RBI cyber security compliance: what Indian boards must evidence
RBI, SEBI and CERT-In have shifted cyber governance from assertion to evidence. What Indian boards are now expected to demonstrate, and how continuous measurement supports it.
For most of the last decade, board-level cyber governance in India meant approving a policy, noting an annual audit, and recording that the matter had been considered. That is no longer sufficient — not because the language of the regulations is dramatically different, but because the expectation behind it has hardened. Regulators increasingly want to see that oversight is continuous and evidenced, not periodic and asserted.
The four instruments that matter
| Instrument | Issued | Status | Board relevance |
|---|---|---|---|
| RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices | 7 November 2023 | Effective 1 April 2024 | Assigns explicit roles to the Board, IT Strategy Committee and senior management |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) | 20 August 2024 | In force; principal RE deadline was 31 August 2025 | Standards, guidelines and prescribed compliance reporting formats |
| CERT-In Directions under s.70B(6), IT Act 2000 | 28 April 2022 | In force since June 2022 | Six-hour incident reporting; failure carries penal consequences |
| DPDP Act 2023 and DPDP Rules 2025 | Rules notified 14 November 2025 | Phased; full compliance by 13 May 2027 | Data Protection Board operational; breach notification and consent obligations |
RBI: the board is named, not implied
The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices applies to scheduled commercial banks other than regional rural banks, small finance and payments banks, NBFCs in the Top, Upper and Middle layers, credit information companies, and the all-India financial institutions. Its significance for directors is structural: it specifies the roles of the Board of Directors, an IT Strategy Committee and senior management, and requires a designated Head of IT Function.
Entities must maintain an IT Governance Framework covering strategic alignment, risk management, resource management, performance management and business continuity, together with an IT and Information Security Risk Management Framework, an Information Security Policy, a Cyber Security Policy, and periodic review of IT-related risk.
The practical consequence is that “the CISO reported no significant issues” is a weaker minute than it used to be. Periodic review implies something to review — a measurement that changes between meetings and can be interrogated.
SEBI: standards with prescribed reporting formats
SEBI issued the Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities by circular dated 20 August 2024. CSCRF is structured in parts covering objectives and standards, guidelines, and standardised compliance and audit reporting formats. Deadlines were staggered and extended more than once — most regulated entities were brought to 31 August 2025, with market infrastructure institutions, KYC registration agencies and qualified registrars on separate timelines.
The reporting formats matter more than they first appear. Where a regulator prescribes the shape of the evidence, an internal narrative is no longer a substitute for it.
CERT-In: six hours
The CERT-In Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, require cyber incidents to be reported within six hours of noticing them or being made aware of them. They apply broadly — service providers, intermediaries, data centres, body corporates and government organisations — and non-reporting can attract penal consequences.
Six hours is an operational constraint disguised as a reporting rule. An organisation that learns about its own incidents from a customer, or from a journalist, has already failed the timeline. Boards should ask how detection actually happens, and how quickly, rather than whether a reporting procedure exists on paper.
DPDP: the clock is already running
The Digital Personal Data Protection Rules were notified on 14 November 2025, operationalising the DPDP Act 2023 with a phased timeline. The Data Protection Board became functional on notification, the consent-manager registration window runs into late 2026, and full compliance is required by 13 May 2027.
Eighteen months reads as comfortable and is not. Consent architecture, retention policy, breach response and data-principal rights each touch systems that take multiple quarters to change. Boards seeing a DPDP programme that has not yet started should treat that as a red-flag item now, not in 2027.
Regulatory positions summarised as at July 2026 from public sources. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
What actually counts as evidence
Across all four instruments, the same underlying question recurs: can the organisation demonstrate that oversight happened, rather than assert that it did? Three kinds of artefact carry different weight.
Weak: management assertion
“We take cyber security seriously.” “No material incidents this quarter.” These are statements by the party being overseen, about itself. They are necessary and entirely insufficient.
Better: point-in-time third-party assessment
An annual penetration test or ISO 27001 certification is independent, which is a real improvement. Its limitation is temporal: it describes a moment, and the environment changes daily. A clean test in April says little about your posture in October.
Strongest: continuous, independent, externally verifiable measurement
A measurement calculated by an outside party, updated continuously, benchmarked against sector peers, and reviewable as a trend. It answers the question a director actually needs answered — is this getting better or worse, and how do we compare — in a form that was not produced by the people being assessed.
Where security ratings fit — and where they do not
A security rating is useful here for a specific and limited reason: it is independent, continuous, benchmarked, and produced by a third party. That makes it good evidence of ongoing external oversight, and a reasonable input to the board pack. How ratings are calculated explains the mechanics, including their limits.
It is not, and should not be presented as, compliance with any of the four instruments above. None of them can be satisfied by a score. A rating evidences external hygiene and supports third-party due diligence; it says nothing about your internal controls, your incident response capability, your consent architecture, or your DPDP readiness. Treating a good score as regulatory cover would be a serious misreading — of the regulation and of the rating.
Used properly, it does one thing well: it converts “we take cyber seriously” from a claim into a measured, independently calculated, trended position that a director can interrogate and a regulator can be shown.
Related reading
- Third-party risk management for Indian BFSI — building the vendor-oversight side of the same obligation.
- What is a cyber security rating? — the mechanics, and the honest limitations.