
RBI's 2026 Cybersecurity Directions: What Changed for VAPT, the SOC and 6-Hour Reporting
RBI replaced its cyber and IT governance instructions on 31 July 2026 with entity-wise Directions that took effect the same day. What applies to banks and NBFCs, the VAPT and DR drill cadence, six-hour reporting on DAKSH, the CSOC and CISO lines, and a 90-day plan.
India BFSI Regulation
On 31 July 2026 the Reserve Bank of India replaced its cyber security and IT governance instructions with a new family of Directions, one for each class of regulated entity, and they took effect the same day. Here is what applies to commercial banks and NBFCs, what changes in your testing and drill calendar, how the six-hour reporting rule now works, and a 90-day plan for getting your documents to match.
In short. The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions are in force with no transition period, and they repeal the earlier cyber and IT governance instructions for each entity class they cover. For critical systems and anything in the DMZ with a customer interface: vulnerability assessment at least every six months, penetration testing at least every twelve, and DR drills at least every half year. Cyber incidents go to RBI within six hours of detection, through DAKSH for commercial banks, with CERT-In notified as well. If your policies still cite the 2016 framework or the 2023 Master Direction, they cite instruments that no longer apply to you.
What RBI issued on 31 July 2026
For a decade RBI's technology expectations lived in a stack of instruments: the 2016 Cyber Security Framework in Banks, the 2023 Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, and a long tail of circulars and advisories layered on top. Anyone who has tried to map a bank's controls to "the RBI requirement" knows the problem. There was no single document to map to.
The July 2026 package changes the architecture. Instead of one framework stretched across very different institutions, RBI issued a separate set of Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for each class of regulated entity, alongside a companion set of Digital Payment Security Controls Directions issued the same day. The commercial bank Direction, for example, covers the full stack in one place: board oversight, IT governance, the CISO, IT and cyber risk management, baseline controls, the security operations centre, vulnerability assessment and penetration testing, business continuity and DR, incident response and reporting, and information systems audit.
Two things about the package matter more than any single control. First, it took effect immediately. The commercial bank Direction says it comes into effect "immediately upon issuance", and the NBFC Direction is effective 31 July 2026 "with immediate effect". There is no glide path. Second, each Direction repeals what came before for its entity class, which means the documents most banks and NBFCs use to evidence compliance are now pointing at the wrong instruments.
Which Direction applies to you
Seven entity classes received their own Direction in this family. Read the one addressed to you, not a summary of another class's: the chapter structure, thresholds and some obligations differ.
| Entity class | Notes on scope |
|---|---|
| Commercial banks | RBI/DoS/2026-27/410. Banking companies other than small finance banks, payments banks and local area banks, plus corresponding new banks and the State Bank of India. Foreign banks operating as branches follow a "comply or explain" approach for selected chapters. |
| Small finance banks | A separate Direction addressed to small finance banks only. |
| Payments banks | A separate Direction addressed to payments banks only. |
| Urban co-operative banks | A separate Direction, with obligations graded by the bank's level. |
| All India financial institutions | A separate Direction for the AIFIs. |
| NBFCs | RBI/DoS/2026-27/461. All NBFCs registered under the RBI Act, the Factoring Regulation Act or the National Housing Bank Act. Obligations are layered: base layer NBFCs under ₹500 crore and core investment companies follow Chapter III; base layer NBFCs of ₹500 crore and above follow Chapter IV; middle, upper and top layer NBFCs follow Chapter V. |
| Credit information companies | A separate Direction for credit information companies. |
If you are a payment aggregator, a prepaid instrument issuer or another non-bank payment system operator, you are not one of the seven classes above. Your obligations sit in the instructions addressed to payment system participants, and the companion Digital Payment Security Controls Directions are the place to check how this package touches you.
For NBFCs the layering is the first thing to settle. Some obligations, including the VAPT cadence quoted below, sit in the provisions for middle layer and above. A base layer NBFC should read its own chapter rather than assume the heavier obligations apply, and should equally not assume they do not.
What was repealed, and why your policy pack is now out of date
The commercial bank notification states that "existing Directions, instructions, and guidelines relating to Cybersecurity Framework and IT Governance as applicable to Commercial Banks stand repealed", by circular DoS.CO.PPG.66/11.01.005/2026-27 of the same date. The NBFC Direction does the same for "existing directions, instructions, and guidelines relating to Information Technology Framework and IT Governance as applicable to Non-Banking Financial Companies" at paragraph 155.
That language is broad enough to reach both the 2016 framework and the 2023 Master Direction for the entity classes the new Directions address. The repeal circular is the document that lists exactly what went, and it is worth reading line by line rather than assuming, because some specific circulars on adjacent topics may survive.
The practical consequence is immediate. Your information security policy, your board-approved cyber policy, your VAPT procedure, your incident response plan, your outsourcing policy and your IS audit plan almost certainly cite the old instruments by name and paragraph. An inspection that asks how a control maps to the regulation will now be asking about the 2026 paragraph numbers. Remapping is not cosmetic: in several places the new text is more specific than the old, and in some it is different.
The requirements that change your calendar
Most of the new Directions restate, consolidate and sharpen familiar expectations. A handful of provisions set a frequency or a deadline, and those are the ones that change what your team does every quarter.
| Requirement | Commercial banks (RBI/DoS/2026-27/410) | NBFCs (RBI/DoS/2026-27/461) |
|---|---|---|
| Vulnerability assessment | At least once every six months for critical information systems and systems in the DMZ with a customer interface (para 151) | At least once in every six months, in the provisions for middle layer and above (para 121) |
| Penetration testing | At least once in 12 months for the same systems; risk-based for non-critical systems (para 151) | At least once in 12 months, in the provisions for middle layer and above (para 121) |
| Cyber incident reporting | Within six hours of detection on the DAKSH platform, and CERT-In proactively notified (para 182) | To RBI within six hours of detection (para 141) |
| DR drills | At least half-yearly for critical information systems; risk-based for others (para 165), with switch-over to the DR site run as primary for at least a full working day (para 167) | At least half-yearly for critical information systems (para 129) |
| Security operations centre | Set up a CSOC for continuous surveillance (para 143), with a separate chapter of minimum baseline guidance on the CSOC | The CISO's office manages and monitors the SOC (para 82(4)) |
| CISO | A senior executive, preferably General Manager rank, with no direct reporting line to the head of IT (para 27), reporting to the executive director overseeing risk management (para 28(6)) | Read the governance chapter for your layer |
| Board | Approves IT, information asset, business continuity, information security and cyber security strategies and policies (para 7), reviewed at least annually (para 8) | Read the governance chapter for your layer |
| Red teaming | Permissive: the bank "may" conduct red teaming exercises (para 162) | Not stated in the provisions quoted here |
| Cyber drills | Participate periodically and actively in drills run under CERT-In and IDRBT (para 188) | Read the incident management chapter for your layer |
| Metrics | Cyber security metrics are required (paras 195–196) | Define metrics and implement a scorecard to measure IT performance and maturity (paras 147–148) |
Paragraph numbers are from the Directions as issued. NBFC obligations are layered, so confirm which of the NBFC provisions above sit in the chapter for your layer. Where a cell says to read your chapter, we have not quoted the NBFC wording here; check the text addressed to your layer rather than borrowing the commercial bank wording.
Six-monthly VA and annual PT: the scoping questions that matter
"At least once every six months" and "at least once in 12 months" are easy to schedule. The work is in deciding which systems they apply to, because the cadence attaches to two categories: critical information systems, and systems in the DMZ having a customer interface. Everything else is on a risk-based frequency that you define and must be able to defend.
Classify before you schedule
Maintain a list of critical information systems with the reason each one is critical, approved at the right level. If a system is left off the list, an inspector will ask why, and "it was not in last year's VAPT scope" is not a reason. The same classification also drives DR drill frequency, so it is worth getting right once.
Treat "customer interface" broadly
Internet banking and the mobile app are obvious. The APIs behind the mobile app, partner and fintech integration endpoints, customer-facing chat and support portals, and payment pages hosted by third parties on your behalf are all customer interfaces in the DMZ in any sensible reading. The APIs are where the serious findings usually are.
Separate VA from PT in the plan
A vulnerability assessment twice a year and a penetration test once a year are different activities with different evidence. A scanner report is not a penetration test, and a penetration test that only reports what a scanner found has not tested the authorisation logic where customer data actually leaks.
Close the loop on findings
Frequency without remediation tracking just produces the same report twice. Keep findings, owners, due dates and retest evidence together, so the six-month VA can show which findings from the last round are closed and which are accepted risks with sign-off.
Decide your position on red teaming
For commercial banks it is permissive, not mandatory. A bank that has not run one should still be able to say how it tests detection and response, because a penetration test checks whether a door is locked, not whether anyone notices someone trying it.
In practice the six-monthly cycle works best when the annual penetration test is split by surface rather than done once as a single large engagement: internet banking and the APIs behind it in one half, the mobile application and external network perimeter in the other, with vulnerability assessment running across everything in both halves. It spreads the remediation load and gives the board two data points a year instead of one.
Six hours on DAKSH, and CERT-In alongside
For commercial banks, paragraph 182 is specific: cyber incidents are reported "within six hours of detection on DAKSH platform", RBI's supervisory monitoring system, and the bank "shall also pro-actively notify CERT-In". For NBFCs, paragraph 141 sets the same six hours for reporting to RBI. Separately, CERT-In's own directions of April 2022 already require a defined list of incident types to be reported to CERT-In within six hours of noticing them, and that obligation applies to every Indian entity regardless of who regulates it.
So a bank now has two six-hour clocks running from the same event, to two recipients, through two channels. Neither is a replacement for the other. The six hours are short enough that the report has to be an early notification filed with what you know, then updated, which means the decisions about whether something is reportable and who files it have to be made in advance.
- Name the reporters. Who files on DAKSH and who notifies CERT-In, with deputies for nights, weekends and holidays. Test their credentials before you need them.
- Define "detection". The clock starts at detection, so your runbook needs a clear rule for the moment an alert becomes a detected incident. If that moment is not defined, it will be argued about after the fact.
- Keep a pre-filled template. Entity details, contacts and system inventory references filled in already, so the first report is about the incident and nothing else.
- Exercise it. A tabletop exercise that runs the clock from first alert to both submissions finds the gaps cheaply. Paragraph 188's expectation that banks join CERT-In and IDRBT drills is a good forcing function for the same rehearsal.
Our earlier guide to CERT-In's six-hour reporting rule covers the CERT-In side in detail, including which incident types are reportable.
The CSOC and the CISO
Commercial banks must "set up a CSOC to ensure continuous surveillance and keep itself regularly updated on the latest nature of emerging cyber threats" (paragraph 143), and the Direction carries a separate chapter of minimum baseline guidance on how the CSOC should operate. For NBFCs, paragraph 82(4) places the management and monitoring of the SOC with the CISO's office. The paragraphs quoted here do not, by themselves, say the SOC must be staffed entirely in-house; read the CSOC chapter and your outsourcing obligations together before deciding how to deliver it, and remember that if a provider runs part of it, overseeing that provider is still your job.
The CISO provisions for commercial banks settle a long-running argument. The CISO is a senior executive, preferably at General Manager rank or equivalent, with no direct reporting relationship with the head of IT (paragraph 27), and reports directly to the executive director or equivalent overseeing risk management (paragraph 28(6)). If your organisation chart still has the CISO inside the technology function, it is now out of line with the text.
If you are deciding between building, co-managing or outsourcing the monitoring function, our comparison of managed and in-house SOC models sets out the trade-offs, and a SOC maturity assessment against the CSOC chapter is the fastest way to find out how far your current operation is from the baseline.
DR drills that count
Half-yearly DR drills for critical information systems are a frequency. Paragraph 167 for commercial banks sets the standard: the drill involves switching over to the DR or alternate site and using it as the primary site for a sufficiently long period, covering at least a full working day of normal operations from beginning of day to end of day.
That is a much higher bar than a weekend failover test that proves the DR site starts. A full business day on the DR site exercises batch jobs, interfaces to payment systems and partners, reconciliations and the people who run them. It also exposes the difference between the recovery time you have written down and the one you can actually achieve. Two things are worth doing before the first drill under the new text:
- Revisit recovery objectives with the business. Recovery time and recovery point objectives set years ago are often set for infrastructure failure. Check them against a scenario where the primary site is unavailable because of a cyber attack, not a power cut. A business impact analysis is the structured way to do it.
- Include the cyber scenario in the plan. Ransomware does not fail over cleanly: replication will happily copy encrypted data to the DR site. The continuity plan needs a path for recovering from known-clean backups, not only for switching sites. Our ransomware defence playbook covers the recovery side.
A 90-day plan
The Directions took effect on issue, so the honest position for most regulated entities is that there is already a gap between the text and the documents. This is the order we would close it in.
Days 1–15 — Confirm which Direction, which chapter, and what was repealed
Identify your Direction and, for NBFCs, your layer and chapter. Read the repeal circular and list every internal policy and procedure that cites a repealed instrument. Brief the board risk committee on the change: this is a board-approved policy matter, not an IT update.
Days 15–30 — Fix the clocks first
Incident reporting has the shortest deadline and the highest consequence. Update the incident response plan for six-hour reporting to RBI alongside CERT-In, name the reporters, and test access to DAKSH. Run one tabletop on it.
Days 30–45 — Classify systems and re-baseline the test calendar
Approve the list of critical information systems and DMZ customer-interface systems. Set the six-monthly VA and annual PT dates against it, and define the risk-based frequency for everything else in writing.
Days 45–75 — Gap assessment against the full text
Map every control to its new paragraph: governance and CISO reporting line, baseline controls, CSOC chapter, DR standard, third-party arrangements, metrics. Record gaps with owners and dates. Where a gap needs budget, take it to the board with the paragraph reference.
Days 75–90 — Re-approve, re-train, schedule the drill
Board approval of the revised policies, an update for the teams who run the controls, and the next DR drill planned to the full-working-day standard. Agree the metrics the board will see each quarter, so progress against the gaps is visible.
Frequently Asked Questions
Click any question to expand the answer.
QWhen did the 2026 Directions take effect?
Immediately, on 31 July 2026. The commercial bank Direction comes into effect "immediately upon issuance" and the NBFC Direction is effective from 31 July 2026 with immediate effect. Neither provides a transition period.
QDo they replace the 2016 framework and the 2023 IT Governance Master Direction?
For the entity classes they cover, each Direction repeals the existing directions, instructions and guidelines on cyber security and IT governance applicable to that class. That language reaches both instruments. The repeal circular, DoS.CO.PPG.66/11.01.005/2026-27, is the document to check for the definitive list.
QHow often must a commercial bank run VA and PT?
For critical information systems and systems in the DMZ with a customer interface, vulnerability assessment at least once every six months and penetration testing at least once in 12 months. For non-critical systems the frequency is risk-based, which means you set it, document it and defend it.
QDoes the six-hour RBI report replace the CERT-In report?
No. Commercial banks report to RBI on DAKSH within six hours of detection and also proactively notify CERT-In. CERT-In's April 2022 directions separately require reportable incident types to be reported to CERT-In within six hours. Plan for both from the same event.
QIs red teaming now mandatory for banks?
Not in the commercial bank Direction's wording. Paragraph 162 says the bank "may" conduct red teaming exercises to identify vulnerabilities and business risk and to assess the efficacy of its defences. It is a permitted and encouraged activity rather than a fixed obligation.
QDo small NBFCs have the same obligations as large ones?
No. The NBFC Direction is layered. Base layer NBFCs under ₹500 crore and core investment companies follow Chapter III, base layer NBFCs of ₹500 crore and above follow Chapter IV, and middle, upper and top layer NBFCs follow Chapter V. Read the chapter for your layer rather than a summary written for another.
QWho should the CISO report to?
For commercial banks, the CISO has no direct reporting relationship with the head of IT and reports directly to the executive director or equivalent overseeing the risk management function. The CISO should be a senior executive, preferably of General Manager rank or equivalent.
QCan the SOC be delivered by a managed service provider?
The provisions quoted here require a CSOC and place its management with the CISO's office, but do not by themselves say it must be staffed entirely in-house. Read the CSOC chapter alongside your outsourcing obligations. If a provider runs part of the function, accountability and oversight of that provider remain with you.
QWhat does a DR drill under the new text involve?
For commercial banks, drills for critical information systems at least half-yearly, and testing that switches over to the DR or alternate site and runs it as primary for a sufficiently long period, covering at least a full working day of business operations from beginning to end of day.
QWe are a payment aggregator. Does this apply to us?
Payment aggregators and other non-bank payment system operators are not among the seven entity classes that received a Direction in this family. Check the instructions addressed to payment system participants, and the companion Digital Payment Security Controls Directions issued on the same day.
QWhat is the first thing to do?
Fix incident reporting. It has the shortest deadline and the highest consequence. Update the incident response plan for six-hour reporting to RBI alongside CERT-In, name the reporters and their deputies, confirm access to the reporting channel, and rehearse it once before the next real incident does it for you.
Related reading
Our earlier articles describe the instruments these Directions replaced, and remain useful background on how RBI's expectations developed: the 2023 Master Direction on IT governance, RBI's SOC expectations for banks and NBFCs and a beginner's guide to RBI cyber requirements. Read them for context, and this article for what applies now.
For the parallel regime in capital markets, see our guide to SEBI's Cybersecurity and Cyber Resilience Framework.
About Adayptus
Adayptus Consulting Private Limited is a cybersecurity consultancy based in Noida, India. We work with banks, NBFCs and fintechs on RBI and SEBI cyber compliance, the testing that evidences it, and the security operations that keep it true between audits.
What we can do for you:
- A gap assessment against the 2026 Direction that applies to you. Control by control, mapped to the new paragraph numbers, with the policy pack updated so it cites the instruments that are actually in force. Part of our BFSI security practice.
- The VAPT calendar the Directions describe. Manual web, API, mobile and network testing scheduled across the six-monthly cycle, with every finding reproduced by hand and a remediation retest included.
- The CSOC and the clocks. Managed or co-managed SOC operations, a six-hour reporting runbook, and a tabletop exercise that rehearses it, plus the cyber metrics the board will now expect to see.
Sources
- Reserve Bank of India, Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/410, 31 July 2026.
- Reserve Bank of India, Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/461, 31 July 2026.
- KPMG India, RBI's technology focused master directions issued on 31 July 2026, for the companion Digital Payment Security Controls Directions.
This article summarises the Directions for planning purposes and quotes them where the wording matters. It is not legal advice. Paragraph numbers and thresholds should be confirmed against the Direction addressed to your entity class.
Adayptus Consulting
BFSI Security and Compliance, Adayptus
Adayptus Consulting Private Limited is a cybersecurity consultancy based in Noida, India, working with banks, NBFCs and fintechs on RBI and SEBI cyber compliance and the security testing that evidences it.
On This Page
- What RBI issued on 31 July 2026
- Which Direction applies to you
- What was repealed, and why your policy pack is now out of date
- The requirements that change your calendar
- Six-monthly VA and annual PT: the scoping questions that matter
- Six hours on DAKSH, and CERT-In alongside
- The CSOC and the CISO
- DR drills that count
- A 90-day plan
- Frequently Asked Questions
- Related reading
- About Adayptus
- Sources


