RBI Cybersecurity Directions 2026: What Changed and What Banks & NBFCs Must Do
On 31 July 2026 the Reserve Bank of India did something it rarely does: it repealed its two foundational technology instruments at once. The 2016 Cyber Security Framework in Banks and the November 2023 Master Direction on IT Governance, Risk, Controls and Assurance Practices — the documents every Indian bank and most NBFCs have run their security programmes against — were withdrawn the same day and replaced by a single, consolidated framework. There was no transition window. If you are a regulated entity, the rulebook you were complying with yesterday is no longer the one you are measured against today.
The replacement is the RBI (Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. This is a plain-English guide to what actually changed, what is genuinely new versus carried forward, who it binds, and what a bank or NBFC should do in the first 90 days.
What exactly changed on 31 July 2026
The change is a repeal-and-consolidate, not an amendment. The 2016 Cyber Security Framework, the 2023 IT Governance Master Direction and roughly 626 other circulars ceased to have effect and were folded into one framework. Three things make this different from a routine update:
- It took effect immediately. The Directions commenced on issuance with no glide path and no phased dates. Action already taken under the old instruments stays governed by them, and approvals already granted carry over — but new obligations apply now.
- It is entity-specific. Instead of one circular for banks and scattered directions for everyone else, RBI issued separate Directions under one common title for commercial banks (RBI/DoS/2026-27/410), small finance banks, payments banks, urban co-operative banks, all-India financial institutions, NBFCs and credit information companies.
- It is consolidated. IT governance and cyber security — previously split across the 2016 framework and the 2023 Master Direction — now sit in a single document per entity type, alongside baseline controls, the Cyber Security Operations Centre, resilience and Information Systems audit.
What is genuinely new (not just carried forward)
Much of the 2026 framework carries forward the DNA of the earlier instruments — board accountability, a baseline of mandatory controls, VAPT, incident reporting and IS audit. But several requirements are sharper or new, and these are where most entities have real work to do:
| Area | What the 2026 Directions now require |
|---|---|
| Cyber Security Operations Centre | A 24x7 C-SOC with SIEM-based log collection and correlation and tiered L1/L2/L3 staffing — an explicit, structured requirement, not merely 'continuous surveillance'. |
| CISO independence | An independent Chief Information Security Officer of General Manager rank, with no reporting line to the Head of IT and no business targets, reporting to the Board. |
| Incident reporting | Cyber incidents reported to the RBI on the DAKSH platform within six hours of detection, with CERT-In notification. |
| Testing cadence | Vulnerability assessment at least every six months and penetration testing at least annually for critical and internet-facing systems, by independent, competent assessors. |
| Board ownership | An IT Strategy Committee of the Board that meets at least quarterly and approves the cyber strategy at least annually, with board-level training. |
| Resilience testing | Disaster-recovery drills for critical information systems at least half-yearly, against defined RTO/RPO. |
The single most common gap we expect to see is the C-SOC: many entities monitor during business hours, or outsource monitoring without the tiered structure and SIEM correlation the Directions now expect. Close behind are CISO independence (the CISO still reporting into the Head of IT) and the ability to actually report an incident within the six-hour DAKSH clock.
Who it applies to
The framework binds the full universe of RBI-regulated entities, each under its own entity-specific Direction, proportioned to the entity's category, scale and digital footprint:
- Commercial banks — including the State Bank of India and corresponding new banks; foreign banks may follow a comply-or-explain approach on certain chapters.
- Small finance banks and payments banks — under their own entity-specific Directions.
- Urban co-operative banks — calibrated to tier and digital footprint.
- NBFCs — calibrated to the layer under scale-based regulation (Base, Middle, Upper, Top). This replaces the IT-governance obligations NBFCs carried under the 2023 Master Direction and, earlier, the 2017 NBFC IT Framework.
- All-India financial institutions — EXIM Bank, NABARD, NaBFID, NHB and SIDBI.
- Credit information companies.
Does our 2016 / 2023 compliance work still count?
Largely yes — but not automatically. The governance architecture you built to the 2023 Master Direction (the IT Strategy Committee, an independent CISO, the risk framework, the IS-audit function) and the baseline controls you implemented for the 2016 framework transfer into the 2026 regime. What you cannot do is assume your existing posture is compliant. Your policies, control mappings and evidence reference instruments that no longer exist, and they must be re-mapped to the applicable 2026 Direction and extended to its sharper requirements — the mandatory 24x7 C-SOC, CISO independence at GM rank, the six-hour DAKSH runbook, the VA/PT cadence and the half-yearly DR drills. Treat it as a gap assessment against a new baseline, not a paperwork refresh.
What to do in the first 90 days
- Identify your entity-specific Direction and read it against your current posture — the obligations differ by entity type.
- Run a gap assessment focused on the 2026 additions: C-SOC coverage and structure, CISO independence and rank, the six-hour DAKSH reporting capability, VA/PT cadence, and DR-drill frequency.
- Fix the CISO reporting line first if it runs through the Head of IT — it is the cheapest, most-cited finding to close.
- Build and test the six-hour incident-reporting runbook on DAKSH; prove you can detect, triage and report inside the clock.
- Confirm the IT Strategy Committee is actually meeting quarterly and has approved the cyber strategy; schedule board training.
- Re-map policies and evidence from the repealed instruments to the applicable 2026 Direction, and schedule the independent IS audit.
Frequently asked questions
FAQs
Is the 2016 RBI Cyber Security Framework still in force?
No. It was repealed on 31 July 2026 and replaced, together with the 2023 IT Governance Master Direction, by the entity-specific RBI (Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, which took effect immediately with no transition window.
Is there a transition period to comply with the 2026 Directions?
No. The Directions commenced on issuance with no glide path. Action already taken under the repealed instruments remains governed by them, and existing approvals carry over, but the new obligations apply now.
What are the biggest new requirements?
A mandatory 24x7 Cyber Security Operations Centre with SIEM and tiered staffing; an independent CISO of GM rank with no reporting line to the Head of IT; six-hour incident reporting to RBI on the DAKSH platform; vulnerability assessment at least six-monthly and penetration testing at least annually for critical and internet-facing systems; and half-yearly DR drills for critical systems.
Do the Directions apply to NBFCs?
Yes. RBI issued an NBFC-specific Direction, calibrated to the NBFC's layer under scale-based regulation. It replaces the IT and cyber obligations NBFCs held under the 2023 Master Direction and the earlier 2017 NBFC IT Framework.
Who can perform the VAPT and IS audit?
Independent, competent assessors — ideally CERT-In empanelled. The Information Systems audit should be independent of IT operations and report to the Audit Committee of the Board, with findings tracked to closure.
The bottom line
The 2026 Directions are not a tweak — they retire the instruments Indian banks and NBFCs have run on for a decade and replace them, immediately, with a tougher, consolidated, entity-specific framework. The governance you already have mostly transfers, but the 24x7 C-SOC, CISO independence, six-hour DAKSH reporting and the testing and DR cadences are where posture must genuinely change. For a control-by-control breakdown, see our guides to the RBI cyber security framework and RBI IT governance requirements. CyberSigma is CERT-In empanelled and runs the gap assessment, C-SOC review, mandated VA/PT, DAKSH runbook and independent IS audit against the applicable 2026 Direction for your entity type. Book a free scope review to find where you stand.
Liked the post? Share on:




Leave A Comment