RBI regulates a wide set of entity types under different statutory heads. A Scheduled Commercial Bank sits under Section 35A of the Banking Regulation Act 1949. An NBFC sits under Section 45L of the RBI Act 1934. A Payment Aggregator sits under the Payment and Settlement Systems Act 2007. The cyber obligations layer differently on each.
The RE perimeter chart below tells you exactly which set of instruments applies to your entity today. Read this once, print it, and keep it on your desk.
The RE perimeter chart
| RE type | 2016 CSF | 2019 UCB CSF | 2017 NBFC IT Fw | 2023 ITGRCA MD | 2023 IT Outs MD | 2026 CB Cyber |
|---|---|---|---|---|---|---|
| SCBs (PSBs, private, foreign; excluding RRBs) | Superseded | — | — | Yes [L2-C1] | Yes | Yes [L2-C2] |
| Small Finance Banks | Continuing baseline | — | — | — | Yes | Excluded |
| Payments Banks | Continuing baseline | — | — | — | Yes | Excluded |
| Local Area Banks | Continuing baseline | — | — | — | Yes | Excluded |
| Regional Rural Banks | Excluded historically | — | — | Excluded | Excluded | Excluded |
| Urban Cooperative Banks | — | Yes at Level I–IV [L2-C3] | — | — | Yes | — |
| Base Layer NBFC (assets < ₹1,000 cr) | — | — | Yes if assets ≥ ₹500 cr [L2-C4] | No | Yes | — |
| Middle / Upper / Top Layer NBFC | — | — | Yes | Yes [L2-C5] | Yes | — |
| All-India Financial Institutions | Baseline reference | — | — | Yes | Yes | — |
| Credit Information Companies | — | — | — | Yes | Yes | — |
| Payment Aggregators | — | — | — | — | Indirect via bank | — |
Read horizontally: pick your row, tick the columns that apply, and you have the compliance perimeter. Read vertically: pick an instrument, and you see every RE type it binds.
Two entity-type edge cases most CISOs get wrong
1. The Regional Rural Bank exception
RRBs are excluded from the 2023 ITGRCA Master Direction on issuance (confirmed by the RBI applicability text of 7 November 2023 [L2-C1]) and remain excluded through August 2026 as no subsequent RBI notification has captured them. RRBs are also excluded from the 31 July 2026 Commercial Banks Cybersecurity Directions, which explicitly cover only SCBs, corresponding new banks and the State Bank of India.
RRBs continue to be governed by RRB-specific Directions issued through 2025 covering Digital Banking Channels Authorisation, Undertaking of Financial Services, Governance, Prudential Norms and Credit / Debit Card Issuance and Conduct. If you advise an RRB, do not treat ITGRCA or the 2026 Directions as applicable; do treat the RRB-specific set as your operative source.
2. The NBFC layer split
The Scale-Based Regulation Framework of 22 October 2021 [L2-C6] puts every NBFC in one of four layers. Base Layer NBFCs sit under the 2017 IT Framework only (and only if asset size is ₹500 crore or above; below that, the 2017 IT Framework asks for proportionate controls but does not apply in full). Middle Layer, Upper Layer and Top Layer NBFCs sit under both the 2017 IT Framework AND the 2023 ITGRCA Master Direction.
The trap: some Middle Layer NBFCs read only the 2023 ITGRCA MD and skip the 2017 IT Framework. That is wrong. Both apply. Where they say the same thing, no problem. Where the 2017 IT Framework asks for something the 2023 ITGRCA does not repeat, you still owe it.
Practical CISO test
Take a sheet of paper. Write your entity type at the top. List the six columns from the chart. Tick every column that applies. Cross-reference against your current compliance register. Any column ticked in the chart but missing from your register is an exposure to fix in the current quarter. Any column missing from the chart but present in your register is either over-compliance or reflects an obligation the chart does not capture (bring it to the ITSC for reconciliation).