We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

RBI Cyber Security Framework: A Compliance Guide for REs

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

RBI Cyber Security Framework: A Compliance Guide for REs

Most banks and NBFCs think they are compliant with the RBI cybersecurity framework right up until the examiner asks one question: show me the board minute where your CISO presented the last unusual cyber incident, and show me you reported it to RBI within six hours. The room goes quiet. The policy exists, beautifully bound. The evidence does not.

That gap between having a policy and being able to prove you live it is where almost every RBI cyber audit goes wrong. This guide is about closing it. Not the theory of the framework, but what a regulated entity actually has to produce, on what timeline, and what an examiner does when you cannot.

What the framework actually is and who it binds

When people say the RBI cybersecurity framework they usually mean one specific circular: RBI/2015-16/418 (DBS.CO/CSITE/BC.11/33.01.001/2015-16) dated 2 June 2016, titled Cyber Security Framework in Banks. But that circular is now the floor, not the ceiling. Over the years RBI layered several instruments on top, and which ones bind you depends on what kind of regulated entity (RE) you are.

An RE is any entity RBI regulates: scheduled commercial banks, small finance banks, payments banks, urban co-operative banks, and non-banking financial companies (NBFCs). The rulebook is not one document. It is a stack, and the examiner expects you to know which layers apply to you.

InstrumentWho it bindsWhat it demands
Cyber Security Framework in Banks (June 2016)All scheduled commercial banksBoard-approved policy, baseline controls, CSOC, incident reporting within 2-6 hours
Master Direction on IT Governance, Risk, Controls and Assurance (Nov 2023, effective Apr 2024)Banks, NBFCs, credit info companies, EXIM/NABARD etcIT governance structure, IT strategy committee, risk management, BCP, IS audit
Master Direction on Outsourcing of IT Services (Apr 2023)Banks, NBFCs, co-op banksDue diligence on vendors, right to audit, exit strategy, concentration risk
Cybersecurity framework for UCBs (Dec 2019, graded)Urban co-operative banksBaseline to advanced controls graded by digital depth (Levels I-IV)
Master Direction on Digital Payment Security Controls (Feb 2021)Banks, card issuers, PPI issuersApp security, transaction monitoring, fraud controls, customer protection

The practical mistake is reading only the 2016 circular. If you are an NBFC, your primary obligation now flows from the 2023 IT Governance Master Direction, and your outsourcing obligations from the IT Outsourcing Master Direction. If you issue cards or run a mobile app, the Digital Payment Security Controls direction is where you will actually get hurt in an audit.

The five things RBI actually checks

Strip away the hundreds of individual control points and an RBI cyber inspection is really testing five things. Get these five right and the detailed controls tend to fall into place. Get them wrong and no amount of tooling saves you.

1. A board that actually owns cyber risk

The framework is explicit that cybersecurity is a board and top-management responsibility, not something you delegate to IT and forget. The examiner will ask for the board-approved cybersecurity policy, and crucially it must be distinct from your broader IT policy or information security policy. They are separate documents for a reason. Then they will read the minutes: did the board actually discuss cyber risk, or did it rubber-stamp a policy once and never revisit it?

  • A board-approved Cyber Security Policy, separate from the IT/IS policy, reviewed at least annually
  • A functioning IT Strategy Committee and Risk Management Committee at board level, with cyber on the agenda
  • A designated Chief Information Security Officer (CISO) with a clear reporting line to the board or a board committee, not buried under the CIO
  • Evidence that the CISO briefs the board on the cyber threat landscape and material incidents

2. A control baseline you can evidence

The 2016 circular ships with Annex 1, a baseline of controls every bank must implement regardless of size. This is where inspections spend most of their time, because it is concrete and testable. Annex 1 covers inventory management, network and boundary defences, patch and vulnerability management, user access, secure configuration, application security, anti-malware, data leak prevention, and more. The examiner does not want to hear that you have a firewall. They want the rule base, the change tickets, and the last review date.

Annex 1 control areaWhat the examiner asks to see
Inventory of assetsA live CMDB with owners; unmanaged devices flagged; last reconciliation date
Patch/vulnerability managementVA scan reports, remediation SLAs, ageing of open criticals, exception approvals
User access / PIMAccess review evidence, privileged access logs, joiner-mover-leaver records
Secure configurationHardening baselines mapped to CIS benchmarks, deviation reports
Network securityFirewall rule reviews, network segmentation diagram, IDS/IPS logs
Anti-phishing / DMARCSPF, DKIM, DMARC records for your domains and reject/quarantine policy

3. A Security Operations Centre that is actually watching

The framework requires continuous surveillance through a Cyber Security Operations Centre (C-SOC or SOC). Whether you build it in-house or outsource it, the examiner tests whether it produces outcomes. What is your log source coverage? Are your critical systems and privileged accounts actually feeding the SIEM, or is coverage 40 percent and nobody noticed? When was your last detected-and-contained incident, and what was the mean time to detect?

4. Incident reporting on RBI time, not your time

This is the single control most REs fail. The 2016 framework requires banks to report unusual cybersecurity incidents to RBI within two to six hours of detection. It is not enough to eventually file a report. You must show the detection timestamp, the triage decision, and the report submission timestamp, and the delta must be inside the window. Separately, if you are also a CERT-In constituent, you must report specified incident types to CERT-In within six hours under the CERT-In directions of 28 April 2022. Two clocks, both running, both from the moment of noticing.

5. Independent assurance

You cannot mark your own homework. The framework and the 2023 IT Governance direction require periodic Information Systems (IS) audit and Vulnerability Assessment and Penetration Testing (VAPT). Critically, RBI expects VAPT of internet-facing and critical applications at least annually, and after every material change, conducted by a competent, independent party (in practice, a CERT-In empanelled auditor). The examiner reads the report AND the closure evidence for the findings.

What actually happens in the audit room

Let me give you a concrete scene, because the abstract requirements only make sense once you have watched them play out.

A mid-sized NBFC, roughly 900 crore book, invites us for a pre-inspection readiness review three months before RBI is due. The CISO is confident. The policy binder is immaculate. We ask for the VAPT report on the customer-facing loan app. It exists, dated fourteen months ago. Since then they shipped a new eKYC flow and switched payment gateways. No re-test. That is a finding on its own: the framework requires re-testing after material change, and a new eKYC and gateway is unambiguously material.

Then we ask for the last incident. They had a credential-stuffing wave two months prior. Detected by the SOC at 11:20, escalated internally, remediated by end of day. Good response. We ask for the RBI incident report. Blank stares. Nobody had classified it as an unusual cyber incident, so nothing went to RBI. That is the finding that turns a routine inspection into a supervisory concern, because it signals a governance failure, not just a control gap. Detection worked; the reporting muscle did not exist.

The fix took six weeks: a written incident classification matrix mapping event types to RBI and CERT-In reporting obligations, a two-hour reporting SLA baked into the runbook with a named accountable officer, and a re-test of the app. None of it was expensive. All of it was invisible until someone asked the right question.

The reporting clocks you must not miss

Because timing is where REs get caught, it is worth setting out the clocks side by side. Treat these as hard deadlines, not targets.

TriggerReport toDeadlineGoverning instrument
Unusual cybersecurity incidentRBI (department supervising you)2-6 hours of detectionCyber Security Framework, June 2016
Specified incident types (e.g. targeted scanning, unauthorised access, data breach)CERT-In6 hours of noticingCERT-In Directions, 28 Apr 2022
Material data breach involving personal dataData Protection Board (once DPDP Rules in force)As prescribed by rulesDigital Personal Data Protection Act 2023
Card/payment fraud incidentsRBI / NPCI as applicablePer scheme rulesDigital Payment Security Controls, Feb 2021

One clarification that trips people up: the six-hour CERT-In clock starts when you notice the incident, and CERT-In also requires you to keep logs for 180 days and sync clocks to NPL or NIC time. If your log retention is 90 days, you have a live non-compliance sitting in your infrastructure right now, and it is trivially provable.

NBFCs: the framework tightened and most missed it

For years NBFCs treated the bank framework as somebody else s problem. The 2023 Master Direction on IT Governance, Risk, Controls and Assurance Practices ended that. Effective 1 April 2024, it brought NBFCs (in the middle and upper layers of the scale-based regulation) firmly into scope for board-level IT governance, IT and information security functions, cyber crisis management plans, BCP and DR with defined RTO and RPO, and IS audit.

If you are an NBFC and your last board-approved cyber policy predates April 2024, or you have no independent CISO function, or your IS audit does not exist, you are behind. RBI has been actively inspecting NBFC IT governance since the direction took effect, and this is exactly the low-hanging finding inspectors look for.

What continuous compliance actually costs

REs consistently under-budget for this, then panic-spend before an inspection. Here is a realistic picture for a mid-sized NBFC or small bank, annualised. Figures are indicative ranges and vary with scope and geography.

ActivityFrequencyIndicative cost (INR)
Board-approved policy refresh + gap assessmentAnnual2-6 lakh
VAPT (external + internal + app)Annual + on major change4-12 lakh
IS audit by external firmAnnual5-15 lakh
SOC (outsourced MSSP, mid-tier)Ongoing15-40 lakh/year
CISO + IS team (2-4 FTE)Ongoing40-90 lakh/year
DLP, PIM, SIEM toolingLicences + run10-30 lakh/year

The number that should worry you is not the spend. It is the cost of getting it wrong. A supervisory finding can trigger enhanced monitoring, restrictions on onboarding new digital customers, and in serious cases monetary penalties running from tens of lakhs upward. RBI has levied penalties in the crore range on entities for IT and cyber lapses. The audit is the cheap part.

Five gaps that sink RBI cyber audits

Across readiness reviews, the same five gaps recur. If you fix nothing else this quarter, fix these.

  • No separate board-approved cybersecurity policy, or one that has not been reviewed in over a year
  • Incident reporting that is not wired to the 2-6 hour RBI clock and 6-hour CERT-In clock, with no named accountable officer
  • VAPT that is stale or was never re-run after a material application change
  • SOC log coverage well below 100 percent for critical assets and privileged accounts, with no coverage metric tracked
  • Outsourcing arrangements (cloud, SOC, fintech partners) with no right-to-audit clause and no documented exit strategy, a direct breach of the IT Outsourcing Master Direction

Your fix-it checklist

Turn the above into action. Work through this in order; it is roughly the sequence an examiner would.

  • Confirm which instruments bind you (2016 framework / 2023 IT Governance MD / IT Outsourcing MD / Digital Payment Security Controls / UCB framework) and map each to an owner
  • Produce or refresh a standalone board-approved Cyber Security Policy and table it at the next board meeting with minuted discussion
  • Verify the CISO reports independently of the CIO and briefs the board on threats and incidents at least quarterly
  • Build a written incident classification matrix mapping event types to RBI and CERT-In deadlines, with a named accountable officer and a runbook SLA inside the shortest clock
  • Confirm log retention is at least 180 days and clocks are synced to NPL/NIC time per CERT-In directions
  • Run an independent VAPT on all internet-facing and critical apps now, and set a policy to re-test after every material change
  • Measure SOC log-source coverage as a percentage and drive it toward full coverage of critical and privileged assets
  • Review every IT outsourcing contract for right-to-audit, data localisation, and exit clauses
  • Commission an annual IS audit by an independent, competent firm and track finding closure to completion, not just to report delivery

The point most REs miss

Come back to that silent audit room. The policy was fine. The tooling was fine. What was missing was proof that the organisation lives its controls day to day: the board minute, the six-hour report, the re-test after the change. RBI compliance is not a binder you produce for the inspection. It is an evidence trail you generate continuously, so that whenever the examiner asks, the answer is already sitting there with a timestamp on it.

If you want a candid read on where your evidence trail actually stands before RBI asks, our CERT-In empanelled auditors do this hands-on, in the room, the same way an examiner would. No binder theatre, just the questions that matter and the gaps that would surface.

FAQs

Does the RBI cybersecurity framework apply to NBFCs or only banks?

Both, but through different instruments. The 2016 Cyber Security Framework primarily binds banks. NBFCs in the middle and upper regulatory layers are covered by the Master Direction on IT Governance, Risk, Controls and Assurance Practices, effective 1 April 2024, which brings board-level IT governance, a CISO function, cyber crisis management, BCP/DR and IS audit into scope for them.

How quickly must we report a cyber incident to RBI?

The 2016 framework requires banks to report unusual cybersecurity incidents to RBI within two to six hours of detection. If you are also a CERT-In constituent, specified incident types must additionally be reported to CERT-In within six hours of noticing. Both clocks start from the moment of detection, not from the moment you finish investigating.

How often is VAPT required?

RBI expects Vulnerability Assessment and Penetration Testing of internet-facing and critical applications at least annually, and additionally after every material change such as a new payment gateway or eKYC flow. It should be conducted by a competent, independent party, in practice a CERT-In empanelled auditor, and findings must be closed with evidence, not just documented.

Do we need a separate cybersecurity policy or is our IT policy enough?

You need a separate, board-approved Cyber Security Policy that is distinct from your general IT policy or information security policy. RBI specifically expects it as a standalone document, reviewed at least annually, with the board's discussion recorded in the minutes.

What are the penalties for non-compliance?

Consequences range from supervisory findings and enhanced monitoring to restrictions on onboarding new digital customers and monetary penalties. RBI has imposed penalties running into crores on entities for IT and cyber lapses. Beyond the fine, a governance failure such as an unreported incident can escalate a routine inspection into a broader supervisory concern.

What log retention does the framework require?

Under the CERT-In directions of 28 April 2022, you must retain logs for a rolling 180 days and enable them within Indian jurisdiction, with system clocks synchronised to NPL or NIC time. Many REs still run 90-day retention, which is a provable non-compliance sitting in their infrastructure.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity firm helping Indian businesses with VAPT, ISO 27001, PCI DSS, SOC 2 and DPDP compliance — delivered by senior auditors, not juniors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →