Tool 3

Which Indian cyber security regulation applies to you

Route from your entity class to the instrument that actually governs it, including which of the seven RBI Directions of 31 July 2026 binds you and the two classes that have none.

In short
Which Indian cyber security instrument binds an entity follows from its class. The RBI issued seven parallel Directions on 31 July 2026, one per entity class, so a commercial bank, an NBFC and an Urban Co-operative Bank each file under a different one. SEBI runs CSCRF, IRDAI reissued its Guidelines in April 2026, and CERT-In binds nearly everyone.

Find your instrument

Pick your entity class. Every instrument shown links to the issuing regulator's own notification, and carries the trap most often hit when citing it.

Your entity
4instruments apply
InstrumentReferenceWhy it applies
CERT-In Directions, 2022CERT-InNo. 20(3)/2022-CERT-In28 April 2022The CERT-In Directions bind service providers, intermediaries, data centres, body corporates and Government organisations — which reaches almost every Indian entity operating IT systems.A sectoral filing never discharges the CERT-In obligation. They are separate filings on separate channels.
Commercial BanksRBIRBI/DoS/2026-27/41031 July 2026One of the seven Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions issued on 31 July 2026 — this is the one for a commercial bank.The paragraph numbers differ between the seven instruments. Quote the number from this one, not from the Commercial Banks Directions.
RBI outsourcing Directions, 2025RBIRBI/DOR/2025-26/17128 November 2025Vendor and outsourcing governance sits in its own instrument. The 2026 cyber Directions expressly preserve it rather than absorbing it.RBI 2026 cyber and RBI 2025 outsourcing are separate tracks. Where an incident originates at a service provider, both are in play.
DPDP Rules, 2025MeitYG.S.R. 846(E)13 November 2025A Data Fiduciary is anyone determining the purpose and means of processing digital personal data, which is orthogonal to sector and can bind alongside any of the above.Next date — 13 May 2027: Full compliance with the Rules.Phased. The breach-intimation duty in Rule 7, and section 8 of the Act, commence on 13 May 2027 — plan against them, but there is no DPDP breach clock running today.

Indicative, and not a determination that any instrument applies. Applicability is entity-specific and belongs to your compliance and legal team. Every link goes to the issuing regulator's own notification.

Take this away as an obligation map

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Where instruments run together

The instruments are cumulative. A filing under one never discharges another, and three overlaps catch people out.

  • Cyber and outsourcing are separate tracks. The 2026 cyber Directions expressly preserve the Managing Risks in Outsourcing Directions, 2025 rather than absorbing them. Where an incident originates at a service provider, both are live.
  • Listing obligations reach beyond the financial sector. A listed manufacturer with no financial-sector regulator still owes SEBI LODR disclosure on a material cyber incident.
  • DPDP is orthogonal to sector. A Data Fiduciary is anyone determining the purpose and means of processing digital personal data. Its obligations phase in to 13 May 2027 and sit alongside, not instead of, the sectoral instruments.

Once you know which instruments bind you, work out what an incident would cost you in hours with the incident reporting clock, or read the full guide to cyber security regulations in India.

This tool is indicative and is not a determination that any instrument applies. Applicability is entity-specific and belongs to your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

Do the RBI Cybersecurity Directions, 2026 apply to every RBI regulated entity?
No. The RBI issued seven parallel Directions on 31 July 2026, one per entity class — commercial banks at 410, Small Finance Banks 419, Payments Banks 428, Urban Co-operative Banks 437, All India Financial Institutions 456, NBFCs 461 and Credit Information Companies 470. Regional Rural Banks and Local Area Banks have no instrument in the family at all, and the Commercial Banks Directions must not be stretched to cover either.
Do the 2026 RBI cyber Directions replace the outsourcing rules?
No. Vendor and outsourcing governance remains in the RBI Directions on Managing Risks in Outsourcing, 2025, which the 2026 cyber Directions expressly preserve and carve around rather than absorb. They are separate tracks, and where an incident originates at a service provider both are in play at once.
Can more than one Indian cyber security regulation apply at the same time?
Routinely. A listed private-sector bank holding customer personal data answers to CERT-In, to its own RBI Directions, to the stock exchanges under LODR, and in due course to the DPDP regime — on different clocks, to different recipients, in different formats, from the same triggering event. The instruments are cumulative, and a filing under one never discharges another.
Does the DPDP Act apply alongside sectoral cyber security regulation?
Yes, and orthogonally. A Data Fiduciary is anyone determining the purpose and means of processing digital personal data, which is unrelated to which sector regulator licences the entity. Its obligations phase in: the Rules were notified on 13 November 2025, and the breach-intimation duty in Rule 7 together with section 8 of the Act commence on 13 May 2027.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools