Live Founding Cohort open, limited seats remaining Back to main site →
Cybersecurity

RBI Cybersecurity Framework Practitioner Certification

The 2016 CSF, the 2023 ITGRCA, the 2026 Commercial Banks Directions, and every RBI incident-clock a CISO has to hit

₹9,999 Advanced 8.5 hours 9 modules Founding Cohort: 836 seats left
Founding Cohort, DPDP Class of 2026. The first 1,000 learners to pass the final exam receive a permanent "Founding #N" badge on their certificate. 836 seats remaining.
9
Modules
40
Lessons
40
Exam questions
75%
Pass mark

A citation-anchored, exam-backed practitioner course on the RBI Cybersecurity Framework as it stands on 10 August 2026. Reads the full RBI cyber stack as one coherent regime: the 2 June 2016 Cyber Security Framework in Banks, the 8 June 2017 IT Framework for the NBFC Sector, the 31 December 2019 Comprehensive Cyber Security Framework for UCBs (graded four-level), the 6 April 2018 Storage of Payment System Data Direction, the 18 February 2021 Master Direction on Digital Payment Security Controls, the 10 April 2023 Master Direction on Outsourcing of IT Services, the 7 November 2023 Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective 1 April 2024), the 15 July 2024 three Master Directions on Fraud Risk Management, the 15 September 2025 Payment Aggregators Directions (RBI/DPSS/2025-26/141), and the cornerstone 31 July 2026 Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions that consolidate commercial-bank cyber into a single instrument and codify DAKSH-based 6-hour reporting. Includes the 13 August 2025 FREE-AI Framework, the April 2026 Digital Payment Authentication Framework, and the 15 July 2026 Draft Data Governance Guidance still in consultation. Cross-checked against the parallel CERT-In Directions 2022, DPDP Rules 2025 Rule 7, NCIIPC Protected System designations, IT Act 2000 Section 70B, Banking Regulation Act 1949 Section 35A, and RBI Act 1934 Section 45L.

Built for the senior CISO, Head of IT Risk, Head of Cyber Compliance, in-house counsel, and Big 4 associate at an RBI Regulated Entity. Every module ships with practitioner artefacts including the RE-perimeter chart (which instrument applies to which bank / NBFC / PA layer), the ITGRCA governance rhythm, the six-hour DAKSH template, and the enforcement pattern for 2022-2026 built from the Kotak Mahindra Bank, IIFL Finance, JM Financial Products, HDFC Bank, and Axis Bank cases.

What you will learn
  • Read the full RBI cyber stack (2016 CSF through 31 July 2026 Commercial Banks Directions) as one coherent regime
  • Determine which set of instruments applies to a given RE by category (SCB, SFB, PB, UCB, NBFC layer, PA sub-category, AIFI, CIC, RRB)
  • Apply the 2023 ITGRCA Master Direction — IT Strategy Committee, CISO independence, IS Audit cadence, third-party arrangements
  • Operate the 2016 CSF and 2019 UCB Graded CSF as continuing baselines for non-commercial-bank REs
  • File a cyber security incident report through the DAKSH portal within six hours, satisfying the 31 July 2026 Directions
  • Reconcile RBI reporting obligations with the parallel CERT-In 6-hour clock and DPDP Board 72-hour clock in a single incident record
  • Structure IT outsourcing and cloud arrangements that satisfy the 2023 IT Outsourcing MD, the 2006 Financial Services Outsourcing Guidelines, and the ITGRCA overlay
  • Design an NBFC IT governance programme that satisfies the 2017 NBFC IT Framework AND the ITGRCA overlay for Top / Upper / Middle Layer NBFCs
  • Operationalise the FREE-AI Framework at Board level pending future binding RBI notifications
  • Prepare a Board Technology / IT Strategy Committee agenda that satisfies both RBI cadence and Audit Committee scrutiny
  • Anticipate RBI enforcement risk based on the 2022-2026 pattern (Kotak, IIFL, JM, HDFC, Axis)
Prerequisites
  • Working experience as a CISO, Head of Cyber, Head of IT Risk, senior IT audit lead, in-house counsel or Big 4 associate at an RBI-supervised entity — 6+ years in an information security or banking-technology context recommended
  • Familiarity with an information security framework (NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8) or equivalent operational experience
  • Working knowledge of the CERT-In Directions 2022 and DPDP Rules 2025 (both are separately covered as free or paid courses on dcomply Academy)
Who this is for
  • Chief Information Security Officers at Scheduled Commercial Banks (public sector, private sector, foreign banks)
  • CISOs at Small Finance Banks, Payments Banks, and Local Area Banks
  • CISOs and Heads of IT at Urban Cooperative Banks and District Central Cooperative Banks
  • Heads of IT / Cyber at NBFCs across Base, Middle, Upper and Top Layers under the Scale-Based Regulation framework
  • Heads of Cyber and Data Protection Officers at Payment Aggregators (PA-Physical, PA-Online, PA-Cross Border) and Payment System Providers
  • CISOs at All-India Financial Institutions (NABARD, NHB, EXIM Bank, SIDBI, NaBFID)
  • Chief Compliance Officers at RBI Regulated Entities coordinating cyber compliance with the compliance function
  • In-house counsel advising banks, NBFCs and PAs on RBI cyber obligations
  • CERT-In empanelled Information Security auditors engaging RBI Regulated Entities
  • Big 4 and MSSP consultants working on RBI RE cyber compliance mandates
  • IT Strategy Committee and Board Audit Committee members at RBI Regulated Entities
About the author
dA
dcomply Academy
Course authored by the dcomply Cyber Practice

This course is authored institutionally by the dcomply Cyber Practice. RBI cyber compliance is prudential regulation, not Cyber Law practice in the strict sense that would sit inside an individual advocate's practice areas. The course is built for senior professionals at RBI Regulated Entities: CISOs, Heads of IT Risk, Heads of Cyber Compliance, in-house counsel, and Big 4 associates who advise banks, NBFCs and payment aggregators. It assumes 6+ years of information security or banking-IT audit background and does not spend time on foundational infosec material.

Every substantive claim is anchored to a primary RBI instrument, adjacent regulator instrument, or RBI press release. Where a specific circular reference number or verbatim paragraph could not be pulled from rbi.org.in via open web at the time of authoring, the lesson flags this explicitly and directs the practitioner to the RBI Notifications or Press Releases page for the exact text.

No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 75%.
Curriculum

Syllabus

9 modules, 40 lessons. Click any module to expand.

The full RBI cyber stack in the order a CISO reads it, from the 2016 Cyber Security Framework through the 31 July 2026 Commercial Banks Cybersecurity Directions. RE categorisation across SCBs, SFBs, PBs, UCBs, NBFCs by SBR layer, PAs, AIFIs and RRBs, and which instrument applies to which entity today. The RE-perimeter chart that tells you which set of obligations you actually sit under.

Free preview so senior buyers can validate the depth of the citation-anchoring before purchasing.

  1. 1. The RBI cyber stack in 2026: ten instruments, one regulator 12 min
  2. 2. Regulated entity categorisation: the RE perimeter chart 14 min
  3. 3. The 31 July 2026 consolidation: what it changes for commercial banks 12 min
  4. 4. How to read a CSITE inspection observation 10 min

The 7 November 2023 Master Direction on IT Governance, Risk, Controls and Assurance Practices as it operates in production. Applicability perimeter (SCBs excluding RRBs, LABs, PBs, SFBs, Cooperative Banks; NBFCs in Top, Upper and Middle Layers; CICs; AIFIs). The IT Strategy Committee composition and cadence.

The CISO independence rule (no operational reporting through the CTO / Head of IT). The Information Systems Audit annual cadence. Chapter-by-chapter walkthrough with practitioner examples of how CSITE inspections read against each chapter.

  1. 1. ITGRCA applicability perimeter in detail 10 min
  2. 2. IT Strategy Committee: composition, cadence, chair independence 12 min
  3. 3. CISO independence: the reporting line that actually works 12 min
  4. 4. IS Audit: cadence, charter, and auditor competencies 11 min
  5. 5. Three management committees that do the actual work 10 min

The cornerstone 31 July 2026 Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, and how they consolidate commercial-bank cyber into a single instrument. DAKSH portal as the current reporting channel with the codified six-hour clock. Security-testing floor (six-monthly VA, annual PT, half-yearly DR drills).

Board-approved cyber, information security and business continuity policies with annual review. What of the 2016 CSF now applies only to non-commercial-bank REs (SFBs, PBs, LABs, Cooperative Banks under the 2019 UCB CSF, AIFIs) as continuing baseline. The Cyber Security Policy vs IT Policy distinction that CSITE inspections continue to enforce.

  1. 1. Reading the 2026 Directions chapter by chapter 12 min
  2. 2. The 2016 CSF as continuing baseline for non-commercial-bank REs 10 min
  3. 3. UCB Graded Framework: picking the right level and staying in it 11 min
  4. 4. The Cyber Security Policy vs the IT Policy: two documents, one Board 10 min
  5. 5. The security-testing floor: VA every six months, PT annually, DR half-yearly 11 min

The 8 June 2017 Master Direction on IT Framework for the NBFC Sector, and how the Scale-Based Regulation Framework (22 October 2021) layers ITGRCA on top for Top, Upper and Middle Layer NBFCs. Base Layer NBFCs (asset size below ₹1,000 crore, plus specific NBFC types) sit under the 2017 IT Framework only. Middle Layer, Upper Layer and Top Layer NBFCs sit under both the 2017 IT Framework and the 2023 ITGRCA Master Direction.

Reconciling apparent conflicts across the two instruments. Which of the 2017 IT Framework provisions are the operational floor and which are governance provisions that ITGRCA now supersedes for the overlaid NBFCs.

  1. 1. The 2017 NBFC IT Framework: what it still does 11 min
  2. 2. SBR layer mapping and the NBFC IT overlay 12 min
  3. 3. Reconciling apparent conflicts between the 2017 IT Framework and the 2023 ITGRCA MD 10 min
  4. 4. NBFC-specific enforcement: IIFL Finance and JM Financial Products 10 min
  5. 5. Proportionality for sub-₹500 crore NBFCs: a documented risk statement, not a licence 9 min

The Master Direction on Digital Payment Security Controls (18 February 2021) for SCBs, SFBs, PBs and credit-card-issuing NBFCs. The Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025) creating the three PA sub-categories (PA-Physical, PA-Online, PA-Cross Border). The 6 April 2018 Storage of Payment System Data Direction and the 26 June 2019 FAQ.

The April 2026 Digital Payment Authentication Framework and the Card-on-File Tokenisation regime live from 1 October 2022. The acquirer-bank relay that pulls non-bank PAs into DPSC obligations indirectly. Escrow account, settlement timelines, KYC and Cash Handling for PAs.

Cross-border payments compliance.

  1. 1. The DPSC Master Direction: scope and application 12 min
  2. 2. The 2025 Payment Aggregators Directions: three sub-categories and one repeal list 12 min
  3. 3. Payment data storage 2018: end-to-end in India, foreign leg permitted 11 min
  4. 4. The April 2026 Digital Payment Authentication Framework 10 min
  5. 5. The payments compliance stack for a non-bank PA: the eight-instrument register 9 min

The 10 April 2023 Master Direction on Outsourcing of IT Services (RBI/2023-24/102). The 3 November 2006 Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services that HDFC Bank was penalised under in November 2025. Cloud governance in the absence of a standalone RBI cloud framework, through the 2023 IT Outsourcing MD and the 2023 ITGRCA MD.

IFTAS's Indian Financial Services (IFS) Cloud initiative as a future service option, not a current compliance obligation. Vendor risk playbook: due diligence, minimum contract clauses, audit and inspection rights, sub-contracting rules, business continuity, breach notification, exit management, right of RBI to examine service providers. Material outsourcing test.

  1. 1. The 2023 IT Outsourcing Master Direction in one page 12 min
  2. 2. The 2006 Financial Services Outsourcing Guidelines that HDFC was penalised under 9 min
  3. 3. Cloud without a standalone cloud framework 11 min
  4. 4. Vendor-risk playbook: due diligence to exit management 10 min
  5. 5. Pooled audits of common third-party providers 8 min

The full incident-reporting fan-out an RBI RE has to hit on a cyber incident. RBI DAKSH within six hours under the 31 July 2026 Directions for commercial banks; RBI CSITE reporting continuing for non-commercial-bank REs. Parallel CERT-In reporting within six hours under the 28 April 2022 Directions with log retention of 180 days on Indian territory.

DPDP Board reporting within 72 hours under DPDP Rules 2025 Rule 7. Fraud Risk Management Master Directions of 15 July 2024 (three MDs consolidating 36 legacy circulars): Early Warning Signal framework, Red-Flagged Account reporting within seven days, penal action principles, and Board oversight. Worked example: a ransomware event at a bank-cum-PA that is also NCIIPC-designated, showing every clock and every artefact.

  1. 1. The DAKSH portal: six-hour clock for commercial banks 11 min
  2. 2. The CERT-In Directions 2022 obligation in practice 10 min
  3. 3. DPDP Rule 7: the 72-hour clock for personal data breaches 10 min
  4. 4. The 2024 Fraud Risk Management Master Directions: EWS, RFA, and seven-day reporting 11 min
  5. 5. The single incident record that satisfies four parallel regulator clocks 12 min
  6. 6. A worked example: ransomware at a bank-cum-PA that is also NCIIPC-designated 12 min

The 13 August 2025 FREE-AI Framework Report and how a Regulated Entity should operationalise it at Board level pending future binding RBI notifications. The 15 July 2026 Draft Guidance on Regulatory Expectations for Data Governance, its scope and the consultation close on 17 August 2026. The RBI enforcement pattern 2022-2026 as a working model for CISOs: the Kotak Mahindra Bank supervisory business restrictions of 24 April 2024; the IIFL Finance gold-loan and JM Financial Products IPO-financing restrictions of March 2024; the HDFC Bank penalty of November 2025 that cited a 20-year-old instrument; the FY25 aggregate of 353 penalties totalling ₹54.78 crore.

Single-view crosswalk of the RBI stack with SEBI CSCRF, IRDAI 2026 Cyber Security Guidelines, NCIIPC Protected System obligations, and CERT-In. Capstone: design an end-to-end compliance programme for a mid-size private-sector bank that is also a corporate agent for insurance and holds an ARC subsidiary; identify every applicable instrument and the incident-reporting fan-out; draft the IT Strategy Committee agenda.

  1. 1. The FREE-AI Framework and Board-level AI governance 11 min
  2. 2. The 15 July 2026 Draft Data Governance Guidance: reading the direction of travel 10 min
  3. 3. Reading the 2022-2026 RBI enforcement pattern 11 min
  4. 4. Crosswalk: RBI stack with SEBI CSCRF, IRDAI 2026 Guidelines, NCIIPC and CERT-In 11 min
  5. 5. Capstone: end-to-end compliance programme for a multi-regulated RE 14 min

Final certification exam covering all eight content modules. Every question is anchored to a specific RBI instrument, RBI press release, adjacent regulator instrument, or case study cited in the course. Randomised order, shuffled options, explanations shown after each question cite the source.

Lessons coming soon.

Frequently Asked

Everything a buyer usually asks

Who is this course for?
Chief Information Security Officers at Scheduled Commercial Banks (public sector, private sector, foreign banks) Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 9 modules covering 40 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 75% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹9,999 founding-cohort price (list price ₹24,999) One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme aimed at senior CISO, Head of IT Risk, Head of Cyber Compliance, in-house counsel, and Big 4 associate roles at RBI Regulated Entities. Every substantive claim is anchored to a primary RBI instrument, adjacent regulator instrument, RBI press release, or public disclosure. As of 10 August 2026 the following items require ongoing verification and are flagged inside the relevant lessons: the exact RBI reference number for the 31 July 2026 Commercial Banks Cybersecurity Directions and its formal repeal list against prior instruments; the exact reference number for the April 2026 Digital Payment Authentication Framework; the final notification status of the 15 July 2026 Draft Data Governance Guidance after the 17 August 2026 consultation close; the verbatim paragraphs of the 24 April 2024 Kotak Mahindra Bank supervisory order (currently summarised from press release and secondary reporting); the instrument-level split of RBI's FY25 enforcement totals (available only via RTI to Department of Supervision); the appointment status of the DPDP Board of India Chairperson; and any post-August 2026 RBI notification operationalising the FREE-AI Framework. The course maintains a 15-item CISO manual-verification checklist for these items.

This is not legal advice and does not create a lawyer-client relationship. For specific compliance decisions, consult qualified banking-and-technology counsel or a CERT-In empanelled Information Security auditor.