What the 2026 RBI Directions ask of an NBFC
The NBFC instrument is built differently from the banks’ — three mutually exclusive chapters, split at ₹500 crore of assets inside the Base Layer alone.
The seven Directions the RBI issued on 31 July 2026 are usually described as one framework addressed to seven audiences. For five of them that is very nearly true. For NBFCs it is not: RBI/DoS/2026-27/461 is a differently built instrument, and an NBFC that reads the commercial banks version to work out its obligations will get the wrong answer about which of them apply.
The commercial banks instrument runs to eight chapters and 233 paragraphs, with one 31-section baseline control set that binds every commercial bank alike. The NBFC instrument runs to six chapters and 158 paragraphs, and splits its obligations into three chapters of which exactly one applies to any given firm.
Which chapter binds you
Paragraph 3 assigns the chapters. Chapter II — the role of the Board — applies to every NBFC in scope. After that, one chapter and one only:
| If you are | Your chapter | What it holds |
|---|---|---|
| A Base Layer NBFC with asset size below ₹500 crore, or a Core Investment Company | Chapter III | One section: baseline cybersecurity and resilience requirements |
| A Base Layer NBFC with asset size ₹500 crore and above | Chapter IV | Seven sections: IT governance, IT policy, information security and cybersecurity, IT operations, information systems audit, business continuity and disaster recovery, and IT services outsourcing |
| A Middle Layer NBFC or above — excluding Core Investment Companies | Chapter V | Four sections: IT governance, IT and information security risk management, baseline cybersecurity and resilience requirements, and information systems audit |
Scope is wider than the RBI Act alone. The Directions reach every NBFC registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 and the National Housing Bank Act, 1987.
Three chapters, only one of which applies
This is the part that is easy to get wrong, because the neighbouring instrument in the same family does the opposite. The urban co-operative bank Directions grade a bank into four levels and stack the chapters — a Level III UCB complies with Chapters II through V together. The NBFC Directions do not stack. Paragraph 3 says the provisions of each chapter “shall be applicable only for” its named class.
What each chapter actually asks for
Chapter III — the smallest Base Layer NBFCs, and Core Investment Companies
The lightest of the three, and written in the language of a firm that may not yet have systems to secure. It asks the NBFC to prioritise implementing basic IT systems to digitise and secure its primary business databases, and to put in place a Board-approved IT and information security policy built to stated basic standards: physical and logical access controls with a defined password policy, well-defined user roles, the maker-checker principle to reduce error and misuse, information security and cybersecurity controls, and system-generated reports summarising the financial position for senior management.
Chapter IV — Base Layer NBFCs at or above ₹500 crore
A recognisable governance regime rather than a starter set. Its seven sections cover IT governance, the IT policy itself, information security and cybersecurity, IT operations, an information systems audit function, business continuity planning and disaster recovery, and — the one that surprises people — IT services outsourcing, with its own requirement to assess risk before an arrangement commences and to have the contract vetted by legal counsel.
Chapter V — Middle Layer and above
Four sections, and the shortest list of the three, which reads oddly until you see what is in them: IT governance, IT and information security risk management, the full baseline cybersecurity and resilience requirements, and information systems audit. The baseline section here is the substantial one, and it carries the vulnerability assessment and penetration testing regime — conducted by appropriately trained and independent information security experts, across a system’s whole lifecycle including pre-implementation, post-implementation and after changes, with a risk-based approach permitted for non-critical systems only.
The two things called CIC
Both of these are true at once, and they are not about the same companies.
- In RBI/DoS/2026-27/461, CIC means a Core Investment Company. It is grouped with the smallest Base Layer NBFCs in Chapter III and expressly excluded from Chapter V, so a Core Investment Company takes the lightest chapter in the instrument whatever its size.
- In RBI/DoS/2026-27/470, a separate instrument in the same family issued the same day, CIC means a Credit Information Company as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005. That instrument has eight chapters and the full 31-section baseline.
Each instrument defines the abbreviation for itself, so neither is wrong. But a search for “the RBI 2026 cyber Directions for CICs” returns both, and they sit at opposite ends of the framework’s weight.
Six hours, twice over
A cyber incident goes to the RBI on the DAKSH supervisory platform within six hours of detection. That is the same clock the other six Directions set, and it is the second one an NBFC is already running: CERT-In has required a six-hour report under section 70B(6) of the Information Technology Act, 2000 since 2022. Two filings, two recipients, one deadline. The incident reporting clock resolves both into wall-clock times for an NBFC.
The Directions also leave the outsourcing track standing. RBI/DOR/2025-26/363, the NBFC outsourcing Directions of 28 November 2025, is a separate instrument with its own transition date, and Chapter IV’s IT services outsourcing section does not replace it.
Read next
- The seven Directions of 31 July 2026 — the family, why it is seven instruments and not one, and which entity classes have none.
- What the 2026 Directions ask of a UCB — the other instrument in the family with its own structure, graded four ways and stacked rather than exclusive.
- RBI/DoS/2026-27/461 — the reference record: dates, status, and the RBI’s own copy.
Chapter structure, applicability and paragraph counts read from RBI/DoS/2026-27/461 on the RBI’s own notification page, and compared against RBI/DoS/2026-27/410 and RBI/DoS/2026-27/470. Indicative, and not legal advice: your layer, your asset size and therefore your chapter are determinations for your compliance team.
Every instrument cited here was verified against the issuing regulator's own notification on .Questions this page answers
- Which chapter of the RBI NBFC cybersecurity Directions applies to us?
- One of three, and only one. Chapter III applies to Base Layer NBFCs with asset size below ₹500 crore and to Core Investment Companies. Chapter IV applies to Base Layer NBFCs with asset size of ₹500 crore and above. Chapter V applies to Middle Layer NBFCs and above, excluding Core Investment Companies. Chapter II, the role of the Board, applies to all of them. The instrument says "applicable only for" in each case, so the chapters are alternatives rather than a cumulative ladder.
- Is there a threshold inside the NBFC Base Layer?
- Yes, at ₹500 crore of asset size, and it is the split most accounts of these Directions miss. A Base Layer NBFC below ₹500 crore takes Chapter III, which asks for basic IT systems, a Board-approved IT and information security policy, access controls, a password policy, defined user roles and maker-checker. A Base Layer NBFC at or above ₹500 crore takes Chapter IV instead, which runs to seven sections including IT governance, information systems audit, business continuity and IT services outsourcing.
- Do the NBFC Directions cover Core Investment Companies?
- Yes, and they place them in the lightest chapter. A Core Investment Company takes Chapter III alongside the smallest Base Layer NBFCs, and is expressly excluded from Chapter V whatever its size. Note that a separate instrument in the same family — RBI/DoS/2026-27/470 — binds Credit Information Companies, which the RBI also abbreviates to CIC. The two are different entities under different Directions.
- How is the NBFC instrument different from the commercial banks one?
- Structurally, not just in addressee. The commercial banks Directions run to eight chapters and 233 paragraphs with a single 31-section baseline control set that binds every commercial bank. The NBFC Directions run to six chapters and 158 paragraphs, and split the obligations into three alternative chapters by layer and asset size. Reading the commercial banks instrument to understand NBFC obligations produces the wrong answer about what applies.
- How quickly must an NBFC report a cyber incident?
- Within six hours of detection, on the RBI’s DAKSH supervisory platform. CERT-In’s own six-hour clock under section 70B(6) of the IT Act 2000 runs in parallel and has done since 2022, so an NBFC files twice on the same deadline to two different recipients.