Cyber security regulations in India: which one applies to you
Every instrument a regulated Indian entity has to answer to — RBI, SEBI, IRDAI, CERT-In and DPDP — with who each one binds, what it requires, and where to read it.
Almost every summary of Indian cyber regulation is written from one instrument outwards, which is useful only if you already know which instrument binds you. This page runs the other way: what exists, who each thing binds, and where to read the text. The detailed pages sit one click away.
Every instrument, in one table
| Instrument | Issued | Who it binds |
|---|---|---|
| Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 RBI/DoS/2026-27/410 | 31 July 2026 | Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters. |
| Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 | 20 August 2024 | SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. |
| IRDAI Information and Cyber Security Guidelines, 2026 IRDAI/GA&HR/CIR/MISC/51/4/2026 | 6 April 2026 | All insurers, insurance intermediaries and the Insurance Information Bureau of India. Compliance required from the financial year current at issue, which opened on 1 April 2026. Supersedes the 2023 Guidelines issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023. |
| Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs IFSCA-CSD0MSC/13/2025-DCS | 10 March 2025 | Any entity licensed, recognised, registered or authorised by IFSCA — the GIFT City IFSC. In force 1 April 2025. Applied on a principle of proportionality, with express exemptions for branches, group-only Global In-House Centres, entities with fewer than ten employees and foreign universities — conditional, and lapsing on 10 March 2028 unless extended. |
| Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 RBI/DOR/2025-26/171 | 28 November 2025 | Commercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered. |
| CERT-In Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 No. 20(3)/2022-CERT-In | 28 April 2022 | Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them. |
| Digital Personal Data Protection Rules, 2025 G.S.R. 846(E) | 13 November 2025 | Data Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027. |
The RBI row names the commercial banks instrument because it is the one most readers arrive looking for. It is one of seven issued the same day — the others cover small finance banks, payments banks, urban co-operative banks, the all India financial institutions, NBFCs and credit information companies. All seven, with reference numbers sets out which is which.
Find yourself
The fastest route from an entity type to the instrument that governs it. Where an organisation holds more than one registration — a bank with a depository participant licence, an insurer with an asset management arm — it is in scope for both, and SEBI has clarified that its controls apply to the infrastructure used for SEBI-regulated activities rather than to the whole estate.
To do this interactively — and get the reference number, issue date and a link to the regulator's own notification for each instrument — use the regulation finder.
Banks, NBFCs, co-operative banks and credit bureaux
One of the seven RBI Directions of 31 July 2026. Which one depends on your licence, and the obligations then scale within it — by layer for NBFCs, by level for urban co-operative banks. Outsourcing sits in a separate instrument that the 2026 Directions deliberately preserved.
Brokers, AMCs, RTAs, depositories and exchanges
SEBI's CSCRF, at the standard set by your category — Market Infrastructure Institution, Qualified RE, Mid-size, Small-size or Self-certification. The category is re-fixed at the start of each financial year on the previous year's data, so it is not a permanent property of the firm. The CSCRF guide covers the thresholds.
Insurers, brokers, corporate agents, web aggregators and TPAs
IRDAI's Information and Cyber Security Guidelines, 2026, which replaced the 2023 Guidelines on 6 April 2026 and reach the intermediary chain as well as the insurer.
Everyone, regardless of sector
CERT-In's six-hour incident reporting under section 70B(6) of the IT Act 2000, and the DPDP Act and Rules for anyone processing digital personal data. Neither is a financial-sector instrument and neither can be discharged by satisfying a sector regulator.
Indian entities serving clients abroad inherit a second set on top of these, arriving through the customer contract rather than from an Indian regulator: NIS2, DORA and SEC Regulation S-P each place obligations on their regulated firms' suppliers, wherever those suppliers sit.
What the regulators have converged on
The instruments were written separately and read very differently, but four expectations now appear in all of them. Where three regulators independently arrive at the same requirement, it is worth treating as the direction of travel rather than as one regulator's preference.
- The board is named. Not “senior management” — the board, with specified committees and, in the RBI's case, a composition test for the IT Strategy Committee that a board either passes or does not.
- CISO independence is structural. The RBI wants the CISO reporting into the executive overseeing risk; IRDAI states the CISO must not report to the Head of IT and must not carry business targets; SEBI sets the CISO's standing at least equivalent to the CTO or CIO for its larger entities. Each is a reporting line, visible on a chart.
- Assurance is continuous, not annual. Half-yearly vulnerability assessment, annual penetration testing at minimum, half-yearly disaster recovery drills, continuous auditing of critical systems where practicable.
- Third parties are a first-class obligation. Every one of these instruments carries a third-party chapter, and none of them accepts that liability travels with the contract.
Regulatory positions are taken from the issuing regulators' own notifications, each linked above. Every instrument cited here was verified against the issuing regulator's own notification on . The RBI's notification search is the canonical place to check whether this family has been added to. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
Where BitScore fits, and where it does not
One theme runs through every instrument above: the regulator wants evidence of oversight rather than an assertion of it. A security rating is useful for exactly that and for nothing beyond it. It is calculated by an outside party from attacker-visible signals, updated continuously, benchmarked against sector peers, and reviewable as a trend — so it is an artefact the organisation did not produce about itself and could not have assembled retrospectively.
It is not compliance with any instrument on this page, and presenting it as such would be a serious misreading of both the regulation and the rating. It says nothing about internal controls, incident response capability, consent architecture or DPDP readiness. What it does is convert “we take cyber seriously” into a measured, independently calculated, trended position that a director can interrogate and a supervisor can be shown.
The three regulator pages below carry the clause-level detail, including what a rating evidences under each instrument and what it leaves untouched.
Read next
- The Indian cyber regulation register — the complete list rather than the seven above, with each instrument's status, the dates it sets and when it was last checked at source. Downloadable as JSON and CSV.
- The RBI Directions of 31 July 2026 — all 7, and which one applies to you.
- SEBI CSCRF — categories, the Cyber Capability Index, and the audit cadence.
- IRDAI's 2026 Guidelines — what changed for insurers and their intermediaries.
- What Indian boards must evidence — the same landscape read from the board pack backwards.