Live Founding Cohort open, limited seats remaining Back to main site →

Regulated entity categorisation: the RE perimeter chart

The RBI cyber stack does not treat every Regulated Entity the same way. This lesson lays out the RE perimeter chart: which instruments apply to SCBs, SFBs, PBs, LABs, UCBs, NBFCs by SBR layer, PAs by sub-category, AIFIs, CICs and RRBs. Get this wrong and you either over-comply (waste) or under-comply (enforcement risk).

Free preview 14 min read Verified
Legal basis
RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).

RBI regulates a wide set of entity types under different statutory heads. A Scheduled Commercial Bank sits under Section 35A of the Banking Regulation Act 1949. An NBFC sits under Section 45L of the RBI Act 1934. A Payment Aggregator sits under the Payment and Settlement Systems Act 2007. The cyber obligations layer differently on each.

The RE perimeter chart below tells you exactly which set of instruments applies to your entity today. Read this once, print it, and keep it on your desk.

The RE perimeter chart

RE type 2016 CSF 2019 UCB CSF 2017 NBFC IT Fw 2023 ITGRCA MD 2023 IT Outs MD 2026 CB Cyber
SCBs (PSBs, private, foreign; excluding RRBs)SupersededYes [L2-C1]YesYes [L2-C2]
Small Finance BanksContinuing baselineYesExcluded
Payments BanksContinuing baselineYesExcluded
Local Area BanksContinuing baselineYesExcluded
Regional Rural BanksExcluded historicallyExcludedExcludedExcluded
Urban Cooperative BanksYes at Level I–IV [L2-C3]Yes
Base Layer NBFC (assets < ₹1,000 cr)Yes if assets ≥ ₹500 cr [L2-C4]NoYes
Middle / Upper / Top Layer NBFCYesYes [L2-C5]Yes
All-India Financial InstitutionsBaseline referenceYesYes
Credit Information CompaniesYesYes
Payment AggregatorsIndirect via bank

Read horizontally: pick your row, tick the columns that apply, and you have the compliance perimeter. Read vertically: pick an instrument, and you see every RE type it binds.

Two entity-type edge cases most CISOs get wrong

1. The Regional Rural Bank exception

RRBs are excluded from the 2023 ITGRCA Master Direction on issuance (confirmed by the RBI applicability text of 7 November 2023 [L2-C1]) and remain excluded through August 2026 as no subsequent RBI notification has captured them. RRBs are also excluded from the 31 July 2026 Commercial Banks Cybersecurity Directions, which explicitly cover only SCBs, corresponding new banks and the State Bank of India.

RRBs continue to be governed by RRB-specific Directions issued through 2025 covering Digital Banking Channels Authorisation, Undertaking of Financial Services, Governance, Prudential Norms and Credit / Debit Card Issuance and Conduct. If you advise an RRB, do not treat ITGRCA or the 2026 Directions as applicable; do treat the RRB-specific set as your operative source.

2. The NBFC layer split

The Scale-Based Regulation Framework of 22 October 2021 [L2-C6] puts every NBFC in one of four layers. Base Layer NBFCs sit under the 2017 IT Framework only (and only if asset size is ₹500 crore or above; below that, the 2017 IT Framework asks for proportionate controls but does not apply in full). Middle Layer, Upper Layer and Top Layer NBFCs sit under both the 2017 IT Framework AND the 2023 ITGRCA Master Direction.

The trap: some Middle Layer NBFCs read only the 2023 ITGRCA MD and skip the 2017 IT Framework. That is wrong. Both apply. Where they say the same thing, no problem. Where the 2017 IT Framework asks for something the 2023 ITGRCA does not repeat, you still owe it.

Practical CISO test

Take a sheet of paper. Write your entity type at the top. List the six columns from the chart. Tick every column that applies. Cross-reference against your current compliance register. Any column ticked in the chart but missing from your register is an exposure to fix in the current quarter. Any column missing from the chart but present in your register is either over-compliance or reflects an obligation the chart does not capture (bring it to the ITSC for reconciliation).

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (36 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
RBI ITGRCA Master Direction 2023, ITGRCA Applicability (ITGRCA Master Direction applicability perimeter) L2-C1
RBI Master Direction RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024. Applies to Scheduled Commercial Banks (excluding RRBs, LABs, PBs, SFBs, and Cooperative Banks), Non-Banking Financial Companies in Top, Upper and Middle Layer, Credit Information Companies, and All-India Financial Institutions (NABARD, NHB, EXIM Bank, SIDBI, NaBFID). Does NOT apply to Base Layer NBFCs, RRBs, LABs, PBs, SFBs, or Cooperative Banks. Structures IT governance, third-party arrangements, information and cyber security, business continuity, and IS audit and assurance across five chapters.
RBI CB Cybersecurity Directions 2026, Commercial Banks Cybersecurity 2026 (Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026) L2-C2
RBI Directions dated 31 July 2026 consolidating cyber security obligations for commercial banks into a single instrument. Applies to commercial banks including banking companies, corresponding new banks and the State Bank of India. Excludes Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Reporting obligation for cyber security incidents: DAKSH portal within six hours of detection. Security-testing floor: vulnerability assessment every six months, penetration test annually for critical internet-facing systems, half-yearly disaster recovery drills. Board obligations: approve IT policy, cybersecurity policy, information security policy, and business continuity policy; annual review minimum; Board-level IT Strategy Committee. Effectively supersedes the 2016 CSF for commercial banks. Exact RBI reference number to be verified against the rbi.org.in Notifications entry dated 31 July 2026 before quoting in lesson prose.
RBI UCB Cyber Framework 2019, UCB Graded Framework (Four-level graded cyber framework for UCBs) L2-C3
RBI Circular DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019. Introduces a graded four-level framework for Urban Cooperative Banks. Level I: basic controls applicable to all UCBs regardless of size. Level II: additional controls for UCBs offering digital banking services. Level III: further controls for larger UCBs / those on centralised banking solutions. Level IV: highest control set for UCBs of systemic significance. Each level embeds baseline controls, endpoint protection, network security, application security, VAPT, incident response, and BCP. Live and unamended as of Aug 2026.
RBI NBFC IT Framework 2017, NBFC IT Framework 2017 (IT Framework for the NBFC Sector) L2-C4
RBI Master Direction DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017. Applies to NBFCs with asset size of ₹500 crore or above. Covers IT Governance, IT Policy, Information and Cyber Security, IT Operations, IT Audit, BCP, DR, Outsourcing and Fraud Risk Management. Graded provisions inside the framework distinguish NBFCs above ₹500 crore from those below. Still live in Aug 2026 as the standalone NBFC IT baseline, with the 2023 ITGRCA Master Direction layered on top for Top, Upper and Middle Layer NBFCs under the Scale-Based Regulation framework.
RBI ITGRCA Master Direction 2023, ITSC and CISO (IT Strategy Committee and CISO independence) L2-C5
ITGRCA Chapter II requires every applicable RE to constitute an IT Strategy Committee (ITSC) of the Board, chaired by an independent director, meeting at least once every quarter. The RE must appoint a full-time Chief Information Security Officer (CISO) of sufficient rank and independence, not reporting through the CTO / CIO or Head of IT. The CISO reports to the RE's risk function or directly to the MD/CEO. The RE must also have an IT Steering Committee (management-level) and an Information Security Committee (management-level, chaired by a senior functionary other than the CTO/CIO).
RBI SBR Framework for NBFCs 2021, SBR Layer Mapping (Scale-Based Regulation four-layer NBFC classification) L2-C6
RBI Scale-Based Regulation Framework of 22 October 2021 classifies NBFCs into four layers: Base Layer (BL) for NBFCs with asset size under ₹1,000 crore; Middle Layer (ML) for NBFCs with asset size between ₹1,000 crore and ₹10,000 crore; Upper Layer (UL) for NBFCs identified by RBI as systemically important (typically top 10-15 by scoring methodology); and Top Layer (TL) reserved for NBFCs identified as posing extreme systemic risk. The layer determines which additional RBI instruments apply on top of the 2017 NBFC IT Framework. Base Layer NBFCs sit under the 2017 IT Framework only. Middle, Upper and Top Layer NBFCs sit under both the 2017 IT Framework and the 2023 ITGRCA Master Direction.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The RBI Cyber Stack in 2026
Module 2: IT Governance under the 2023 ITGRCA Master Direction
  • ITGRCA applicability perimeter in detail
  • IT Strategy Committee: composition, cadence, chair independence
  • CISO independence: the reporting line that actually works
  • IS Audit: cadence, charter, and auditor competencies
  • Three management committees that do the actual work
Module 3: The 2026 Commercial Banks Cybersecurity Directions and the 2016 CSF Baseline
  • Reading the 2026 Directions chapter by chapter
  • The 2016 CSF as continuing baseline for non-commercial-bank REs
  • UCB Graded Framework: picking the right level and staying in it
  • The Cyber Security Policy vs the IT Policy: two documents, one Board
  • The security-testing floor: VA every six months, PT annually, DR half-yearly
Module 4: NBFC IT Framework and the ITGRCA Overlay by SBR Layer
  • The 2017 NBFC IT Framework: what it still does
  • SBR layer mapping and the NBFC IT overlay
  • Reconciling apparent conflicts between the 2017 IT Framework and the 2023 ITGRCA MD
  • NBFC-specific enforcement: IIFL Finance and JM Financial Products
  • Proportionality for sub-₹500 crore NBFCs: a documented risk statement, not a licence
Module 5: Payments: DPSC, PA Directions 2025, Payment Data Storage, Digital Payment Authentication 2026
  • The DPSC Master Direction: scope and application
  • The 2025 Payment Aggregators Directions: three sub-categories and one repeal list
  • Payment data storage 2018: end-to-end in India, foreign leg permitted
  • The April 2026 Digital Payment Authentication Framework
  • The payments compliance stack for a non-bank PA: the eight-instrument register
Module 6: IT Outsourcing, Cloud, and Third-Party Risk
  • The 2023 IT Outsourcing Master Direction in one page
  • The 2006 Financial Services Outsourcing Guidelines that HDFC was penalised under
  • Cloud without a standalone cloud framework
  • Vendor-risk playbook: due diligence to exit management
  • Pooled audits of common third-party providers
Module 7: Incident Response, Fraud Reporting, and the Multi-Regulator Parallel Clocks
  • The DAKSH portal: six-hour clock for commercial banks
  • The CERT-In Directions 2022 obligation in practice
  • DPDP Rule 7: the 72-hour clock for personal data breaches
  • The 2024 Fraud Risk Management Master Directions: EWS, RFA, and seven-day reporting
  • The single incident record that satisfies four parallel regulator clocks
  • A worked example: ransomware at a bank-cum-PA that is also NCIIPC-designated
Module 8: FREE-AI, Draft Data Governance, Enforcement Pattern, and Crosswalk Capstone
  • The FREE-AI Framework and Board-level AI governance
  • The 15 July 2026 Draft Data Governance Guidance: reading the direction of travel
  • Reading the 2022-2026 RBI enforcement pattern
  • Crosswalk: RBI stack with SEBI CSCRF, IRDAI 2026 Guidelines, NCIIPC and CERT-In
  • Capstone: end-to-end compliance programme for a multi-regulated RE
Module 9: Final Exam and Certificate