Regulation

Cyber security regulations in India: which one applies to you

Every instrument a regulated Indian entity has to answer to — RBI, SEBI, IRDAI, CERT-In and DPDP — with who each one binds, what it requires, and where to read it.

In short
A regulated Indian entity answers to its sector regulator and to two rules that bind everyone. The RBI reset its framework on 31 July 2026 with seven Directions, one per entity class; SEBI runs CSCRF; IRDAI reissued its Guidelines on 6 April 2026. CERT-In requires six-hour incident reporting, and the DPDP Rules phase in to 13 May 2027.

Almost every summary of Indian cyber regulation is written from one instrument outwards, which is useful only if you already know which instrument binds you. This page runs the other way: what exists, who each thing binds, and where to read the text. The detailed pages sit one click away.

Every instrument, in one table

InstrumentIssuedWho it binds
Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/410
31 July 2026Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.
Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
20 August 2024SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.
IRDAI Information and Cyber Security Guidelines, 2026
IRDAI/GA&HR/CIR/MISC/51/4/2026
6 April 2026All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023.
Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs
IFSCA-CSD0MSC/13/2025-DCS
10 March 2025Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions for branches, group-only Global In-House Centres, entities with fewer than ten employees and foreign universities — conditional, and lapsing on 10 March 2028 unless extended.
Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025
RBI/DOR/2025-26/171
28 November 2025Commercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered.
CERT-In Directions under sub-section (6) of section 70B of the Information Technology Act, 2000
No. 20(3)/2022-CERT-In
28 April 2022Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them.
Digital Personal Data Protection Rules, 2025
G.S.R. 846(E)
13 November 2025Data Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027.
Principal instruments as at August 2026. Reference numbers and dates read from each regulator's own notification. Applicability varies — confirm your own scope with counsel.

The RBI row names the commercial banks instrument because it is the one most readers arrive looking for. It is one of seven issued the same day — the others cover small finance banks, payments banks, urban co-operative banks, the all India financial institutions, NBFCs and credit information companies. All seven, with reference numbers sets out which is which.

Find yourself

The fastest route from an entity type to the instrument that governs it. Where an organisation holds more than one registration — a bank with a depository participant licence, an insurer with an asset management arm — it is in scope for both, and SEBI has clarified that its controls apply to the infrastructure used for SEBI-regulated activities rather than to the whole estate.

To do this interactively — and get the reference number, issue date and a link to the regulator's own notification for each instrument — use the regulation finder.

Banks, NBFCs, co-operative banks and credit bureaux

One of the seven RBI Directions of 31 July 2026. Which one depends on your licence, and the obligations then scale within it — by layer for NBFCs, by level for urban co-operative banks. Outsourcing sits in a separate instrument that the 2026 Directions deliberately preserved.

Brokers, AMCs, RTAs, depositories and exchanges

SEBI's CSCRF, at the standard set by your category — Market Infrastructure Institution, Qualified RE, Mid-size, Small-size or Self-certification. The category is re-fixed at the start of each financial year on the previous year's data, so it is not a permanent property of the firm. The CSCRF guide covers the thresholds.

Insurers, brokers, corporate agents, web aggregators and TPAs

IRDAI's Information and Cyber Security Guidelines, 2026, which replaced the 2023 Guidelines on 6 April 2026 and reach the intermediary chain as well as the insurer.

Everyone, regardless of sector

CERT-In's six-hour incident reporting under section 70B(6) of the IT Act 2000, and the DPDP Act and Rules for anyone processing digital personal data. Neither is a financial-sector instrument and neither can be discharged by satisfying a sector regulator.

Indian entities serving clients abroad inherit a second set on top of these, arriving through the customer contract rather than from an Indian regulator: NIS2, DORA and SEC Regulation S-P each place obligations on their regulated firms' suppliers, wherever those suppliers sit.

What the regulators have converged on

The instruments were written separately and read very differently, but four expectations now appear in all of them. Where three regulators independently arrive at the same requirement, it is worth treating as the direction of travel rather than as one regulator's preference.

  • The board is named. Not “senior management” — the board, with specified committees and, in the RBI's case, a composition test for the IT Strategy Committee that a board either passes or does not.
  • CISO independence is structural. The RBI wants the CISO reporting into the executive overseeing risk; IRDAI states the CISO must not report to the Head of IT and must not carry business targets; SEBI sets the CISO's standing at least equivalent to the CTO or CIO for its larger entities. Each is a reporting line, visible on a chart.
  • Assurance is continuous, not annual. Half-yearly vulnerability assessment, annual penetration testing at minimum, half-yearly disaster recovery drills, continuous auditing of critical systems where practicable.
  • Third parties are a first-class obligation. Every one of these instruments carries a third-party chapter, and none of them accepts that liability travels with the contract.

Regulatory positions are taken from the issuing regulators' own notifications, each linked above. Every instrument cited here was verified against the issuing regulator's own notification on . The RBI's notification search is the canonical place to check whether this family has been added to. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.

Where BitScore fits, and where it does not

One theme runs through every instrument above: the regulator wants evidence of oversight rather than an assertion of it. A security rating is useful for exactly that and for nothing beyond it. It is calculated by an outside party from attacker-visible signals, updated continuously, benchmarked against sector peers, and reviewable as a trend — so it is an artefact the organisation did not produce about itself and could not have assembled retrospectively.

It is not compliance with any instrument on this page, and presenting it as such would be a serious misreading of both the regulation and the rating. It says nothing about internal controls, incident response capability, consent architecture or DPDP readiness. What it does is convert “we take cyber seriously” into a measured, independently calculated, trended position that a director can interrogate and a supervisor can be shown.

The three regulator pages below carry the clause-level detail, including what a rating evidences under each instrument and what it leaves untouched.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ