RBI cyber security compliance: what Indian boards must evidence
The RBI Directions of 31 July 2026 name the board directly. What Indian boards must now demonstrate under RBI, SEBI, CERT-In and DPDP, and how continuous measurement helps.
For most of the last decade, board-level cyber governance in India meant approving a policy, noting an annual audit, and recording that the matter had been considered. That is no longer sufficient — not because the language of the regulations is dramatically different, but because the expectation behind it has hardened. Regulators increasingly want to see that oversight is continuous and evidenced, not periodic and asserted.
The instruments that matter
| Instrument | Issued | Status | Board relevance |
|---|---|---|---|
| RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 | 31 July 2026 | In force immediately; repeals the earlier cyber and IT-governance instructions for the banks it covers | Board approval of strategy, a qualified IT Strategy Committee, a CISO reporting into risk, and an IS Audit function |
| RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices | 7 November 2023 | Effective 1 April 2024; superseded for commercial banks by the 2026 Directions, and still the instrument for NBFCs, credit information companies and AIFIs | Assigns explicit roles to the Board, IT Strategy Committee and senior management |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) | 20 August 2024 | In force; principal RE deadline was 31 August 2025 | Standards, guidelines and prescribed compliance reporting formats |
| CERT-In Directions under s.70B(6), IT Act 2000 | 28 April 2022 | In force since June 2022 | Six-hour incident reporting; failure carries penal consequences |
| DPDP Act 2023 and DPDP Rules 2025 | Rules notified 14 November 2025 | Phased; full compliance by 13 May 2027 | Data Protection Board operational; breach notification and consent obligations |
RBI: the board is named, not implied
On 31 July 2026 the RBI issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — reference RBI/DoS/2026-27/410, issued by the Department of Supervision and in force immediately on issuance. They consolidate what had been a scattered body of circulars into one instrument, and they repeal the earlier cybersecurity and IT-governance instructions for the banks they cover.
Scope is the first thing to establish, because it is narrower than the name suggests. The Directions apply to commercial banks under the Banking Regulation Act, 1949, excluding small finance banks, payments banks and local area banks. Foreign banks operating through branches follow a comply-or-explain approach on selected provisions. Everyone else — NBFCs, credit information companies, the all-India financial institutions — remains under the Master Direction on IT Governance and the applicable outsourcing norms. Citing the wrong instrument in a supervisory response is an avoidable own goal.
What changed for directors specifically
The Directions run to eight chapters, and the second of them is titled for the board. Its significance is that the obligations are now specified rather than implied:
- Annual board approval of the IT, cybersecurity and business continuity strategies — a recurring agenda item, not a one-time adoption.
- A qualified IT Strategy Committee of at least three directors, chaired by an independent director with substantial IT expertise, which the Directions define as a minimum of seven years managing information systems. That is a composition test a board either passes or does not.
- A senior CISO — preferably at General Manager rank or equivalent — reporting directly to the Executive Director or equivalent overseeing risk management. The reporting line is the point: it separates the person raising the risk from the person whose delivery timetable the risk inconveniences.
- A cybersecurity policy distinct from the IT policy. The Directions require the two to be separate documents rather than one policy with a security section.
- An Information Systems Audit function under Audit Committee oversight, planned on a risk basis, with continuous auditing of critical systems where practicable.
The operational floor beneath the governance
Chapters IV to VI set out what has to exist for the board's assurance to mean anything: an information asset inventory with criticality classification; secure configuration and patch management; multi-factor authentication for privileged users and critical systems; data loss prevention across endpoints, transit and storage; and a Cyber Security Operations Centre running round-the-clock monitoring with SIEM-based log collection and correlation. Vulnerability assessment is required at least every six months and penetration testing at least annually for critical systems, conducted by independent, trained assessors.
Two timings deserve a director's attention. Cyber incidents must be reported within six hours of detection on the RBI's DAKSH supervisory platform — the same clock CERT-In runs, now with a second regulator at the other end of it. And disaster recovery drills are expected half-yearly for critical systems, with recovery objectives set close to zero. Both are commitments about capability, not paperwork; neither can be assembled after the incident that tests them.
The practical consequence for a board pack is unchanged in kind but sharper in degree: “the CISO reported no significant issues” is a weaker minute than it used to be. Periodic review implies something to review — a measurement that changes between meetings and can be interrogated.
SEBI: standards with prescribed reporting formats
SEBI issued the Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities by circular dated 20 August 2024. CSCRF is structured in parts covering objectives and standards, guidelines, and standardised compliance and audit reporting formats. Deadlines were staggered and extended more than once — most regulated entities were brought to 31 August 2025, with market infrastructure institutions, KYC registration agencies and qualified registrars on separate timelines.
The reporting formats matter more than they first appear. Where a regulator prescribes the shape of the evidence, an internal narrative is no longer a substitute for it.
CERT-In: six hours
The CERT-In Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, require cyber incidents to be reported within six hours of noticing them or being made aware of them. They apply broadly — service providers, intermediaries, data centres, body corporates and government organisations — and non-reporting can attract penal consequences.
Six hours is an operational constraint disguised as a reporting rule. An organisation that learns about its own incidents from a customer, or from a journalist, has already failed the timeline. Boards should ask how detection actually happens, and how quickly, rather than whether a reporting procedure exists on paper.
DPDP: the clock is already running
The Digital Personal Data Protection Rules were notified on 14 November 2025, operationalising the DPDP Act 2023 with a phased timeline. The Data Protection Board became functional on notification, the consent-manager registration window runs into late 2026, and full compliance is required by 13 May 2027.
Eighteen months reads as comfortable and is not. Consent architecture, retention policy, breach response and data-principal rights each touch systems that take multiple quarters to change. Boards seeing a DPDP programme that has not yet started should treat that as a red-flag item now, not in 2027.
Regulatory positions summarised as at August 2026 from public sources, including the RBI Directions of 31 July 2026 linked above. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
What actually counts as evidence
Across every one of these instruments, the same underlying question recurs: can the organisation demonstrate that oversight happened, rather than assert that it did? Three kinds of artefact carry different weight.
Weak: management assertion
“We take cyber security seriously.” “No material incidents this quarter.” These are statements by the party being overseen, about itself. They are necessary and entirely insufficient.
Better: point-in-time third-party assessment
An annual penetration test or ISO 27001 certification is independent, which is a real improvement. Its limitation is temporal: it describes a moment, and the environment changes daily. A clean test in April says little about your posture in October.
Strongest: continuous, independent, externally verifiable measurement
A measurement calculated by an outside party, updated continuously, benchmarked against sector peers, and reviewable as a trend. It answers the question a director actually needs answered — is this getting better or worse, and how do we compare — in a form that was not produced by the people being assessed.
Where security ratings fit — and where they do not
A security rating is useful here for a specific and limited reason: it is independent, continuous, benchmarked, and produced by a third party. That makes it good evidence of ongoing external oversight, and a reasonable input to the board pack. How ratings are calculated explains the mechanics, including their limits.
It is not, and should not be presented as, compliance with any of the instruments above. None of them can be satisfied by a score. A rating evidences external hygiene and supports third-party due diligence; it says nothing about your internal controls, your incident response capability, your consent architecture, or your DPDP readiness. Treating a good score as regulatory cover would be a serious misreading — of the regulation and of the rating.
Used properly, it does one thing well: it converts “we take cyber seriously” from a claim into a measured, independently calculated, trended position that a director can interrogate and a regulator can be shown.
Related reading
- Third-party risk management for Indian BFSI — building the vendor-oversight side of the same obligation.
- What is a cyber security rating? — the mechanics, and the honest limitations.