Regulation

The RBI Directions of 31 July 2026: which of the seven applies to you

The RBI issued seven parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions on 31 July 2026, one per entity class. Which one binds you, what it requires, and how the obligations scale.

In short
On 31 July 2026 the Reserve Bank of India issued seven Directions under one title — Cybersecurity, Technology: Risk, Resilience and Assurance Framework — one each for commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies. All are in force immediately, and all repeal the earlier cyber and IT-governance instructions.

The single most common error on this subject is treating the framework as one instrument for commercial banks. It is not. Seven Directions were issued on the same day, each addressed to one class of regulated entity, each repealing that class's previous instructions through the same covering circular. A commercial bank citing the NBFC Directions in a supervisory response has made an avoidable mistake; so has an NBFC assuming the commercial banks instrument does not apply to it and that nothing else does.

Which one applies to you

Entity classReferenceApplicability
Commercial BanksRBI/DoS/2026-27/410Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.
Small Finance BanksRBI/DoS/2026-27/419Small Finance Banks.
Payments BanksRBI/DoS/2026-27/428Payments Banks.
Urban Co-operative BanksRBI/DoS/2026-27/437Primary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949, graded into Levels I to IV by the digital services they offer.
All India Financial InstitutionsRBI/DoS/2026-27/456EXIM Bank, NABARD, SIDBI, NHB and NaBFID.
Non-Banking Financial CompaniesRBI/DoS/2026-27/461All NBFCs, with chapters applying by scale-based layer — Base, Middle, Upper and Top — and to Core Investment Companies.
Credit Information CompaniesRBI/DoS/2026-27/470Credit Information Companies as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005.
The seven Directions, all issued 31 July 2026. Reference numbers and applicability read from each notification.

Two classes are not in this family. Regional Rural Banks have no instrument under this title. Local Area Banks received (Local Area Banks – Miscellaneous) Supervisory Directions, 2026 on the same date, which is a different instrument with a different scope. So the framework reaches most of the RBI's regulated universe, but “all regulated entities” overstates it.

A separate family of (Digital Payment Security Controls) Directions, 2026 was issued on the same day to several of the same entity classes. Those are about payment channels rather than the enterprise security framework, and they are not interchangeable with the Directions on this page.

What all seven require

The instruments share a structure. Chapter II is written for the board, and its significance is that the obligations are specified rather than implied:

  • Annual board approval of the IT, cybersecurity and business continuity strategies — a recurring agenda item, not a one-time adoption.
  • A qualified IT Strategy Committee of at least three directors, chaired by an independent director with substantial IT expertise — defined as a minimum of seven years managing information systems. That is a composition test, not a statement of intent.
  • A senior CISO reporting directly to the executive overseeing risk management, rather than into the function whose delivery timetable the risk inconveniences.
  • A cybersecurity policy distinct from the IT policy — two documents, not one policy with a security section in it.
  • An Information Systems Audit function under Audit Committee oversight, planned on a risk basis, with continuous auditing of critical systems where practicable.

The operational floor

Beneath the governance chapters sits what has to exist for the board's assurance to mean anything: an information asset inventory with criticality classification; secure configuration and patch management; multi-factor authentication for privileged users and critical systems; data loss prevention across endpoints, transit and storage; and a Cyber Security Operations Centre running round-the-clock monitoring with SIEM-based log collection and correlation. The Directions also reach cryptography, secure software development, source code escrow, IPv6 readiness, teleworking and cloud.

The timings that cannot be assembled after the fact

ObligationFrequency or deadline
Cyber incident reporting to the RBI on DAKSHWithin six hours of detection
Vulnerability assessmentAt least half-yearly
Penetration testing of critical systemsAt least annually, by independent trained assessors
Disaster recovery drills for critical systemsHalf-yearly, with recovery objectives set close to zero
Board approval of strategyAnnual
Recurring obligations under the Directions. Frequencies are minimums; several classes are expected to go further on critical systems.

The six-hour clock deserves separate attention because it is an operational constraint disguised as a reporting rule, and because it is the second one. CERT-In has required reporting within six hours since 2022. A bank now runs both, to two recipients. An organisation that learns about its own incidents from a customer has already failed the timeline, whichever regulator is at the other end of it.

How the obligations scale

The Directions are not uniform within a class. Two of the seven grade their requirements explicitly, and this is the part that secondary summaries flatten.

NBFCs — by scale-based layer

The NBFC Directions apply to all NBFCs, including entities regulated under the Factoring Regulation Act, 2011 and the National Housing Bank Act, 1987. Which chapters bind a given NBFC depends on its position in the scale-based regulatory framework — Base, Middle, Upper and Top Layers — and on whether it is a Core Investment Company. A Base Layer NBFC and an Upper Layer NBFC are both in scope and are not carrying the same obligations.

Urban co-operative banks — by level

The UCB Directions define four levels by the digital services a bank actually offers, and attach chapters accordingly:

LevelTestChapters
IAll UCBs, whatever digital services they offerII, III
IISub-members of centralised payment systems offering internet or mobile banking, or direct members of CTS, IMPS or UPIII, III, IV
IIIDirect CPS members, or running their own ATM switch or a SWIFT interfaceII, III, IV, V
IVCPS members with both an ATM switch and SWIFT, or hosting their own data centre or softwareII, III, IV, V, VI
UCB levels under the 2026 Directions. Higher levels attract the chapters beneath them as well.

A UCB may adopt a higher level of security than its level requires on its board's own assessment of risk and capability, and one that already runs a dedicated CISO structure meeting the Chapter VI requirements may continue its existing governance arrangements. The proportionality runs one way: upward voluntarily, never downward.

Outsourcing is a separate track

It is easy to assume the 2026 Directions swallowed the outsourcing rules, since they repeal a great deal else and carry their own third-party chapter. They did not. The Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 RBI/DOR/2025-26/171, issued 28 November 2025 — remain in force, and the 2026 Directions carve themselves around them: their third-party provisions apply only to IT and cybersecurity arrangements falling outside the outsourcing instrument.

So a bank runs both, and the transition window on the outsourcing side has already closed — existing IT outsourcing agreements had until 10 April 2026. Third-party risk management for Indian BFSI covers how the two fit together in a working programme.

Read from the RBI's own notifications of 31 July 2026, each linked in the table above. Every instrument cited here was verified against the issuing regulator's own notification on . The RBI's notification search is the place to check for amendments. This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.

Where BitScore fits, and where it does not

Two provisions in these Directions are the ones a continuous external measurement speaks to directly. The first is the information asset inventory with criticality classification: an outside-in view of the estate finds internet-facing assets that the register does not describe, which is where the worst findings tend to live. The second is the third-party chapter, where continuous monitoring of a supplier's external posture is evidence about that supplier rather than an assertion from it.

There is also the softer but real point about board reporting. “The CISO reported no significant issues” is a weaker minute than it used to be. A measurement that is independent, continuous, benchmarked and trended gives an IT Strategy Committee something it can actually interrogate between meetings.

What it does not do is satisfy these Directions. It is not a Cyber Security Operations Centre, not a vulnerability assessment, not a penetration test, and not an Information Systems Audit. It says nothing about internal controls, encryption at rest, privileged access or recovery capability. A high rating is not regulatory cover, and presenting it as such would misread both the Directions and the rating.

Questions this page answers

Which of the seven RBI Directions applies to us?
Your licence decides it. There is one instrument each for commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies. The commercial banks Directions exclude small finance banks, payments banks and local area banks — the first two because they have their own, the third because it was given a different instrument entirely.
Do the 2026 Directions replace the RBI outsourcing rules?
No. The outsourcing Directions of 28 November 2025 run on a separate track, and the 2026 cybersecurity Directions preserve them rather than absorbing them. A bank managing a third-party arrangement answers to both at once. Citing one where a supervisor expects the other is the most common error on this subject.
Are Regional Rural Banks covered?
No. Regional Rural Banks have no instrument in this family. Local area banks were given a separate (Local Area Banks – Miscellaneous) Supervisory Directions, 2026 on the same date rather than one of the seven. The framework reaches most of the RBI’s regulated universe, but “all regulated entities” overstates it.
How quickly must a cyber incident be reported to the RBI?
Within six hours of detection, on the DAKSH platform. That runs alongside CERT-In’s own six-hour clock under section 70B(6) of the IT Act 2000, which has applied since 2022 — two obligations, to two recipients, on the same deadline. An organisation that learns of its incidents from a customer has already missed both.
Do all NBFCs carry the same obligations?
No. The NBFC Directions cover every NBFC, but which chapters bind a given firm follows its place in the scale-based regulatory framework — Base, Middle, Upper or Top Layer — and whether it is a Core Investment Company. Urban co-operative banks are graded separately, by four levels set by the digital services the bank actually offers.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ