← Back to blog
Cloud SecuritySep 15, 2026· 9 min

RBI Cybersecurity Directions 2026: What BFSI Must Do

RBI's new Cybersecurity Directions 2026 replace the 2016 framework with one rulebook and a 6-hour incident reporting clock. Here's what BFSI must do now.

RBI Cybersecurity Directions 2026: What BFSI Must Do

What it is: on 31 July 2026, the Reserve Bank of India (RBI) issued the Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions - a single, consolidated rulebook for how banks, NBFCs, and other regulated financial entities must manage cyber risk. Why it matters: these RBI cybersecurity directions 2026 replace the older 2016 Cyber Security Framework, which many entities had treated as a one-time checklist rather than an ongoing discipline. The new Directions push for operational proof - can you actually detect an incident, report it fast, and show your controls work - not just a policy document in a drawer. When it applies: the Directions took effect immediately on issue, so every covered entity is already on the clock.

What is actually new

Instead of one generic circular, RBI has issued seven separate Directions under the same overall framework, each tailored to a category of regulated entity: commercial banks, small finance banks, payments banks, urban co-operative banks, all-India financial institutions, non-banking financial companies (NBFCs), and credit information companies. The core ideas repeat across all seven, but the exact obligations and timelines are graded by how large and systemically important the entity is.

The 6-hour incident reporting clock

The single most operationally demanding change is the reporting timeline: a covered entity must report a cyber incident to RBI within six hours of detecting it. Six hours is not six hours from when the incident started - it is six hours from when your team notices it. That means detection speed now directly determines whether you can even meet the compliance deadline. An organisation that only finds out about an incident during a weekly log review has already failed the clock before it starts.

VA/PT and periodic testing

The Directions call for periodic review, testing, and audit of security controls, commonly referred to as VA/PT (Vulnerability Assessment and Penetration Testing). In plain words: a vulnerability assessment is a scan that lists the weaknesses in your systems, while a penetration test is a controlled, hands-on attempt to actually exploit those weaknesses the way a real attacker would, to prove which ones are truly dangerous. RBI expects these to happen on a defined schedule, not just once before a launch or once when an auditor asks.

Governance and vendor flow-down

Each Direction spells out who inside the organisation is responsible for cybersecurity governance, based on the entity's size and category - board oversight, a named senior owner, and defined escalation paths. The Directions also require what is often called contractual flow-down: named cybersecurity controls that apply to your own organisation must also be written into contracts with critical vendors. In plain words, flow-down means you cannot outsource the risk along with the work - if your ATM switch provider or your core banking software vendor has weak security, that is treated as your problem too, so the contract must obligate them to meet the same bar.

Tiered rules for NBFCs

For NBFCs specifically, the obligations are tiered by RBI's existing regulatory layer classification, which is broadly based on size and systemic importance: Base Layer (below Rs 500 crore), Base Layer (Rs 500 crore and above), and Middle, Upper, and Top Layer NBFCs. The stricter requirements - including the tighter VA/PT cadence and the 6-hour incident reporting obligation - apply from the Middle Layer upward. Smaller Base Layer NBFCs still have obligations, but the intensity scales with size.

What to do now

  • Confirm which of the seven Directions applies to your entity, and if you are an NBFC, confirm your regulatory layer and asset size so you know which tier of rules applies to you.
  • Set up an internal process that can detect a cyber incident and get it reported to RBI within six hours - this usually means investing in monitoring and alerting, not just a reporting template.
  • Put VA/PT (vulnerability assessment and penetration testing) on a recurring calendar, matched to the cadence your tier requires, rather than treating it as a one-off exercise.
  • Review contracts with critical vendors - such as your ATM switch provider or core banking platform - and add the flow-down cybersecurity clauses the Directions expect.
  • Make sure governance responsibilities are formally assigned and documented, matching what your specific Direction requires for an entity of your size.

None of this is optional or phased in gently - the Directions are already in force. The entities that will struggle most are the ones that treat this as a paperwork exercise rather than building the actual detection and reporting capability the 6-hour clock demands.

Learn it by doing

Pick your track and launch a hands-on lab in a real, isolated environment.

24 people viewing now