Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this RBI Cybersecurity Framework Practitioner Certification register is built
This trust page is the citation register for the RBI Cybersecurity Framework Practitioner Certification course. It cites 25 authorities across 21 statutory instruments, drawn from the legal basis snapshot above (RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).).
Primary sources: RBI Banks Cyber Framework 2016 (3 entries), RBI ITGRCA Master Direction 2023 (3 entries), CERT-In Directions 2022 (1 entry).
Every claim in every RBI Cybersecurity Framework Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
CERT-In 6-hour Rule , CERT-In Directions 2022 six-hour incident reporting 28 Apr 2022
DPDP Rule 7 , DPDP Rules 2025 Rule 7 breach reporting 13 Nov 2025
CCMP , Cyber Crisis Management Plan requirement 02 Jun 2016
Incident Reporting Template , CSITE incident reporting template and immediacy 02 Jun 2016
Master Circular 2016 , Cyber Security Framework in Banks 02 Jun 2016
Commercial Banks Cybersecurity 2026 , Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 31 Jul 2026
DAKSH Portal , DAKSH cyber incident reporting portal 06 Oct 2022
Digital Payment Authentication 2026 , RBI Digital Payment Authentication Framework 01 Apr 2026
DPSC Master Direction , Digital Payment Security Controls Master Direction 18 Feb 2021
Draft Data Governance , RBI Draft Guidance on Data Governance (consultation) 15 Jul 2026
FRM MDs Consolidation , Three FRM Master Directions supersede 36 legacy circulars 15 Jul 2024
FREE-AI Report , Framework for Responsible and Ethical Enablement of AI 13 Aug 2025
Outsourcing Guidelines 2006 , Financial services outsourcing guidelines (still enforced) 03 Nov 2006
HDFC Nov 2025 , HDFC Bank penalty citing 2006 Outsourcing Guidelines 01 Nov 2025
IIFL and JM Mar 2024 , IIFL Finance and JM Financial supervisory restrictions 01 Mar 2024
IT Outsourcing MD 2023 , Master Direction on Outsourcing of IT Services 10 Apr 2023
IS Audit Cadence , Information Systems Audit annual cadence 07 Nov 2023
ITGRCA Applicability , ITGRCA Master Direction applicability perimeter 07 Nov 2023
ITSC and CISO , IT Strategy Committee and CISO independence 07 Nov 2023
Kotak Mahindra 24 Apr 2024 , Kotak Mahindra Bank supervisory business restrictions 24 Apr 2024
NBFC IT Framework 2017 , IT Framework for the NBFC Sector 08 Jun 2017
PA Directions 2025 , Consolidated Payment Aggregators Directions 15 Sep 2025
Payment Data Localisation , RBI Payment Data Storage Direction 2018 06 Apr 2018
SBR Layer Mapping , Scale-Based Regulation four-layer NBFC classification 22 Oct 2021
UCB Graded Framework , Four-level graded cyber framework for UCBs 31 Dec 2019
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.