Cyber security regulations in India: which one applies to you
Six regulators, and two rules that bind every Indian entity whatever its sector. Which instruments apply to you — RBI, SEBI, IRDAI, IFSCA, CERT-In, DPDP.
Almost every summary of Indian cyber regulation is written from one instrument outwards, which is useful only if you already know which instrument binds you. This page runs the other way: what exists, who each thing binds, and where to read the text. The detailed pages sit one click away.
Every instrument, in one table
| Instrument | Issued | Who it binds |
|---|---|---|
| Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 RBI/DoS/2026-27/410 | 31 July 2026 | Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters. |
| Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 | 20 August 2024 | SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. |
| IRDAI Information and Cyber Security Guidelines, 2026 IRDAI/GA&HR/CIR/MISC/51/4/2026 | 6 April 2026 | All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023. |
| Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs IFSCA-CSD0MSC/13/2025-DCS | 10 March 2025 | Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions that the March 2026 amendment restructured into two tiers: branches, group-only Global In-House Centres and REs with fewer than ten employees at para 21, and foreign universities, newly incorporated standalone REs with no parent, and Credit Rating Agencies at the new para 23. Both tiers are conditional and lapse on 10 March 2028 unless extended. |
| Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 RBI/DOR/2025-26/171 | 28 November 2025 | Commercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered. |
| CERT-In Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 No. 20(3)/2022-CERT-In | 28 April 2022 | Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them. |
| Digital Personal Data Protection Rules, 2025 G.S.R. 846(E) | 13 November 2025 | Data Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027. |
The RBI row names the commercial banks instrument because it is the one most readers arrive looking for. It is one of seven issued the same day — the others cover small finance banks, payments banks, urban co-operative banks, the all India financial institutions, NBFCs and credit information companies. All seven, with reference numbers sets out which is which.
Find yourself
The fastest route from an entity type to the instrument that governs it. Where an organisation holds more than one registration — a bank with a depository participant licence, an insurer with an asset management arm — it is in scope for both, and SEBI has clarified that its controls apply to the infrastructure used for SEBI-regulated activities rather than to the whole estate.
Banks, NBFCs, co-operative banks and credit bureaux
One of the seven RBI Directions of 31 July 2026. Which one depends on your licence, and the obligations then scale within it — by layer for NBFCs, by level for urban co-operative banks. Outsourcing sits in a separate instrument that the 2026 Directions deliberately preserved.
Brokers, AMCs, RTAs, depositories and exchanges
SEBI's CSCRF, at the standard set by your category — Market Infrastructure Institution, Qualified RE, Mid-size, Small-size or Self-certification. The category is re-fixed at the start of each financial year on the previous year's data, so it is not a permanent property of the firm. The CSCRF guide covers the thresholds.
Insurers, brokers, corporate agents, web aggregators and TPAs
IRDAI's Information and Cyber Security Guidelines, 2026, which replaced the 2023 Guidelines on 6 April 2026 and reach the intermediary chain as well as the insurer.
Everyone, regardless of sector
CERT-In's six-hour incident reporting under section 70B(6) of the IT Act 2000, and the DPDP Act and Rules for anyone processing digital personal data. Neither is a financial-sector instrument and neither can be discharged by satisfying a sector regulator.
Indian entities serving clients abroad inherit a second set on top of these, arriving through the customer contract rather than from an Indian regulator: NIS2, DORA and SEC Regulation S-P each place obligations on their regulated firms' suppliers, wherever those suppliers sit.
What the regulators have converged on
The instruments were written separately and read very differently, but four expectations now appear in all of them. Where three regulators independently arrive at the same requirement, it is worth treating as the direction of travel rather than as one regulator's preference.
- The board is named. Not “senior management” — the board, with specified committees and, in the RBI's case, a composition test for the IT Strategy Committee that a board either passes or does not.
- CISO independence is structural. The RBI wants the CISO reporting into the executive overseeing risk; IRDAI states the CISO must not report to the Head of IT and must not carry business targets; SEBI sets the CISO's standing at least equivalent to the CTO or CIO for its larger entities. Each is a reporting line, visible on a chart.
- Assurance is continuous, not annual. Half-yearly vulnerability assessment, annual penetration testing at minimum, half-yearly disaster recovery drills, continuous auditing of critical systems where practicable.
- Third parties are a first-class obligation. Every one of these instruments carries a third-party chapter, and none of them accepts that liability travels with the contract.
Regulatory positions are taken from the issuing regulators' own notifications, each linked above. Every instrument cited here was verified against the issuing regulator's own notification on . The RBI's notification search is the canonical place to check whether this family has been added to. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
Where BitScore fits, and where it does not
One theme runs through every instrument above: the regulator wants evidence of oversight rather than an assertion of it. A security rating is useful for exactly that and for nothing beyond it. It is calculated by an outside party from attacker-visible signals, updated continuously, benchmarked against sector peers, and reviewable as a trend — so it is an artefact the organisation did not produce about itself and could not have assembled retrospectively.
It is not compliance with any instrument on this page, and presenting it as such would be a serious misreading of both the regulation and the rating. It says nothing about internal controls, incident response capability, consent architecture or DPDP readiness. What it does is convert “we take cyber seriously” into a measured, independently calculated, trended position that a director can interrogate and a supervisor can be shown.
The three regulator pages below carry the clause-level detail, including what a rating evidences under each instrument and what it leaves untouched.
Read next
- The Indian cyber regulation register — the complete list rather than the seven above, with each instrument's status, the dates it sets and when it was last checked at source. Downloadable as JSON and CSV.
- The RBI Directions of 31 July 2026 — all 7, and which one applies to you.
- SEBI CSCRF — categories, the Cyber Capability Index, and the audit cadence.
- IRDAI's 2026 Guidelines — what changed for insurers and their intermediaries.
- What Indian boards must evidence — the same landscape read from the board pack backwards.
Questions this page answers
- Which cyber security regulations apply to us in India?
- A regulated Indian entity answers to its sector regulator and to two rules that bind everyone regardless of sector. Banks, NBFCs and the other RBI-regulated classes fall under the RBI’s Directions of 31 July 2026. Securities-market entities fall under SEBI’s CSCRF. Insurers and intermediaries fall under IRDAI’s 2026 Guidelines. On top of whichever applies, CERT-In requires six-hour incident reporting and the DPDP Rules phase in to 13 May 2027.
- Is the RBI’s 2026 cyber security framework a single instrument?
- No — seven, issued the same day, one per entity class. Commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, non-banking financial companies and credit information companies each have their own Directions under the RBI/DoS/2026-27/ stem. The commercial banks instrument excludes the classes that have their own, so citing it for an NBFC or a payments bank cites the wrong document.
- Do the 2026 RBI Directions replace the outsourcing rules?
- No. The RBI’s cyber security Directions of July 2026 and its outsourcing Directions of November 2025 are separate tracks, and the 2026 instruments preserve the outsourcing obligations rather than absorbing them. An entity in scope of both complies with both. A parallel family of Digital Payment Security Controls Directions was issued the same day as the cyber framework and is a third set again — the three are not interchangeable.
- What binds an entity regardless of which regulator it answers to?
- Two instruments. The CERT-In Directions of 28 April 2022, issued under section 70B(6) of the IT Act 2000, require specified cyber incidents to be reported within six hours of noticing them, and they apply to every organisation rather than to a sector. The DPDP Rules 2025 apply to any Data Fiduciary processing digital personal data, phased to full compliance by 13 May 2027.
- What have the Indian regulators converged on?
- Evidence rather than assertion. Across the RBI, SEBI and IRDAI instruments the pattern is the same: continuous assessment rather than an annual snapshot, a named accountable executive whose independence is protected, third-party and supply-chain risk treated as the entity’s own, and a reporting clock measured in hours. The drafting differs by regulator; the direction does not.