Live Founding Cohort open, limited seats remaining Back to main site →

The 31 July 2026 consolidation: what it changes for commercial banks

On 31 July 2026 the Reserve Bank of India issued the Commercial Banks Cybersecurity Directions, 2026, consolidating commercial-bank cyber into a single instrument. This lesson walks through what changed on the ground, what stayed the same, and what a commercial-bank CISO has to redo in the next quarter.

Free preview 12 min read Verified
Legal basis
RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).

The 31 July 2026 Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 are the most significant change to commercial-bank cyber since the 2016 Cyber Security Framework [L3-C1]. They consolidate cyber obligations for commercial banks into a single instrument, move incident reporting to the DAKSH portal, and codify a security-testing floor that many banks currently do not meet.

Applicability

The Directions apply to commercial banks. In the applicability text, this means banking companies as defined under Section 5(c) of the Banking Regulation Act 1949, corresponding new banks as defined under Section 5(da) of the same Act, and the State Bank of India constituted under the State Bank of India Act 1955.

The Directions explicitly exclude Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Those entities continue to be governed by their sector-specific instruments (the 2016 CSF as continuing baseline for SFBs, PBs and LABs; RRB-specific Directions for RRBs). This exclusion matters because a common early-2026 mistake in trade press was to describe the Directions as applying to "all banks". They do not.

Five things the Directions changed on the ground

1. Incident reporting: DAKSH within six hours

The Directions codify DAKSH as the reporting portal and mandate a six-hour clock from detection [L3-C2]. This aligns commercial-bank RBI reporting with the parallel CERT-In six-hour clock under the 28 April 2022 Directions [L3-C3]. It supersedes the "immediate" language of the 2016 CSF and the earlier CIMS references for commercial banks. Practical consequence: your incident-response runbook needs to fire DAKSH and CERT-In notifications in parallel from a single incident record.

2. Security-testing floor

The Directions set a security-testing floor: vulnerability assessment every six months, penetration test at least annually for critical internet-facing systems, and disaster recovery drills at least half-yearly. Many banks previously ran annual VA. That is now insufficient. Practical consequence: the ITSC minutes for Q3 2026 onwards need to show the six-monthly VA cadence, or a Board-noted delta with a remediation plan.

3. Board-approved policy suite

Four Board-approved policies are called out explicitly: the IT Policy, the Cybersecurity Policy, the Information Security Policy and the Business Continuity Policy. Annual review is the minimum. The Directions make clear that these four are distinct policies; one composite "IT and Security Policy" does not satisfy the obligation. Practical consequence: if you currently maintain a merged policy, you have to bifurcate before the next Board review cycle.

4. IT Strategy Committee obligations reaffirmed

The Directions reaffirm the Board-level IT Strategy Committee obligation already imposed by the 2023 ITGRCA Master Direction Chapter II [L3-C4]. The two instruments now speak in one voice for commercial banks. The ITSC composition and cadence rules from ITGRCA continue to apply and are reinforced by the 2026 Directions.

5. Effective repeal of the 2016 CSF for commercial banks

The 2016 CSF is superseded for commercial banks. It remains as continuing baseline reference for SFBs, PBs, LABs and (indirectly) for AIFIs on cyber principles until each sub-sector receives its own consolidation. If you advise a commercial bank, treat the 2016 CSF as historical context and read all live obligations off the 31 July 2026 Directions and the 2023 ITGRCA MD.

Verification note

The exact RBI reference number in the RBI/2026-27/xxx format for the 31 July 2026 Directions must be pulled from the rbi.org.in Notifications entry dated 31 July 2026 before quoting in Board papers or filings. Secondary coverage of the Directions in Aug 2026 did not consistently reproduce the reference number. The course flags this in the manual-verification checklist and directs the CISO to the primary source.

What has not changed

Not everything is new. The 2023 IT Outsourcing Master Direction continues to apply to commercial banks unchanged. The 2006 Financial Services Outsourcing Guidelines continue to apply and continue to be enforced (see the HDFC Bank November 2025 penalty). The 2024 Fraud Risk Management Master Direction /47 (for SCBs, AIFIs and SFBs) applies unchanged and covers the Early Warning Signal framework and Red-Flagged Account seven-day reporting. The 2018 Payment Data Storage Direction continues to apply to every commercial bank that operates a payment system.

The trap: because the 31 July 2026 Directions are the biggest change, teams sometimes assume they replace everything else in the RBI cyber stack for commercial banks. They do not. They consolidate cyber obligations. Governance, outsourcing, fraud and payment-data obligations continue under their own instruments.

The 90-day action list for a commercial-bank CISO

  1. Pull the exact reference number of the 31 July 2026 Directions from rbi.org.in and cite it in the next ITSC pack.
  2. Bifurcate any composite IT and Security Policy into the four distinct policies called out in the Directions.
  3. Move to six-monthly VA cadence and half-yearly DR drills; if not achievable in Q3 2026, note the delta with a plan to the ITSC.
  4. Update the incident-response runbook to fire DAKSH and CERT-In in parallel from a single incident record with the six-hour clock as the operative deadline.
  5. Retire CIMS from any current reporting documentation; reference DAKSH instead.
  6. Retire the 2016 CSF from your live compliance register for commercial-bank obligations; retain it as historical context and continue to apply it for any SFB / PB / LAB parts of the group.
Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (36 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
RBI CB Cybersecurity Directions 2026, Commercial Banks Cybersecurity 2026 (Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026) L3-C1
RBI Directions dated 31 July 2026 consolidating cyber security obligations for commercial banks into a single instrument. Applies to commercial banks including banking companies, corresponding new banks and the State Bank of India. Excludes Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Reporting obligation for cyber security incidents: DAKSH portal within six hours of detection. Security-testing floor: vulnerability assessment every six months, penetration test annually for critical internet-facing systems, half-yearly disaster recovery drills. Board obligations: approve IT policy, cybersecurity policy, information security policy, and business continuity policy; annual review minimum; Board-level IT Strategy Committee. Effectively supersedes the 2016 CSF for commercial banks. Exact RBI reference number to be verified against the rbi.org.in Notifications entry dated 31 July 2026 before quoting in lesson prose.
RBI DAKSH Portal, DAKSH Portal (DAKSH cyber incident reporting portal) L3-C2
DAKSH (Reserve Bank's Advanced Supervisory Monitoring System) is RBI's web-based end-to-end workflow application launched October 2022. Used by RBI to receive cyber security incident reports from supervised entities and to conduct compliance monitoring. The 31 July 2026 Commercial Banks Cybersecurity Directions codify DAKSH as the reporting channel with a six-hour clock. Earlier references to CIMS in some 2020-2024 material are superseded by DAKSH for cyber incident reporting.
CERT-In Directions 2022, CERT-In 6-hour Rule (CERT-In Directions 2022 six-hour incident reporting) L3-C3
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
RBI ITGRCA Master Direction 2023, ITSC and CISO (IT Strategy Committee and CISO independence) L3-C4
ITGRCA Chapter II requires every applicable RE to constitute an IT Strategy Committee (ITSC) of the Board, chaired by an independent director, meeting at least once every quarter. The RE must appoint a full-time Chief Information Security Officer (CISO) of sufficient rank and independence, not reporting through the CTO / CIO or Head of IT. The CISO reports to the RE's risk function or directly to the MD/CEO. The RE must also have an IT Steering Committee (management-level) and an Information Security Committee (management-level, chaired by a senior functionary other than the CTO/CIO).
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The RBI Cyber Stack in 2026
Module 2: IT Governance under the 2023 ITGRCA Master Direction
  • ITGRCA applicability perimeter in detail
  • IT Strategy Committee: composition, cadence, chair independence
  • CISO independence: the reporting line that actually works
  • IS Audit: cadence, charter, and auditor competencies
  • Three management committees that do the actual work
Module 3: The 2026 Commercial Banks Cybersecurity Directions and the 2016 CSF Baseline
  • Reading the 2026 Directions chapter by chapter
  • The 2016 CSF as continuing baseline for non-commercial-bank REs
  • UCB Graded Framework: picking the right level and staying in it
  • The Cyber Security Policy vs the IT Policy: two documents, one Board
  • The security-testing floor: VA every six months, PT annually, DR half-yearly
Module 4: NBFC IT Framework and the ITGRCA Overlay by SBR Layer
  • The 2017 NBFC IT Framework: what it still does
  • SBR layer mapping and the NBFC IT overlay
  • Reconciling apparent conflicts between the 2017 IT Framework and the 2023 ITGRCA MD
  • NBFC-specific enforcement: IIFL Finance and JM Financial Products
  • Proportionality for sub-₹500 crore NBFCs: a documented risk statement, not a licence
Module 5: Payments: DPSC, PA Directions 2025, Payment Data Storage, Digital Payment Authentication 2026
  • The DPSC Master Direction: scope and application
  • The 2025 Payment Aggregators Directions: three sub-categories and one repeal list
  • Payment data storage 2018: end-to-end in India, foreign leg permitted
  • The April 2026 Digital Payment Authentication Framework
  • The payments compliance stack for a non-bank PA: the eight-instrument register
Module 6: IT Outsourcing, Cloud, and Third-Party Risk
  • The 2023 IT Outsourcing Master Direction in one page
  • The 2006 Financial Services Outsourcing Guidelines that HDFC was penalised under
  • Cloud without a standalone cloud framework
  • Vendor-risk playbook: due diligence to exit management
  • Pooled audits of common third-party providers
Module 7: Incident Response, Fraud Reporting, and the Multi-Regulator Parallel Clocks
  • The DAKSH portal: six-hour clock for commercial banks
  • The CERT-In Directions 2022 obligation in practice
  • DPDP Rule 7: the 72-hour clock for personal data breaches
  • The 2024 Fraud Risk Management Master Directions: EWS, RFA, and seven-day reporting
  • The single incident record that satisfies four parallel regulator clocks
  • A worked example: ransomware at a bank-cum-PA that is also NCIIPC-designated
Module 8: FREE-AI, Draft Data Governance, Enforcement Pattern, and Crosswalk Capstone
  • The FREE-AI Framework and Board-level AI governance
  • The 15 July 2026 Draft Data Governance Guidance: reading the direction of travel
  • Reading the 2022-2026 RBI enforcement pattern
  • Crosswalk: RBI stack with SEBI CSCRF, IRDAI 2026 Guidelines, NCIIPC and CERT-In
  • Capstone: end-to-end compliance programme for a multi-regulated RE
Module 9: Final Exam and Certificate