence, an insurer with an asset management arm — it is in scope for both, and SEBI has clarified that its controls apply to the infrastructure used for SEBI-regulated activities rather than to the whole estate.

Banks, NBFCs, co-operative banks and credit bureaux

One of the seven RBI Directions of 31 July 2026. Which one depends on your licence, and the obligations then scale within it — by layer for NBFCs, by level for urban co-operative banks. Outsourcing sits in a separate instrument that the 2026 Directions deliberately preserved.

Brokers, AMCs, RTAs, depositories and exchanges

SEBI's CSCRF, at the standard set by your category — Market Infrastructure Institution, Qualified RE, Mid-size, Small-size or Self-certification. The category is re-fixed at the start of each financial year on the previous year's data, so it is not a permanent property of the firm. The CSCRF guide covers the thresholds.

Insurers, brokers, corporate agents, web aggregators and TPAs

IRDAI's Information and Cyber Security Guidelines, 2026, which replaced the 2023 Guidelines on 6 April 2026 and reach the intermediary chain as well as the insurer.

Everyone, regardless of sector

CERT-In's six-hour incident reporting under section 70B(6) of the IT Act 2000, and the DPDP Act and Rules for anyone processing digital personal data. Neither is a financial-sector instrument and neither can be discharged by satisfying a sector regulator.

Indian entities serving clients abroad inherit a second set on top of these, arriving through the customer contract rather than from an Indian regulator: NIS2, DORA and SEC Regulation S-P each place obligations on their regulated firms' suppliers, wherever those suppliers sit.

What the regulators have converged on

The instruments were written separately and read very differently, but four expectations now appear in all of them. Where three regulators independently arrive at the same requirement, it is worth treating as the direction of travel rather than as one regulator's preference.

  • The board is named. Not “senior management” — the board, with specified committees and, in the RBI's case, a composition test for the IT Strategy Committee that a board either passes or does not.
  • CISO independence is structural. The RBI wants the CISO reporting into the executive overseeing risk; IRDAI states the CISO must not report to the Head of IT and must not carry business targets; SEBI sets the CISO's standing at least equivalent to the CTO or CIO for its larger entities. Each is a reporting line, visible on a chart.
  • Assurance is continuous, not annual. Half-yearly vulnerability assessment, annual penetration testing at minimum, half-yearly disaster recovery drills, continuous auditing of critical systems where practicable.
  • Third parties are a first-class obligation. Every one of these instruments carries a third-party chapter, and none of them accepts that liability travels with the contract.

Regulatory positions are taken from the issuing regulators' own notifications, each linked above. Every instrument cited here was verified against the issuing regulator's own notification on . The RBI's notification search is the canonical place to check whether this family has been added to. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.

Where BitScore fits, and where it does not

One theme runs through every instrument above: the regulator wants evidence of oversight rather than an assertion of it. A security rating is useful for exactly that and for nothing beyond it. It is calculated by an outside party from attacker-visible signals, updated continuously, benchmarked against sector peers, and reviewable as a trend — so it is an artefact the organisation did not produce about itself and could not have assembled retrospectively.

It is not compliance with any instrument on this page, and presenting it as such would be a serious misreading of both the regulation and the rating. It says nothing about internal controls, incident response capability, consent architecture or DPDP readiness. What it does is convert “we take cyber seriously” into a measured, independently calculated, trended position that a director can interrogate and a supervisor can be shown.

The three regulator pages below carry the clause-level detail, including what a rating evidences under each instrument and what it leaves untouched.

Questions this page answers

Which cyber security regulations apply to us in India?
A regulated Indian entity answers to its sector regulator and to two rules that bind everyone regardless of sector. Banks, NBFCs and the other RBI-regulated classes fall under the RBI’s Directions of 31 July 2026. Securities-market entities fall under SEBI’s CSCRF. Insurers and intermediaries fall under IRDAI’s 2026 Guidelines. On top of whichever applies, CERT-In requires six-hour incident reporting and the DPDP Rules phase in to 13 May 2027.
Is the RBI’s 2026 cyber security framework a single instrument?
No — seven, issued the same day, one per entity class. Commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, non-banking financial companies and credit information companies each have their own Directions under the RBI/DoS/2026-27/ stem. The commercial banks instrument excludes the classes that have their own, so citing it for an NBFC or a payments bank cites the wrong document.
Do the 2026 RBI Directions replace the outsourcing rules?
No. The RBI’s cyber security Directions of July 2026 and its outsourcing Directions of November 2025 are separate tracks, and the 2026 instruments preserve the outsourcing obligations rather than absorbing them. An entity in scope of both complies with both. A parallel family of Digital Payment Security Controls Directions was issued the same day as the cyber framework and is a third set again — the three are not interchangeable.
What binds an entity regardless of which regulator it answers to?
Two instruments. The CERT-In Directions of 28 April 2022, issued under section 70B(6) of the IT Act 2000, require specified cyber incidents to be reported within six hours of noticing them, and they apply to every organisation rather than to a sector. The DPDP Rules 2025 apply to any Data Fiduciary processing digital personal data, phased to full compliance by 13 May 2027.
What have the Indian regulators converged on?
Evidence rather than assertion. Across the RBI, SEBI and IRDAI instruments the pattern is the same: continuous assessment rather than an annual snapshot, a named accountable executive whose independence is protected, third-party and supply-chain risk treated as the entity’s own, and a reporting clock measured in hours. The drafting differs by regulator; the direction does not.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Work out which instruments bind you