Live Founding Cohort open, limited seats remaining Back to main site →

The RBI cyber stack in 2026: ten instruments, one regulator

A senior CISO at a Regulated Entity is expected to know every instrument in the RBI cyber stack by reference number, date, and applicability. This lesson lists all ten, in issuance order, with the one-line practitioner test for each: which entity does this apply to, and what is the one thing you get penalised for if you get it wrong.

Free preview 12 min read Verified
Legal basis
RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).

Most cybersecurity officers at RBI Regulated Entities can name three or four of the instruments the Reserve Bank has issued on cyber. Fewer can name all ten, in order, with dates. If you cannot, you are advising your Board off out-of-date text.

This lesson gives you the stack in one place. The order is the order RBI issued them. The applicability column tells you which set of entities the instrument binds today, after the 31 July 2026 consolidation for commercial banks.

The ten instruments

#DateInstrumentApplies to (as of Aug 2026)
12 Jun 2016Cyber Security Framework in Banks [L1-C1]Continuing baseline for SFBs, PBs, LABs, AIFIs. Superseded for SCBs by the 31 Jul 2026 Directions.
28 Jun 2017IT Framework for the NBFC Sector [L1-C2]All NBFCs above ₹500 crore asset size. Layered under the 2023 ITGRCA MD for Top / Upper / Middle Layer NBFCs.
36 Apr 2018Storage of Payment System Data [L1-C3]Every payment-system operator and every entity in the payment ecosystem.
431 Dec 2019Comprehensive Cyber Security Framework for UCBs (Graded) [L1-C4]All Urban Cooperative Banks, at Level I, II, III or IV depending on size and digital exposure.
518 Feb 2021Master Direction on Digital Payment Security Controls [L1-C5]SCBs, SFBs, PBs, credit-card-issuing NBFCs. Non-bank PAs reach DPSC indirectly through acquirer bank.
610 Apr 2023Master Direction on Outsourcing of IT Services [L1-C6]SCBs (ex-RRB), SFBs, PBs, LABs, UCBs, non-scheduled cooperative banks, AIFIs, NBFCs, CICs, EXIM Bank.
77 Nov 2023Master Direction on IT Governance, Risk, Controls and Assurance Practices [L1-C7]SCBs (ex-RRB, LAB, PB, SFB, Cooperative Banks), Top / Upper / Middle Layer NBFCs, CICs, AIFIs. Effective 1 Apr 2024.
815 Jul 2024Three Master Directions on Fraud Risk Management [L1-C8]SCBs / AIFIs / SFBs (MD /47); Cooperative Banks (MD /48); NBFCs including HFCs (MD /49). Supersede 36 legacy circulars.
915 Sep 2025Payment Aggregators Directions [L1-C9]All non-bank Payment Aggregators, in three sub-categories: PA-Physical, PA-Online, PA-Cross Border.
1031 Jul 2026Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 [L1-C10]Commercial banks: SCBs, corresponding new banks, State Bank of India. Excludes SFBs, PBs, LABs, RRBs.

Three near-adjacent instruments a practitioner must also carry

These three are not RBI cyber instruments in the strict sense but every RBI Regulated Entity carries obligations under them in parallel with the RBI stack. Missing any of them creates the same operational exposure.

  • CERT-In Directions 2022 (28 April 2022), effective 27 June 2022 [L1-C11]. Six-hour incident reporting to CERT-In. Log retention 180 days on Indian territory. Time synchronisation to NIC / NPL.
  • DPDP Rules 2025 notified 13 November 2025 [L1-C12]. Rule 7 requires the Data Fiduciary to intimate the DPDP Board of India of a personal data breach within 72 hours, and to notify each affected Data Principal in plain-language terms without delay.
  • Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services 2006 [L1-C13]. Twenty years old and still enforced. HDFC Bank was penalised ₹91 lakh in November 2025 under these Guidelines read with the KYC Master Direction. The 2023 IT Outsourcing MD does not supersede these Guidelines; the two run in parallel.

What changed in 2026 that most CISOs have not caught up with

The 31 July 2026 Directions are the biggest change to RBI cyber since 2016. Three practical consequences follow from that Direction:

  1. Commercial-bank cyber obligations are now in one instrument, not scattered across the 2016 CSF plus subsequent circulars. If your entity is a commercial bank, this is the single instrument that governs day-to-day cyber operations, subject to any parallel obligation under the 2023 IT Outsourcing MD, the 2023 ITGRCA MD, the 2024 Fraud Risk Management MDs and the parallel non-RBI obligations under CERT-In and DPDP.
  2. DAKSH is the reporting channel, with a codified six-hour clock. Earlier CIMS references and the "immediate" language of the 2016 CSF are superseded for commercial banks. The DAKSH portal is the operational reality now.
  3. The security-testing floor is explicit: vulnerability assessment every six months, penetration test at least annually for critical internet-facing systems, disaster recovery drills at least half-yearly. If your cadence is looser than any of these three, you are non-compliant on the face of the Directions.

Practical filing rule

Every RBI-related document your team produces (Board deck, ITSC minutes, IS Audit report, incident report, outsourcing contract memo) should cite the specific instrument, reference number and date of every provision it relies on. Being able to say "This obligation flows from paragraph 3 of the 31 July 2026 Commercial Banks Cybersecurity Directions, read with Chapter II of the 7 November 2023 ITGRCA Master Direction" is what separates the CISO from the senior engineer. It also protects you when a CSITE inspection asks the same question a year later.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (36 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
RBI Banks Cyber Framework 2016, Master Circular 2016 (Cyber Security Framework in Banks) L1-C1
RBI Master Circular DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016. First comprehensive RBI cyber circular for commercial banks. Required every bank to have a Board-approved Cyber Security Policy distinct from its IT policy, a Cyber Crisis Management Plan (CCMP) aligned to the National CCMP, cyber risk arrangements with a documented SOC, and CSITE incident reporting through a standard template. Superseded for commercial banks by the 31 July 2026 Commercial Banks Cybersecurity Directions; remains context for non-bank REs until each sub-sector receives its own consolidation.
RBI NBFC IT Framework 2017, NBFC IT Framework 2017 (IT Framework for the NBFC Sector) L1-C2
RBI Master Direction DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017. Applies to NBFCs with asset size of ₹500 crore or above. Covers IT Governance, IT Policy, Information and Cyber Security, IT Operations, IT Audit, BCP, DR, Outsourcing and Fraud Risk Management. Graded provisions inside the framework distinguish NBFCs above ₹500 crore from those below. Still live in Aug 2026 as the standalone NBFC IT baseline, with the 2023 ITGRCA Master Direction layered on top for Top, Upper and Middle Layer NBFCs under the Scale-Based Regulation framework.
RBI Payment Data Storage 2018, Payment Data Localisation (RBI Payment Data Storage Direction 2018) L1-C3
RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-2018 dated 6 April 2018 requires all system providers and their service providers, intermediaries, third-party vendors and other entities in the payment ecosystem to store the entire data relating to payment systems operated by them in a system only in India. Data may be processed abroad but must be brought back to India within one business day or 24 hours of processing, whichever is earlier. For an Indian payment-service provider processing EU cardholder data, GDPR Chapter V transfer rules and RBI Payment Data Storage rules both apply; comply with both by design (typically Indian primary storage plus EU-region processing for the EU leg, both with SCCs where cross-border transfer under GDPR applies).
RBI UCB Cyber Framework 2019, UCB Graded Framework (Four-level graded cyber framework for UCBs) L1-C4
RBI Circular DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019. Introduces a graded four-level framework for Urban Cooperative Banks. Level I: basic controls applicable to all UCBs regardless of size. Level II: additional controls for UCBs offering digital banking services. Level III: further controls for larger UCBs / those on centralised banking solutions. Level IV: highest control set for UCBs of systemic significance. Each level embeds baseline controls, endpoint protection, network security, application security, VAPT, incident response, and BCP. Live and unamended as of Aug 2026.
RBI DPSC Master Direction 2021, DPSC Master Direction (Digital Payment Security Controls Master Direction) L1-C5
RBI Master Direction DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021. Applies to all Scheduled Commercial Banks, Small Finance Banks, Payments Banks and Credit-Card-issuing NBFCs. Sets out common minimum standards of security controls for digital payment products and services including internet banking, mobile banking, card payments, and other digital payment applications. Covers governance, product life-cycle security, authentication, fraud risk management, customer protection, awareness, and incident response. Payment Aggregators that do not issue payment instruments themselves reach DPSC obligations indirectly through their acquirer bank.
RBI IT Outsourcing Master Direction 2023, IT Outsourcing MD 2023 (Master Direction on Outsourcing of IT Services) L1-C6
RBI Master Direction RBI/2023-24/102 dated 10 April 2023. Applies to Scheduled Commercial Banks (excluding RRBs), Small Finance Banks, Payments Banks, Local Area Banks, Primary UCBs, non-scheduled Cooperative Banks, All-India Financial Institutions, NBFCs, Credit Information Companies, and EXIM Bank. Introduces a material outsourcing test, mandatory Board-approved Outsourcing Policy, prior approval for material outsourcing arrangements, minimum contract clauses, right of RBI to examine service providers, exit management planning, and specific rules on IT outsourcing to cloud, offshore, and group entities.
RBI ITGRCA Master Direction 2023, ITGRCA Applicability (ITGRCA Master Direction applicability perimeter) L1-C7
RBI Master Direction RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024. Applies to Scheduled Commercial Banks (excluding RRBs, LABs, PBs, SFBs, and Cooperative Banks), Non-Banking Financial Companies in Top, Upper and Middle Layer, Credit Information Companies, and All-India Financial Institutions (NABARD, NHB, EXIM Bank, SIDBI, NaBFID). Does NOT apply to Base Layer NBFCs, RRBs, LABs, PBs, SFBs, or Cooperative Banks. Structures IT governance, third-party arrangements, information and cyber security, business continuity, and IS audit and assurance across five chapters.
RBI Fraud Risk Management MDs 2024, FRM MDs Consolidation (Three FRM Master Directions supersede 36 legacy circulars) L1-C8
RBI Master Directions RBI/2024-25/47, /48 and /49 issued 15 July 2024. Three separate Master Directions for (a) Scheduled Commercial Banks, All-India Financial Institutions and Small Finance Banks; (b) Cooperative Banks (UCBs, StCBs, CCBs); (c) NBFCs (including HFCs). Consolidates and supersedes 36 earlier fraud-related circulars and directions. Introduces Early Warning Signal (EWS) framework, Red-Flagged Account (RFA) 7-day reporting, RE Board oversight requirements, and updated fraud reporting formats.
RBI PA Directions 2025, PA Directions 2025 (Consolidated Payment Aggregators Directions) L1-C9
RBI Directions RBI/DPSS/2025-26/141 dated 15 September 2025. Repeals the 17 March 2020 PA-PG Guidelines, the 31 March 2021 clarifications, and the October 2023 PA-Cross Border Directions. Creates three PA sub-categories: PA-Physical (offline), PA-Online, and PA-Cross Border. Sets minimum net-worth thresholds, KYC obligations, escrow account maintenance, settlement timelines, and data-storage obligations for each sub-category. Non-bank PAs remain outside the direct applicability of the DPSC Master Direction but reach DPSC obligations indirectly through their acquirer bank arrangements.
RBI CB Cybersecurity Directions 2026, Commercial Banks Cybersecurity 2026 (Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026) L1-C10
RBI Directions dated 31 July 2026 consolidating cyber security obligations for commercial banks into a single instrument. Applies to commercial banks including banking companies, corresponding new banks and the State Bank of India. Excludes Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Reporting obligation for cyber security incidents: DAKSH portal within six hours of detection. Security-testing floor: vulnerability assessment every six months, penetration test annually for critical internet-facing systems, half-yearly disaster recovery drills. Board obligations: approve IT policy, cybersecurity policy, information security policy, and business continuity policy; annual review minimum; Board-level IT Strategy Committee. Effectively supersedes the 2016 CSF for commercial banks. Exact RBI reference number to be verified against the rbi.org.in Notifications entry dated 31 July 2026 before quoting in lesson prose.
CERT-In Directions 2022, CERT-In 6-hour Rule (CERT-In Directions 2022 six-hour incident reporting) L1-C11
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
DPDP Rules 2025, DPDP Rule 7 (DPDP Rules 2025 Rule 7 breach reporting) L1-C12
DPDP Rule 7 requires a Data Fiduciary to intimate the Data Protection Board of India of a personal data breach without delay and in any event within 72 hours of becoming aware of the breach, and to notify each affected Data Principal in plain-language terms. Runs in parallel with the 6-hour CERT-In clock and, for commercial banks, the 6-hour DAKSH clock under the 31 July 2026 Directions. A single ransomware event at a bank-cum-PA that also handles personal data can trigger four parallel clocks: RBI DAKSH (6h), CERT-In (6h), DPDP Board (72h), and (if the entity is SDF-flagged) SEBI (6h).
RBI FS Outsourcing Guidelines 2006, Outsourcing Guidelines 2006 (Financial services outsourcing guidelines (still enforced)) L1-C13
RBI Circular DBOD.NO.BP.40/21.04.158/2006-07 dated 3 November 2006. The original RBI outsourcing framework. Continues to apply to outsourcing of financial services (as distinct from IT services which sit under the 2023 IT Outsourcing MD). Confirmed still enforced by the November 2025 HDFC Bank penalty of ₹91 lakh, which cited a 2006 Outsourcing Guidelines contravention (along with a KYC Directions contravention).
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The RBI Cyber Stack in 2026
Module 2: IT Governance under the 2023 ITGRCA Master Direction
  • ITGRCA applicability perimeter in detail
  • IT Strategy Committee: composition, cadence, chair independence
  • CISO independence: the reporting line that actually works
  • IS Audit: cadence, charter, and auditor competencies
  • Three management committees that do the actual work
Module 3: The 2026 Commercial Banks Cybersecurity Directions and the 2016 CSF Baseline
  • Reading the 2026 Directions chapter by chapter
  • The 2016 CSF as continuing baseline for non-commercial-bank REs
  • UCB Graded Framework: picking the right level and staying in it
  • The Cyber Security Policy vs the IT Policy: two documents, one Board
  • The security-testing floor: VA every six months, PT annually, DR half-yearly
Module 4: NBFC IT Framework and the ITGRCA Overlay by SBR Layer
  • The 2017 NBFC IT Framework: what it still does
  • SBR layer mapping and the NBFC IT overlay
  • Reconciling apparent conflicts between the 2017 IT Framework and the 2023 ITGRCA MD
  • NBFC-specific enforcement: IIFL Finance and JM Financial Products
  • Proportionality for sub-₹500 crore NBFCs: a documented risk statement, not a licence
Module 5: Payments: DPSC, PA Directions 2025, Payment Data Storage, Digital Payment Authentication 2026
  • The DPSC Master Direction: scope and application
  • The 2025 Payment Aggregators Directions: three sub-categories and one repeal list
  • Payment data storage 2018: end-to-end in India, foreign leg permitted
  • The April 2026 Digital Payment Authentication Framework
  • The payments compliance stack for a non-bank PA: the eight-instrument register
Module 6: IT Outsourcing, Cloud, and Third-Party Risk
  • The 2023 IT Outsourcing Master Direction in one page
  • The 2006 Financial Services Outsourcing Guidelines that HDFC was penalised under
  • Cloud without a standalone cloud framework
  • Vendor-risk playbook: due diligence to exit management
  • Pooled audits of common third-party providers
Module 7: Incident Response, Fraud Reporting, and the Multi-Regulator Parallel Clocks
  • The DAKSH portal: six-hour clock for commercial banks
  • The CERT-In Directions 2022 obligation in practice
  • DPDP Rule 7: the 72-hour clock for personal data breaches
  • The 2024 Fraud Risk Management Master Directions: EWS, RFA, and seven-day reporting
  • The single incident record that satisfies four parallel regulator clocks
  • A worked example: ransomware at a bank-cum-PA that is also NCIIPC-designated
Module 8: FREE-AI, Draft Data Governance, Enforcement Pattern, and Crosswalk Capstone
  • The FREE-AI Framework and Board-level AI governance
  • The 15 July 2026 Draft Data Governance Guidance: reading the direction of travel
  • Reading the 2022-2026 RBI enforcement pattern
  • Crosswalk: RBI stack with SEBI CSCRF, IRDAI 2026 Guidelines, NCIIPC and CERT-In
  • Capstone: end-to-end compliance programme for a multi-regulated RE
Module 9: Final Exam and Certificate