Most cybersecurity officers at RBI Regulated Entities can name three or four of the instruments the Reserve Bank has issued on cyber. Fewer can name all ten, in order, with dates. If you cannot, you are advising your Board off out-of-date text.
This lesson gives you the stack in one place. The order is the order RBI issued them. The applicability column tells you which set of entities the instrument binds today, after the 31 July 2026 consolidation for commercial banks.
The ten instruments
| # | Date | Instrument | Applies to (as of Aug 2026) |
|---|---|---|---|
| 1 | 2 Jun 2016 | Cyber Security Framework in Banks [L1-C1] | Continuing baseline for SFBs, PBs, LABs, AIFIs. Superseded for SCBs by the 31 Jul 2026 Directions. |
| 2 | 8 Jun 2017 | IT Framework for the NBFC Sector [L1-C2] | All NBFCs above ₹500 crore asset size. Layered under the 2023 ITGRCA MD for Top / Upper / Middle Layer NBFCs. |
| 3 | 6 Apr 2018 | Storage of Payment System Data [L1-C3] | Every payment-system operator and every entity in the payment ecosystem. |
| 4 | 31 Dec 2019 | Comprehensive Cyber Security Framework for UCBs (Graded) [L1-C4] | All Urban Cooperative Banks, at Level I, II, III or IV depending on size and digital exposure. |
| 5 | 18 Feb 2021 | Master Direction on Digital Payment Security Controls [L1-C5] | SCBs, SFBs, PBs, credit-card-issuing NBFCs. Non-bank PAs reach DPSC indirectly through acquirer bank. |
| 6 | 10 Apr 2023 | Master Direction on Outsourcing of IT Services [L1-C6] | SCBs (ex-RRB), SFBs, PBs, LABs, UCBs, non-scheduled cooperative banks, AIFIs, NBFCs, CICs, EXIM Bank. |
| 7 | 7 Nov 2023 | Master Direction on IT Governance, Risk, Controls and Assurance Practices [L1-C7] | SCBs (ex-RRB, LAB, PB, SFB, Cooperative Banks), Top / Upper / Middle Layer NBFCs, CICs, AIFIs. Effective 1 Apr 2024. |
| 8 | 15 Jul 2024 | Three Master Directions on Fraud Risk Management [L1-C8] | SCBs / AIFIs / SFBs (MD /47); Cooperative Banks (MD /48); NBFCs including HFCs (MD /49). Supersede 36 legacy circulars. |
| 9 | 15 Sep 2025 | Payment Aggregators Directions [L1-C9] | All non-bank Payment Aggregators, in three sub-categories: PA-Physical, PA-Online, PA-Cross Border. |
| 10 | 31 Jul 2026 | Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 [L1-C10] | Commercial banks: SCBs, corresponding new banks, State Bank of India. Excludes SFBs, PBs, LABs, RRBs. |
Three near-adjacent instruments a practitioner must also carry
These three are not RBI cyber instruments in the strict sense but every RBI Regulated Entity carries obligations under them in parallel with the RBI stack. Missing any of them creates the same operational exposure.
- CERT-In Directions 2022 (28 April 2022), effective 27 June 2022
[L1-C11]. Six-hour incident reporting to CERT-In. Log retention 180 days on Indian territory. Time synchronisation to NIC / NPL. - DPDP Rules 2025 notified 13 November 2025
[L1-C12]. Rule 7 requires the Data Fiduciary to intimate the DPDP Board of India of a personal data breach within 72 hours, and to notify each affected Data Principal in plain-language terms without delay. - Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services 2006
[L1-C13]. Twenty years old and still enforced. HDFC Bank was penalised ₹91 lakh in November 2025 under these Guidelines read with the KYC Master Direction. The 2023 IT Outsourcing MD does not supersede these Guidelines; the two run in parallel.
What changed in 2026 that most CISOs have not caught up with
The 31 July 2026 Directions are the biggest change to RBI cyber since 2016. Three practical consequences follow from that Direction:
- Commercial-bank cyber obligations are now in one instrument, not scattered across the 2016 CSF plus subsequent circulars. If your entity is a commercial bank, this is the single instrument that governs day-to-day cyber operations, subject to any parallel obligation under the 2023 IT Outsourcing MD, the 2023 ITGRCA MD, the 2024 Fraud Risk Management MDs and the parallel non-RBI obligations under CERT-In and DPDP.
- DAKSH is the reporting channel, with a codified six-hour clock. Earlier CIMS references and the "immediate" language of the 2016 CSF are superseded for commercial banks. The DAKSH portal is the operational reality now.
- The security-testing floor is explicit: vulnerability assessment every six months, penetration test at least annually for critical internet-facing systems, disaster recovery drills at least half-yearly. If your cadence is looser than any of these three, you are non-compliant on the face of the Directions.
Practical filing rule
Every RBI-related document your team produces (Board deck, ITSC minutes, IS Audit report, incident report, outsourcing contract memo) should cite the specific instrument, reference number and date of every provision it relies on. Being able to say "This obligation flows from paragraph 3 of the 31 July 2026 Commercial Banks Cybersecurity Directions, read with Chapter II of the 7 November 2023 ITGRCA Master Direction" is what separates the CISO from the senior engineer. It also protects you when a CSITE inspection asks the same question a year later.