Regulation

RBI cyber security compliance: what Indian boards must evidence

The RBI Directions of 31 July 2026 name the board directly. What Indian boards must now demonstrate under RBI, SEBI, IRDAI, IFSCA, CERT-In and DPDP.

In short
Indian cyber regulation now asks boards to evidence oversight rather than hold a policy. The RBI’s seven Directions of 31 July 2026 name the board directly; SEBI’s CSCRF, IRDAI’s 2026 Guidelines, CERT-In’s six-hour reporting and the DPDP Rules add demands on top. The board’s question throughout is the same: what independent evidence supports the assurance given?

For most of the last decade, board-level cyber governance in India meant approving a policy, noting an annual audit, and recording that the matter had been considered. That is no longer sufficient — not because the language of the regulations is dramatically different, but because the expectation behind it has hardened. Regulators increasingly want to see that oversight is continuous and evidenced, not periodic and asserted.

The instruments that matter

InstrumentIssuedStatusBoard relevance
RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — seven instruments
RBI/DoS/2026-27/410 · 419 · 428 · 437 · 456 · 461 · 470
31 July 2026In force immediately. One instrument each for commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies, replacing the earlier cyber and IT-governance instructions for all of themBoard approval of strategy, a qualified IT Strategy Committee, a CISO reporting into risk, and an IS Audit function
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
20 August 2024In force; principal RE deadline was 31 August 2025 after two extensionsStandards, guidelines and prescribed compliance reporting formats
IRDAI Information and Cyber Security Guidelines, 2026
IRDAI/GA&HR/CIR/MISC/51/4/2026
6 April 2026In force; supersedes the 2023 GuidelinesA board-level cybersecurity committee, CISO independence, and half-yearly testing
CERT-In Directions under s.70B(6), IT Act 200028 April 2022In force since June 2022Six-hour incident reporting; failure carries penal consequences
DPDP Act 2023 and DPDP Rules 2025Rules notified 13 November 2025Phased; full compliance by 13 May 2027Data Protection Board operational now; breach notification and consent obligations commence 13 May 2027
Principal Indian cyber and data-protection instruments affecting board oversight. Reference numbers and dates read from each regulator's own notification. Applicability varies by entity type — confirm your own scope with counsel.

RBI: the board is named, not implied

On 31 July 2026 the RBI issued not one instrument but seven, all carrying the same title — Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — and all in force immediately. One binds each class of regulated entity:

Between them they replace a scattered body of circulars, and they repeal the earlier cybersecurity and IT-governance instructions for every class they cover — all seven through the same covering circular of that date, DoS.CO.PPG.66/11.01.005/2026-27.

Establishing which one binds you is the first job, and it is where most summaries go wrong. The commercial banks instrument defines itself as applying to banking companies other than small finance banks, payments banks and local area banks. The first two are excluded because each has its own Directions in this family; local area banks are excluded and have none, receiving a separate (Local Area Banks – Miscellaneous) Supervisory Directions, 2026 instead. Urban co-operative banks are not in the exclusion list at all — they are primary co-operative banks rather than banking companies, so they were never inside the definition, and they have their own Directions besides. Foreign banks operating through branches follow a comply-or-explain approach on selected provisions. Which of the seven applies to you sets out what each instrument covers, and how the obligations scale by NBFC layer and co-operative bank level. Citing the wrong instrument in a supervisory response is an avoidable own goal.

What changed for directors specifically

The Directions run to eight chapters, and the second of them is titled for the board. Its significance is that the obligations are now specified rather than implied:

  • Annual board approval of the IT, cybersecurity and business continuity strategies — a recurring agenda item, not a one-time adoption.
  • A qualified IT Strategy Committee of at least three directors, chaired by an independent director with substantial IT expertise, which the Directions define as a minimum of seven years managing information systems. That is a composition test a board either passes or does not.
  • A senior CISO — preferably at General Manager rank or equivalent — reporting directly to the Executive Director or equivalent overseeing risk management. The reporting line is the point: it separates the person raising the risk from the person whose delivery timetable the risk inconveniences.
  • A cybersecurity policy distinct from the IT policy. The Directions require the two to be separate documents rather than one policy with a security section.
  • An Information Systems Audit function under Audit Committee oversight, planned on a risk basis, with continuous auditing of critical systems where practicable.

Every one of those is answerable yes or no from a document that already exists — an organisation chart, a board calendar, a policy index — which is what makes them the provisions a supervisor reaches for first. The board governance check puts them as eleven questions and returns the gaps against the clause each comes from, in whichever of the seven instruments binds your class.

The operational floor beneath the governance

Beneath the board chapter sits the machinery that has to exist for the board's assurance to mean anything — asset inventory with criticality classification, patch management, multi-factor authentication, data loss prevention, and a Cyber Security Operations Centre monitoring round the clock. The full chapter-by-chapter reading covers it; two timings deserve a director's attention directly.

Cyber incidents must be reported within six hours of detection on the RBI's DAKSH supervisory platform — the same clock CERT-In runs, now with a second regulator at the other end of it. And disaster recovery drills are expected half-yearly for critical systems, with recovery objectives set close to zero. Both are commitments about capability, not paperwork; neither can be assembled after the incident that tests them.

The practical consequence for a board pack is unchanged in kind but sharper in degree: “the CISO reported no significant issues” is a weaker minute than it used to be. Periodic review implies something to review — a measurement that changes between meetings and can be interrogated.

SEBI: standards with prescribed reporting formats

SEBI issued the Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities by circular dated 20 August 2024 — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. CSCRF is structured in parts covering objectives and standards, guidelines, and standardised compliance and audit reporting formats.

Citing that circular alone is the common error, because the provisions a compliance officer actually needs arrived later. The categorisation thresholds — which decide the standards an entity is held to — were revised by SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 of 30 April 2025. The deadline reached 31 August 2025 through two extensions, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 of 28 March 2025 and SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96 of 30 June 2025, both of which carved out market infrastructure institutions, KYC registration agencies and qualified registrars — those three were never extended.

The reporting formats matter more than they first appear. Where a regulator prescribes the shape of the evidence, an internal narrative is no longer a substitute for it. The CSCRF compliance guide covers the categories, the Cyber Capability Index and the audit cadence in full.

IRDAI: a new instrument, and a reporting-line test

Insurers were brought under a revised regime on 6 April 2026, when IRDAI issued the Information and Cyber Security Guidelines, 2026 — IRDAI/GA&HR/CIR/MISC/51/4/2026 — in place of its 2023 Guidelines. For a board the sharpest provision is structural rather than technical: the CISO must not report to the Head of IT and must not carry business targets. That is a test an insurer either passes or does not, and it is visible from an organisation chart. What the 2026 Guidelines require covers the governance committees, the testing cadence and the third-party obligations.

CERT-In: six hours

The CERT-In Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, require cyber incidents to be reported within six hours of noticing them or being made aware of them. They apply broadly — service providers, intermediaries, data centres, body corporates and government organisations — and non-reporting can attract penal consequences. There is no circular number to cite here: the Directions carry none, and are referenced by their statutory basis and date.

Six hours is an operational constraint disguised as a reporting rule. An organisation that learns about its own incidents from a customer, or from a journalist, has already failed the timeline. Boards should ask how detection actually happens, and how quickly, rather than whether a reporting procedure exists on paper.

DPDP: the clock is already running

The Digital Personal Data Protection Rules were notified on 13 November 2025, operationalising the DPDP Act 2023 with a phased timeline. The Data Protection Board became functional on notification, the consent-manager registration window runs into late 2026, and full compliance is required by 13 May 2027 — the eighteen-month clock running from the notification date.

Eighteen months reads as comfortable and is not. Consent architecture, retention policy, breach response and data-principal rights each touch systems that take multiple quarters to change. Boards seeing a DPDP programme that has not yet started should treat that as a red-flag item now, not in 2027.

Every reference number above was read from the issuing regulator's own notification, each of which is linked. Every instrument cited here was verified against the issuing regulator's own notification on . This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.

What actually counts as evidence

Across every one of these instruments, the same underlying question recurs: can the organisation demonstrate that oversight happened, rather than assert that it did? Three kinds of artefact carry different weight.

Weak: management assertion

“We take cyber security seriously.” “No material incidents this quarter.” These are statements by the party being overseen, about itself. They are necessary and entirely insufficient.

Better: point-in-time third-party assessment

An annual penetration test or ISO 27001 certification is independent, which is a real improvement. Its limitation is temporal: it describes a moment, and the environment changes daily. A clean test in April says little about your posture in October.

Strongest: continuous, independent, externally verifiable measurement

A measurement calculated by an outside party, updated continuously, benchmarked against sector peers, and reviewable as a trend. It answers the question a director actually needs answered — is this getting better or worse, and how do we compare — in a form that was not produced by the people being assessed.

Where security ratings fit — and where they do not

A security rating is useful here for a specific and limited reason: it is independent, continuous, benchmarked, and produced by a third party. That makes it good evidence of ongoing external oversight, and a reasonable input to the board pack. How ratings are calculated explains the mechanics, including their limits.

It is not, and should not be presented as, compliance with any of the instruments above. None of them can be satisfied by a score. A rating evidences external hygiene and supports third-party due diligence; it says nothing about your internal controls, your incident response capability, your consent architecture, or your DPDP readiness. Treating a good score as regulatory cover would be a serious misreading — of the regulation and of the rating.

Used properly, it does one thing well: it converts “we take cyber seriously” from a claim into a measured, independently calculated, trended position that a director can interrogate and a regulator can be shown.

Related reading

Questions this page answers

What does Indian cyber regulation now require of a board?
Evidence of oversight rather than possession of a policy. For most of the last decade board-level cyber governance in India meant approving a policy, noting an annual audit and recording that the matter had been considered. Regulators now expect oversight to be continuous and evidenced rather than periodic and asserted — and the RBI’s Directions of 31 July 2026 name the board directly rather than implying it.
What counts as evidence a board can rely on?
Something produced independently of the people giving the assurance. The board’s question throughout is the same across every instrument: what independent evidence supports the assurance being given? A management report that the estate is secure is an assertion; an externally produced, dated measurement that management did not author is evidence. The distinction is what a supervisor is testing when it asks how the board satisfied itself.
Which instruments does an Indian board need to know about?
The RBI’s seven Directions of 31 July 2026 for RBI-regulated entities, SEBI’s CSCRF with its prescribed reporting formats for securities-market entities, and IRDAI’s 2026 Guidelines for insurers and intermediaries — whichever applies by sector. Then two that apply regardless: CERT-In’s six-hour incident reporting, and the DPDP Rules, whose clock is already running toward 13 May 2027.
Where do security ratings fit in board reporting, and where do they not?
A rating is independent, continuous and dated, which is what makes it usable as evidence alongside management’s own assurance. What it does not do is discharge an obligation. It is not an audit, not a penetration test, not a certification, and it cannot be submitted in place of a prescribed reporting format. Presenting it as compliance rather than as evidence is the error worth avoiding in a board pack.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Check your board’s cyber governance