Regulation

What the 2026 RBI Directions ask of an NBFC

The NBFC instrument is built differently from the banks’ — three mutually exclusive chapters, split at ₹500 crore of assets inside the Base Layer alone.

In short
RBI/DoS/2026-27/461 binds every NBFC, but only one of its three obligation chapters binds any given firm — they are alternatives rather than cumulative tiers. Chapter III covers Base Layer NBFCs below ₹500 crore of assets and Core Investment Companies; Chapter IV covers Base Layer NBFCs at ₹500 crore and above; Chapter V covers Middle Layer and above, expressly excluding Core Investment Companies.

The seven Directions the RBI issued on 31 July 2026 are usually described as one framework addressed to seven audiences. For five of them that is very nearly true. For NBFCs it is not: RBI/DoS/2026-27/461 is a differently built instrument, and an NBFC that reads the commercial banks version to work out its obligations will get the wrong answer about which of them apply.

The commercial banks instrument runs to eight chapters and 233 paragraphs, with one 31-section baseline control set that binds every commercial bank alike. The NBFC instrument runs to six chapters and 158 paragraphs, and splits its obligations into three chapters of which exactly one applies to any given firm.

Which chapter binds you

Paragraph 3 assigns the chapters. Chapter II — the role of the Board — applies to every NBFC in scope. After that, one chapter and one only:

If you areYour chapterWhat it holds
A Base Layer NBFC with asset size below ₹500 crore, or a Core Investment CompanyChapter IIIOne section: baseline cybersecurity and resilience requirements
A Base Layer NBFC with asset size ₹500 crore and aboveChapter IVSeven sections: IT governance, IT policy, information security and cybersecurity, IT operations, information systems audit, business continuity and disaster recovery, and IT services outsourcing
A Middle Layer NBFC or above — excluding Core Investment CompaniesChapter VFour sections: IT governance, IT and information security risk management, baseline cybersecurity and resilience requirements, and information systems audit
Chapter applicability under RBI/DoS/2026-27/461, paragraph 3. Each limb is drafted as 'applicable only for'.

Scope is wider than the RBI Act alone. The Directions reach every NBFC registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 and the National Housing Bank Act, 1987.

Three chapters, only one of which applies

This is the part that is easy to get wrong, because the neighbouring instrument in the same family does the opposite. The urban co-operative bank Directions grade a bank into four levels and stack the chapters — a Level III UCB complies with Chapters II through V together. The NBFC Directions do not stack. Paragraph 3 says the provisions of each chapter “shall be applicable only for” its named class.

What each chapter actually asks for

Chapter III — the smallest Base Layer NBFCs, and Core Investment Companies

The lightest of the three, and written in the language of a firm that may not yet have systems to secure. It asks the NBFC to prioritise implementing basic IT systems to digitise and secure its primary business databases, and to put in place a Board-approved IT and information security policy built to stated basic standards: physical and logical access controls with a defined password policy, well-defined user roles, the maker-checker principle to reduce error and misuse, information security and cybersecurity controls, and system-generated reports summarising the financial position for senior management.

Chapter IV — Base Layer NBFCs at or above ₹500 crore

A recognisable governance regime rather than a starter set. Its seven sections cover IT governance, the IT policy itself, information security and cybersecurity, IT operations, an information systems audit function, business continuity planning and disaster recovery, and — the one that surprises people — IT services outsourcing, with its own requirement to assess risk before an arrangement commences and to have the contract vetted by legal counsel.

Chapter V — Middle Layer and above

Four sections, and the shortest list of the three, which reads oddly until you see what is in them: IT governance, IT and information security risk management, the full baseline cybersecurity and resilience requirements, and information systems audit. The baseline section here is the substantial one, and it carries the vulnerability assessment and penetration testing regime — conducted by appropriately trained and independent information security experts, across a system’s whole lifecycle including pre-implementation, post-implementation and after changes, with a risk-based approach permitted for non-critical systems only.

The two things called CIC

Both of these are true at once, and they are not about the same companies.

  • In RBI/DoS/2026-27/461, CIC means a Core Investment Company. It is grouped with the smallest Base Layer NBFCs in Chapter III and expressly excluded from Chapter V, so a Core Investment Company takes the lightest chapter in the instrument whatever its size.
  • In RBI/DoS/2026-27/470, a separate instrument in the same family issued the same day, CIC means a Credit Information Company as defined under clause (e) of section 2 of the Credit Information Companies (Regulation) Act, 2005. That instrument has eight chapters and the full 31-section baseline.

Each instrument defines the abbreviation for itself, so neither is wrong. But a search for “the RBI 2026 cyber Directions for CICs” returns both, and they sit at opposite ends of the framework’s weight.

Six hours, twice over

A cyber incident goes to the RBI on the DAKSH supervisory platform within six hours of detection. That is the same clock the other six Directions set, and it is the second one an NBFC is already running: CERT-In has required a six-hour report under section 70B(6) of the Information Technology Act, 2000 since 2022. Two filings, two recipients, one deadline. The incident reporting clock resolves both into wall-clock times for an NBFC.

The Directions also leave the outsourcing track standing. RBI/DOR/2025-26/363, the NBFC outsourcing Directions of 28 November 2025, is a separate instrument with its own transition date, and Chapter IV’s IT services outsourcing section does not replace it.

Chapter structure, applicability and paragraph counts read from RBI/DoS/2026-27/461 on the RBI’s own notification page, and compared against RBI/DoS/2026-27/410 and RBI/DoS/2026-27/470. Indicative, and not legal advice: your layer, your asset size and therefore your chapter are determinations for your compliance team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

Which chapter of the RBI NBFC cybersecurity Directions applies to us?
One of three, and only one. Chapter III applies to Base Layer NBFCs with asset size below ₹500 crore and to Core Investment Companies. Chapter IV applies to Base Layer NBFCs with asset size of ₹500 crore and above. Chapter V applies to Middle Layer NBFCs and above, excluding Core Investment Companies. Chapter II, the role of the Board, applies to all of them. The instrument says "applicable only for" in each case, so the chapters are alternatives rather than a cumulative ladder.
Is there a threshold inside the NBFC Base Layer?
Yes, at ₹500 crore of asset size, and it is the split most accounts of these Directions miss. A Base Layer NBFC below ₹500 crore takes Chapter III, which asks for basic IT systems, a Board-approved IT and information security policy, access controls, a password policy, defined user roles and maker-checker. A Base Layer NBFC at or above ₹500 crore takes Chapter IV instead, which runs to seven sections including IT governance, information systems audit, business continuity and IT services outsourcing.
Do the NBFC Directions cover Core Investment Companies?
Yes, and they place them in the lightest chapter. A Core Investment Company takes Chapter III alongside the smallest Base Layer NBFCs, and is expressly excluded from Chapter V whatever its size. Note that a separate instrument in the same family — RBI/DoS/2026-27/470 — binds Credit Information Companies, which the RBI also abbreviates to CIC. The two are different entities under different Directions.
How is the NBFC instrument different from the commercial banks one?
Structurally, not just in addressee. The commercial banks Directions run to eight chapters and 233 paragraphs with a single 31-section baseline control set that binds every commercial bank. The NBFC Directions run to six chapters and 158 paragraphs, and split the obligations into three alternative chapters by layer and asset size. Reading the commercial banks instrument to understand NBFC obligations produces the wrong answer about what applies.
How quickly must an NBFC report a cyber incident?
Within six hours of detection, on the RBI’s DAKSH supervisory platform. CERT-In’s own six-hour clock under section 70B(6) of the IT Act 2000 runs in parallel and has done since 2022, so an NBFC files twice on the same deadline to two different recipients.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Work out which instruments bind you