Which Indian cyber security regulation applies to you
Route from your entity class to the instrument that actually governs it, including which of the seven RBI Directions of 31 July 2026 binds you and the two classes that have none.
Find your instrument
Pick your entity class. Every instrument shown links to the issuing regulator's own notification, and carries the trap most often hit when citing it.
| Instrument | Reference | Why it applies |
|---|---|---|
| CERT-In Directions, 2022CERT-In | No. 20(3)/2022-CERT-In28 April 2022 | The CERT-In Directions bind service providers, intermediaries, data centres, body corporates and Government organisations — which reaches almost every Indian entity operating IT systems.A sectoral filing never discharges the CERT-In obligation. They are separate filings on separate channels. |
| Commercial BanksRBI | RBI/DoS/2026-27/41031 July 2026 | One of the seven Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions issued on 31 July 2026 — this is the one for a commercial bank.The paragraph numbers differ between the seven instruments. Quote the number from this one, not from the Commercial Banks Directions. |
| RBI outsourcing Directions, 2025RBI | RBI/DOR/2025-26/17128 November 2025 | Vendor and outsourcing governance sits in its own instrument. The 2026 cyber Directions expressly preserve it rather than absorbing it.RBI 2026 cyber and RBI 2025 outsourcing are separate tracks. Where an incident originates at a service provider, both are in play. |
| DPDP Rules, 2025MeitY | G.S.R. 846(E)13 November 2025 | A Data Fiduciary is anyone determining the purpose and means of processing digital personal data, which is orthogonal to sector and can bind alongside any of the above.Next date — 13 May 2027: Full compliance with the Rules.Phased. The breach-intimation duty in Rule 7, and section 8 of the Act, commence on 13 May 2027 — plan against them, but there is no DPDP breach clock running today. |
Indicative, and not a determination that any instrument applies. Applicability is entity-specific and belongs to your compliance and legal team. Every link goes to the issuing regulator's own notification.
Take this away as an obligation map
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Where instruments run together
The instruments are cumulative. A filing under one never discharges another, and three overlaps catch people out.
- Cyber and outsourcing are separate tracks. The 2026 cyber Directions expressly preserve the Managing Risks in Outsourcing Directions, 2025 rather than absorbing them. Where an incident originates at a service provider, both are live.
- Listing obligations reach beyond the financial sector. A listed manufacturer with no financial-sector regulator still owes SEBI LODR disclosure on a material cyber incident.
- DPDP is orthogonal to sector. A Data Fiduciary is anyone determining the purpose and means of processing digital personal data. Its obligations phase in to 13 May 2027 and sit alongside, not instead of, the sectoral instruments.
Once you know which instruments bind you, work out what an incident would cost you in hours with the incident reporting clock, or read the full guide to cyber security regulations in India.
This tool is indicative and is not a determination that any instrument applies. Applicability is entity-specific and belongs to your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- Do the RBI Cybersecurity Directions, 2026 apply to every RBI regulated entity?
- No. The RBI issued seven parallel Directions on 31 July 2026, one per entity class — commercial banks at 410, Small Finance Banks 419, Payments Banks 428, Urban Co-operative Banks 437, All India Financial Institutions 456, NBFCs 461 and Credit Information Companies 470. Regional Rural Banks and Local Area Banks have no instrument in the family at all, and the Commercial Banks Directions must not be stretched to cover either.
- Do the 2026 RBI cyber Directions replace the outsourcing rules?
- No. Vendor and outsourcing governance remains in the RBI Directions on Managing Risks in Outsourcing, 2025, which the 2026 cyber Directions expressly preserve and carve around rather than absorb. They are separate tracks, and where an incident originates at a service provider both are in play at once.
- Can more than one Indian cyber security regulation apply at the same time?
- Routinely. A listed private-sector bank holding customer personal data answers to CERT-In, to its own RBI Directions, to the stock exchanges under LODR, and in due course to the DPDP regime — on different clocks, to different recipients, in different formats, from the same triggering event. The instruments are cumulative, and a filing under one never discharges another.
- Does the DPDP Act apply alongside sectoral cyber security regulation?
- Yes, and orthogonally. A Data Fiduciary is anyone determining the purpose and means of processing digital personal data, which is unrelated to which sector regulator licences the entity. Its obligations phase in: the Rules were notified on 13 November 2025, and the breach-intimation duty in Rule 7 together with section 8 of the Act commence on 13 May 2027.