RBI · Cybersecurity

RBI Cyber Security Framework
and the 2026 Directions that replaced it.

The 2016 framework for banks and the 2023 IT governance Master Direction were repealed on 31 July 2026. This is what replaced them, who each instrument now binds, how fast an incident has to reach RBI, and where payment aggregators, data localisation and RBI's AI work fit.

31 July 2026Six hours to DAKSHSeven entity DirectionsStorage of Payment System Data

Last updated Published by TryTrustableNot legal advice

01

Is the RBI Cyber Security Framework still in force?

No. On 31 July 2026 the Reserve Bank of India repealed its existing cybersecurity and IT governance instructions, including the 2 June 2016 Cyber Security Framework for banks and the 7 November 2023 IT governance Master Direction, and issued seven entity-specific Directions in their place, effective on issue with no transition period.

The new instruments share one title: Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026. Each is written for one class of regulated entity. The Commercial Banks Directions (RBI/DoS/2026-27/410) state in their repeal paragraph that the existing directions, instructions and guidelines relating to the cybersecurity framework and IT governance as applicable to commercial banks stand repealed, and list the repealed circulars in a separate circular of the same date. The NBFC Directions (RBI/DoS/2026-27/461) do the same for the NBFC IT framework. Approvals already granted and action already taken under the old instruments remain governed by them.

Two practical consequences. A policy that cites the 2016 circular or the 2023 Master Direction as its authority is now citing repealed law, and needs re-papering against the paragraph numbers of the 2026 Directions. And because the Directions took effect on the day they were issued, the gap analysis is already overdue rather than a project for next year.

02

Which RBI cybersecurity rules apply to which entity?

Since 31 July 2026, each class of RBI-regulated entity has its own cybersecurity Direction. Payment aggregators sit under a separate September 2025 Master Direction, and payment system operators remain bound by the 2018 data storage circular. The table maps each entity to the instrument that governs it today.

EntityInstrument in forceNotes
Commercial banksCommercial Banks Directions, 2026
RBI/DoS/2026-27/410
Excludes small finance banks, payments banks and local area banks. Foreign banks in branch mode may comply or explain on some chapters, subject to supervisory acceptance.
Small finance banksSFB Directions, 2026
RBI/DoS/2026-27/419
Own instrument, same structure.
Payments banksPayments Bank Directions, 2026
RBI/DoS/2026-27/428
Own instrument, same structure.
Urban co-operative banksUCB Directions, 2026
RBI/DoS/2026-27/437
Own instrument.
All-India financial institutionsAIFI Directions, 2026
RBI/DoS/2026-27/456
EXIM, NABARD, NaBFID, NHB, SIDBI.
NBFCsNBFC Directions, 2026
RBI/DoS/2026-27/461
Tiered by layer and asset size: base layer below and above ₹500 crore, middle, upper and top layers, and core investment companies.
Credit information companiesCIC Directions, 2026
RBI/DoS/2026-27/470
Own instrument.
Payment aggregatorsMaster Direction on Regulation of Payment Aggregators
RBI/DPSS/2025-26/141, 15 Sept 2025
Replaced the 2020 and 2021 PA/PG guidelines and the 2023 cross-border PA circular. Technology baseline in Annexure 1: mandatory for aggregators, recommended for gateways.
Payment system operatorsStorage of Payment System Data
6 April 2018
All payment system data stored only in India. Applied to aggregators by the 2025 Master Direction.

Reference numbers from the Directions as published on rbi.org.in. Read the entity's own Direction; the paragraph numbers differ between them.

The 2023 Master Direction it replaced applied to scheduled commercial banks other than regional rural banks, small finance and payments banks, NBFCs in the top, upper and middle layers, credit information companies and the all-India financial institutions. The 2026 NBFC Direction covers every layer, including the base layer, with duties tiered by size, which is the largest change in scope.

03

What do the 2026 Cybersecurity Directions require?

The 2026 Directions make cybersecurity a board-level governance duty with named roles and fixed frequencies: a CISO who does not report to the head of IT, a board IT strategy committee, a security operations centre, vulnerability testing on a fixed cycle, tested backups and recovery drills, a risk-based information systems audit, and six-hour incident reporting.

The Commercial Banks Directions run to 233 paragraphs across eight chapters. The provisions that change day-to-day operations are these:

AreaCommercial banksNBFCs
CISOReports directly to the Executive Director, or equivalent, who oversees risk management; not to the head of IT.A senior executive, preferably General Manager rank, reporting to the executive overseeing risk management, with no direct reporting line to the IT head (paras 81–82).
Board oversightIT Strategy Committee of at least three directors, chaired by an independent director with at least seven years' IT experience.Scaled by layer.
Security operationsA 24x7 cyber SOC with tiered analyst levels, covering detection, root cause analysis, investigation and forensics.The CISO's office manages and monitors the SOC (para 82).
Vulnerability testingVulnerability assessment every six months and penetration testing every twelve months for critical systems and customer-facing systems in the DMZ.VA at least every six months and PT at least every twelve months for critical systems (para 121).
AuthenticationMulti-factor authentication mandatory for privileged users of critical systems and critical activities.As scaled by layer.
ResilienceDisaster recovery drills for critical systems every six months.Back up data, periodically restore it to prove it is usable, preserve its integrity (para 133).
IS auditRisk-based, with continuous auditing of critical systems where practicable.By an internal team, external help for skill gaps, at least once a year (paras 55–56).
IncidentsReport to RBI on DAKSH within six hours of detection (para 182), and notify CERT-In.Report to RBI on DAKSH within six hours of detection (para 141).
Data held by vendorsThe bank stays accountable for customer data security wherever the data is stored, including with third parties.Same principle.

Summarised from the Commercial Banks and NBFC Directions, 2026. Paragraph numbers are the NBFC instrument's unless stated.

None of this is new as an idea. What is new is that RBI now specifies who does the work, who they report to and how often the board sees it, where the 2016 framework mostly specified outcomes. An examiner can now test the org chart and the calendar as well as the controls.

04

How fast must a cyber incident be reported to RBI?

Within six hours of detection, on RBI's DAKSH supervisory platform, for every entity covered by the 2026 Directions. The same event usually starts CERT-In's six-hour clock and, if personal data is involved, the DPDP duty to tell the Data Protection Board and each affected person, with a full report within 72 hours.

One incident, several regulators, several clocks. They run in parallel, not in sequence:

RecipientWhenSource
RBI (DAKSH)Within six hours of detection2026 Directions, e.g. para 182 (banks), para 141 (NBFCs)
CERT-InWithin six hours of noticing or being told of a reportable incidentCERT-In directions of 28 April 2022 under s.70B(6) of the IT Act
Data Protection BoardIntimation without delay; detailed report within 72 hours of becoming awareDPDP Act s.8(6) and Rule 7; see the DPDP guide
Affected customersWithout delay, in plain language, for a personal data breachDPDP Rule 7(1)
Payment aggregators to RBIWithin the stipulated timeframe; monthly incident reports with root cause analysisPA Master Direction, Annexure 1 item 1.3

The six-hour clocks start at detection, which makes detection time the number an examiner will ask about. CERT-In and DPDP breach reporting compared works through the overlap, and the breach notification deadline calculator turns one detection time into every deadline.

05

What do payment aggregators and gateways have to do?

Payment aggregators must hold RBI authorisation, run a board-approved information security policy, meet the Annexure 1 technology baseline, store payment data only in India, have an annual system and cyber security audit done by a CERT-In empanelled auditor, and keep card credentials off merchant systems. Gateways are recommended, not required, to follow the baseline.

The Master Direction on Regulation of Payment Aggregators of 15 September 2025 consolidated the earlier PA/PG guidelines. Its technology annexure is specific:

  • Reporting to the board and IT committee. Quarterly internal and annual external audit reports, VAPT reports twice a year, PCI DSS attestation and report of compliance, and an inventory of applications that store, process or transmit customer sensitive data
  • Merchant onboarding. A security assessment of each merchant against the baseline, and a review of its PCI DSS status
  • Card data. Customer card credentials must not be stored in the database or server the merchant accesses
  • Data sovereignty. Preventive measures so data is not stored on infrastructure belonging to external jurisdictions, and the 2018 storage circular applied as it applies to payment system operators
  • Forensic readiness. Security events from every layer, from endpoints to cryptographic events, collected and analysed
  • Outsourcing. A right-to-audit clause for the aggregator and the regulator, or an annual independent audit report from the third party
06

What does RBI's data localisation circular require?

RBI's circular of 6 April 2018 on Storage of Payment System Data requires every payment system provider to store the entire data relating to the payment systems it operates in a system only in India, including end-to-end transaction details and payment credentials. It gave six months to comply and a system audit report by 31 December 2018.

The circular (RBI/2017-18/153) was not among the instruments the 2026 cybersecurity Directions repealed, and the 2025 Payment Aggregator Direction applies it by name. It is narrower than people assume, since it concerns payment system data rather than every record a bank holds, and stricter than the DPDP Act, which permits transfer abroad except to countries the government restricts. The Act does not loosen it: section 16(2) preserves any other law that provides a higher degree of protection or restriction on transfer. The DPDP cross-border transfer guide covers how the two interact.

07

What is RBI's FREE-AI framework, and is it binding?

FREE-AI, the Framework for Responsible and Ethical Enablement of Artificial Intelligence, is a committee report the Reserve Bank released on 13 August 2025. It sets out seven principles and 26 recommendations across six pillars. It is guidance, not a direction. The binding step came later, as draft model risk guidance.

The FREE-AI Committee report was chaired by Professor Pushpak Bhattacharyya of IIT Bombay. Its seven principles, which it calls sutras, were later adapted by MeitY for the cross-sector India AI Governance Guidelines. On 24 June 2026 RBI published draft guidance on regulatory principles for model risk management, open for comment until 24 July 2026, covering every model a regulated entity uses, including third-party and AI or machine-learning models, with board-level governance, model classification and human oversight of AI-driven decisions. Check rbi.org.in for whether it has been finalised before you plan against it.

For a bank already building model inventories for credit risk, the practical work is the same inventory extended to the chatbot, the fraud model and the foundation-model API the contact centre adopted last quarter.

08

How do the RBI rules sit with the DPDP Act?

They answer different questions. RBI's Directions govern how a regulated entity secures and runs its technology. The DPDP Act governs what it may do with personal data and what it owes each person. A bank must satisfy both, and meeting one does not discharge the other.

They meet in three places. Breach reporting, covered above, where one incident runs several clocks. Retention, where KYC rules and the Prevention of Money-laundering Act require records to be kept and section 8(7) of the DPDP Act requires erasure once the purpose is served: retention required by law is an exception, but only for the data the law names. Transfers, where the storage circular wins over the Act's permissive default. The fintech sector page takes each in turn, and the DPDP Act and Rules guide sets out the timetable, with substantive duties from 13 May 2027.

09

Where TryTrustable fits, and where it does not

TryTrustable does not ship an RBI control set, is not a CERT-In empanelled auditor, and does not file reports on DAKSH. What it does ship is ISO 27001, SOC 2 and CERT-In direction coverage on one control graph, custom framework authoring so a regulator's control list can be entered and mapped onto controls you already operate, and a hash-chained evidence ledger that shows an auditor when each control passed and when it failed. For the personal data side, the consent platform keeps the DPDP consent record and runs the breach and rights clocks.

Questions

The things people ask us

Is the RBI Cyber Security Framework of 2016 still in force?

No. The Reserve Bank repealed its cybersecurity and IT governance instructions for banks on 31 July 2026, including the framework issued on 2 June 2016 and the Master Direction of 7 November 2023, and replaced them with entity-specific Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions. Action already taken under the old instruments stays governed by them.

How quickly must a bank or NBFC report a cyber incident to RBI?

Within six hours of detection, on the Reserve Bank's DAKSH supervisory platform. Paragraph 182 of the Commercial Banks Directions and paragraph 141 of the NBFC Directions both say so. CERT-In has its own six-hour clock under its 2022 directions, and a personal data breach also triggers the DPDP Rule 7 reports to the Data Protection Board.

Does the 2026 RBI cybersecurity direction apply to fintech companies?

Only to the regulated entities it names: commercial banks, small finance banks, payments banks, urban co-operative banks, all-India financial institutions, NBFCs and credit information companies. A fintech that is none of those feels it through its bank or NBFC partner, which remains accountable for technology it outsources and pushes its controls into the contract.

Is RBI's data localisation rule still in force for payment companies?

Yes. The 6 April 2018 circular on Storage of Payment System Data requires the entire data relating to payment systems to be stored in a system only in India. The Payment Aggregator Directions of September 2025 apply it to aggregators expressly. Section 16(2) of the DPDP Act preserves sectoral rules that restrict transfers more tightly.

Is the RBI FREE-AI framework binding on banks?

Not as such. FREE-AI is a committee report the Reserve Bank released on 13 August 2025, with seven principles and 26 recommendations. It is guidance about direction of travel. The binding step is RBI's draft guidance on model risk management, published on 24 June 2026 for comment, which covers AI and machine-learning models including those bought from third parties.

What should a bank's vendor expect from the 2026 Directions?

More contractual flow-down, not a direct duty. The bank stays accountable for customer data wherever it is stored, including at a vendor, so expect audit rights, incident notification well inside six hours, evidence of vulnerability testing and access control, and questions about where data and logs sit.

Six hours starts at detection

Know every clock before the incident, not during it.

Put one detection time into the calculator and see the RBI, CERT-In and DPDP deadlines side by side, then look at how the platform keeps the evidence for the controls behind them.