The 31 July 2026 Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 are the most significant change to commercial-bank cyber since the 2016 Cyber Security Framework [L3-C1]. They consolidate cyber obligations for commercial banks into a single instrument, move incident reporting to the DAKSH portal, and codify a security-testing floor that many banks currently do not meet.
Applicability
The Directions apply to commercial banks. In the applicability text, this means banking companies as defined under Section 5(c) of the Banking Regulation Act 1949, corresponding new banks as defined under Section 5(da) of the same Act, and the State Bank of India constituted under the State Bank of India Act 1955.
The Directions explicitly exclude Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Those entities continue to be governed by their sector-specific instruments (the 2016 CSF as continuing baseline for SFBs, PBs and LABs; RRB-specific Directions for RRBs). This exclusion matters because a common early-2026 mistake in trade press was to describe the Directions as applying to "all banks". They do not.
Five things the Directions changed on the ground
1. Incident reporting: DAKSH within six hours
The Directions codify DAKSH as the reporting portal and mandate a six-hour clock from detection [L3-C2]. This aligns commercial-bank RBI reporting with the parallel CERT-In six-hour clock under the 28 April 2022 Directions [L3-C3]. It supersedes the "immediate" language of the 2016 CSF and the earlier CIMS references for commercial banks. Practical consequence: your incident-response runbook needs to fire DAKSH and CERT-In notifications in parallel from a single incident record.
2. Security-testing floor
The Directions set a security-testing floor: vulnerability assessment every six months, penetration test at least annually for critical internet-facing systems, and disaster recovery drills at least half-yearly. Many banks previously ran annual VA. That is now insufficient. Practical consequence: the ITSC minutes for Q3 2026 onwards need to show the six-monthly VA cadence, or a Board-noted delta with a remediation plan.
3. Board-approved policy suite
Four Board-approved policies are called out explicitly: the IT Policy, the Cybersecurity Policy, the Information Security Policy and the Business Continuity Policy. Annual review is the minimum. The Directions make clear that these four are distinct policies; one composite "IT and Security Policy" does not satisfy the obligation. Practical consequence: if you currently maintain a merged policy, you have to bifurcate before the next Board review cycle.
4. IT Strategy Committee obligations reaffirmed
The Directions reaffirm the Board-level IT Strategy Committee obligation already imposed by the 2023 ITGRCA Master Direction Chapter II [L3-C4]. The two instruments now speak in one voice for commercial banks. The ITSC composition and cadence rules from ITGRCA continue to apply and are reinforced by the 2026 Directions.
5. Effective repeal of the 2016 CSF for commercial banks
The 2016 CSF is superseded for commercial banks. It remains as continuing baseline reference for SFBs, PBs, LABs and (indirectly) for AIFIs on cyber principles until each sub-sector receives its own consolidation. If you advise a commercial bank, treat the 2016 CSF as historical context and read all live obligations off the 31 July 2026 Directions and the 2023 ITGRCA MD.
Verification note
The exact RBI reference number in the RBI/2026-27/xxx format for the 31 July 2026 Directions must be pulled from the rbi.org.in Notifications entry dated 31 July 2026 before quoting in Board papers or filings. Secondary coverage of the Directions in Aug 2026 did not consistently reproduce the reference number. The course flags this in the manual-verification checklist and directs the CISO to the primary source.
What has not changed
Not everything is new. The 2023 IT Outsourcing Master Direction continues to apply to commercial banks unchanged. The 2006 Financial Services Outsourcing Guidelines continue to apply and continue to be enforced (see the HDFC Bank November 2025 penalty). The 2024 Fraud Risk Management Master Direction /47 (for SCBs, AIFIs and SFBs) applies unchanged and covers the Early Warning Signal framework and Red-Flagged Account seven-day reporting. The 2018 Payment Data Storage Direction continues to apply to every commercial bank that operates a payment system.
The trap: because the 31 July 2026 Directions are the biggest change, teams sometimes assume they replace everything else in the RBI cyber stack for commercial banks. They do not. They consolidate cyber obligations. Governance, outsourcing, fraud and payment-data obligations continue under their own instruments.
The 90-day action list for a commercial-bank CISO
- Pull the exact reference number of the 31 July 2026 Directions from rbi.org.in and cite it in the next ITSC pack.
- Bifurcate any composite IT and Security Policy into the four distinct policies called out in the Directions.
- Move to six-monthly VA cadence and half-yearly DR drills; if not achievable in Q3 2026, note the delta with a plan to the ITSC.
- Update the incident-response runbook to fire DAKSH and CERT-In in parallel from a single incident record with the six-hour clock as the operative deadline.
- Retire CIMS from any current reporting documentation; reference DAKSH instead.
- Retire the 2016 CSF from your live compliance register for commercial-bank obligations; retain it as historical context and continue to apply it for any SFB / PB / LAB parts of the group.