RBI just rewrote the rulebook: the 2026 Cybersecurity Directions, what died with the 2016 framework, and how to pass the next audit
On 31 July 2026, the Reserve Bank of India quietly did something it had been building toward for a decade: it retired the 2016 Cyber Security Framework — the circular that defined how every Indian commercial bank has run its security programme since the Gopalakrishna era — and replaced the whole patchwork with a single consolidated rulebook. The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 are effective immediately. Not next financial year. Not after a comfortable transition window. Now. If you're a commercial bank, the compliance programme you built against the 2016 framework's three annexes is measuring against a rulebook that no longer exists — and your next RBI inspection will measure against the new one. If you're an NBFC or a payment system operator, you're not directly in scope of this specific instrument, but the direction of supervisory travel it signals applies to you with maybe a one-cycle lag. This post is the practitioner's read: what the 2026 Directions actually change, who falls under which rulebook now, and — most usefully — the technology capabilities the new audit actually tests for, described as capabilities rather than product names, because the regulator doesn't care whose logo is on the box.
Issued
31 July 2026
RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. Effective immediately on issue.
What it replaces
The 2016 framework — and the patchwork
The June 2016 Cyber Security Framework and the scattered circulars around it are consolidated into one instrument for commercial banks.
Hard cadences now written down
VA 6-monthly · PT annual · DR drills 6-monthly
Plus DR-site-as-primary for at least one full business day per drill, and near-zero RPO expectations for critical systems.
Incident clock
6 hours → DAKSH
Cyber incident reporting through RBI's DAKSH supervisory platform within six hours. The CERT-In 6-hour clock runs in parallel.
The eventWhy the 2016 framework needed killing — and what the 2026 Directions consolidate
The June 2016 Cyber Security Framework was genuinely good regulation for its moment. Its three annexes — baseline controls, the Cyber Security Operations Centre requirement, and incident reporting — pushed Indian banks years ahead of where market forces alone would have taken them. But a decade of bolt-ons made the overall regime a patchwork: the 2016 framework for cyber, the November 2023 IT Governance Master Direction (ITGRCA) for governance and audit, the outsourcing directions for third-party risk, separate digital-payment security controls, and a steady drip of clarifying circulars, each with its own definitions and its own reporting formats. Compliance teams at mid-size banks were maintaining traceability matrices across five-plus instruments that overlapped without quite agreeing.
The 2026 Directions collapse that stack into a single framework covering IT governance and policy, information security and cybersecurity, IT operations, information system audit, business continuity and disaster recovery, and IT outsourcing — one instrument, one set of definitions, one supervisory lens. Coverage extends into territory the 2016 framework never formally reached: data governance, cryptography controls, secure software development, source-code escrow for critical vendored applications, IPv6 readiness, teleworking security, and cloud security.
The philosophical shift matters more than any single control. The 2016 framework was, at its heart, a technical-controls checklist that the IT function could own. The 2026 Directions are built as an enterprise risk instrument: cybersecurity and technology risk sit inside the bank's enterprise risk management framework, the Board approves the policies annually, a Board-level IT Strategy Committee meets at least quarterly, and — the single most consequential org-chart line in the whole document — the CISO reports to the executive who oversees risk management, not to the IT head. The regulator has effectively ended the era of the CISO who reports to the CIO whose budget the CISO's findings threaten.
ScopeWhich rulebook applies to you now — banks, NBFCs, PSOs
The most common confusion we're hearing in the first week is scope. The 2026 Directions do not sweep every RBI-regulated entity into one net. Here's the map as it stands in August 2026:
| You are… | Your primary cyber rulebook today | What changed on 31 July 2026 |
|---|---|---|
| Commercial bank (banking company, corresponding new bank, SBI) | The new 2026 Directions — effective immediately | Everything. The 2016 framework and the patchwork around it are consolidated; your compliance mapping needs rebuilding against the new clause structure. |
| Small finance bank, payments bank, local area bank | Existing instructions continue — explicitly excluded from the 2026 Directions | Nothing yet. Watch this space: RBI's pattern is to extend commercial-bank instruments down-market after a stabilisation cycle. |
| NBFC (₹500 crore+ asset base and up) | ITGRCA Master Direction (Nov 2023, effective Apr 2024) + the NBFC IT Framework it consolidated | Nothing directly — but the 2026 Directions telegraph where NBFC supervision is heading. Treat them as your two-year preview. |
| Non-bank PSO (payment aggregator, card network, PPI issuer, etc.) | Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024) | Nothing on 31 July — but note your own clock: large PSOs went live 1 April 2025, medium PSOs went live 1 April 2026 (four months ago), small PSOs land 1 April 2028. |
| Fintech partnering with any of the above | Contractually inherited — your bank/NBFC/PSO partner's obligations flow into your SLA | Expect your partner banks to re-paper vendor-risk clauses against the 2026 Directions' outsourcing and escrow language over the next two quarters. |
What actually changedThe six shifts that will decide your next audit
The CISO comes out from under IT
The CISO now reports to the executive overseeing risk management — explicitly not the IT head — and presents cybersecurity preparedness to the Board or its committee every quarter. For most mid-tier banks this is an org-chart change with budget-line consequences: security spending stops competing inside the IT budget it exists to audit.
Was: The 2016 framework required a CISO but was silent enough on reporting lines that CISO-under-CIO remained the dominant Indian pattern.Testing cadences are now hard numbers, not "periodic"
Vulnerability assessments at least every six months. Penetration testing at least annually for critical / internet-facing systems. Fresh testing after new implementations and major upgrades — meaning the go-live gate now includes a security test, not just UAT. Testing by independent, qualified assessors.
Was: "Periodic" VA/PT under the 2016 framework — which in practice meant annual VAPT scheduled to precede the inspection, and quietly skipped change-triggered testing.DR moves from paper to proof-of-life
DR drills for critical systems at least every six months — and the drill isn't a checklist walkthrough: the DR site must actually run as primary for at least one full business day. Critical systems carry a near-zero RPO expectation. If your DR strategy is an annual failover test on a Sunday morning with a scripted fail-back before Monday opening, it no longer clears the bar.
Was: BCP/DR drills required, frequency and depth left largely to the bank's own policy. "DR exists" was auditable on paper.Incident reporting standardises on DAKSH, six hours
Cyber incidents go to RBI through the DAKSH platform within six hours. Combined with CERT-In's own six-hour clock, an Indian bank's incident-response playbook now needs a regulatory-notification workstream that runs concurrently with containment — with pre-drafted templates, pre-assigned owners, and a decision tree for what counts as reportable, because six hours disappears fast at 2 a.m. on a long weekend.
Was: Reporting to RBI's cyber cell within hours of detection under the 2016 framework's Annex 3 — email/portal based, format inconsistencies between entities.The technical scope catches up with 2026 reality
Explicit coverage of data governance, cryptography controls, secure software development, source-code escrow for critical vendored apps, IPv6 readiness, teleworking security, and cloud security. The 2016 framework predates the cloud-first Indian bank; the 2026 Directions assume it. If your cloud estate has been governed by an uneasy mapping of on-prem-era controls, the audit now has language that speaks to it directly.
Was: Cloud, SDLC, and crypto handled through interpretation and scattered supplementary circulars — auditor discretion filled the gap.Cyber risk becomes Board work-product, on a calendar
Board approves IT, cybersecurity, and business-continuity policies annually. The Board-level IT Strategy Committee meets at least quarterly. The Audit Committee owns information-systems audit oversight. Continuous Board training is expected. The evidentiary implication: your Board pack now needs a cybersecurity section with the same rigour as the credit-risk section, and the minutes need to show engagement, not receipt.
Was: Board oversight required in principle since 2016 (and tightened by ITGRCA in 2023), but cadence and committee structure were softer, and many boards treated the cyber agenda item as a annual formality.The capability mapWhat the audit actually tests for — in technology terms, not brand names
Here's the part most compliance content skips. The Directions are written as control objectives; the audit tests whether you have the capability behind each objective. Below is the mapping we use in audit-prep engagements — each capability described by what it must demonstrably do, because that's what the evidence request will probe. Any vendor whose product genuinely does these things is fine; no vendor logo substitutes for the capability working.
24×7 monitoring with correlated telemetry
A security-operations function — in-house, co-sourced, or managed — that ingests logs from core banking, channels, network, endpoints, identity, and cloud; correlates across them; and produces triaged alerts a human acts on around the clock. Log retention long enough to support forensic reconstruction months later.
Maps to: C-SOC continuity from the 2016 era, incident-detection obligations, and the six-hour DAKSH clock — you can't report in six hours what you detect in six days.
Endpoint detection and response — not just antivirus
Behavioural telemetry on servers and workstations with the ability to isolate a host remotely, kill a process, and pull forensic artefacts. The audit distinction: signature AV satisfies a 2010 control; the 2026 assume-breach posture expects containment tooling that works during an incident, evidenced by drills.
Maps to: incident response and recovery expectations; malware-defence baseline controls carried forward and hardened.
Privileged access management + MFA everywhere that matters
Vaulted, session-recorded, just-in-time privileged access for admins (including vendors); MFA on every remote, privileged, and customer-facing administrative path; joiner-mover-leaver hygiene proven by recertification records — because orphaned accounts are the first thing inspectors sample.
Maps to: access-control baselines, teleworking security, vendor-access clauses of the outsourcing coverage.
Segmentation that actually holds
Core banking, SWIFT/payment interfaces, ATM switching, and corporate IT in separately-controlled zones with policy-enforced east-west restrictions — and evidence the segmentation holds under test (a segmentation-validation exercise, not a diagram). Flat networks behind a strong perimeter are the single most common Indian bank finding.
Maps to: network-security baselines carried from Annex 1 into the consolidated framework; the drills that must now demonstrate containment.
Data governance, DLP, and cryptography with an inventory
Classified data inventory; leak-prevention controls on email, web, and endpoints tuned to the classification; encryption at rest and in transit with a documented key-management lifecycle. The new cryptography coverage means "we use TLS" stops being an answer — the auditor can now ask for the crypto inventory and the deprecation plan for weak suites.
Maps to: the new data-governance and cryptography-control coverage; DPDP Act obligations run in parallel on the same estate.
Backups that survive the attacker, DR that survives the drill
Immutable or logically air-gapped backup copies for critical systems (a ransomware operator with domain admin must not be able to encrypt the backups too); restore times tested against RTO; and a DR capability that genuinely runs production for a full business day every six months — application-level, not just infrastructure-level failover.
Maps to: the half-yearly DR-as-primary drill mandate and near-zero RPO expectation for critical systems.
A standing VAPT programme + adversary-emulation muscle
Six-monthly VA and annual PT as the floor, by independent qualified assessors, with change-triggered testing wired into the release gate — plus, for banks that want to be ahead of the inspection rather than behind it, periodic breach-and-attack-simulation or red-team exercises that test the detection and response capabilities above, not just the vulnerability surface.
Maps to: the hard VA/PT cadence; the assume-breach philosophy the whole 2026 instrument is built on.
Vendor risk that reaches the code
A third-party risk register with tiering; contractual audit and incident-notification rights; source-code escrow for critical vendored applications; and concentration-risk visibility (what breaks if this one vendor goes down?). Fintech partnerships get the same treatment as legacy vendors.
Maps to: the outsourcing and escrow coverage consolidated into the 2026 Directions.
The playbookThe 90-day audit-readiness sequence we'd run
Weeks 1–2 — Re-map compliance against the new clause structure
Your existing traceability matrix maps controls to the 2016 annexes and the ITGRCA clauses. Rebuild it against the 2026 Directions. Most controls carry over; the gaps cluster in the new coverage areas — cryptography inventory, source-code escrow, cloud, DR-drill depth, CISO reporting line.
Weeks 2–4 — Fix the org chart and the calendar first
The cheapest findings to close are governance findings. Move the CISO reporting line if it still runs into IT. Constitute or re-charter the IT Strategy Committee with quarterly meetings scheduled through FY27. Book the Board's annual policy-approval agenda item. Put the six-monthly VA, annual PT, and six-monthly DR-drill dates in the calendar now — a scheduled cadence is evidence in itself.
Weeks 3–6 — Run the gap VA and a DAKSH fire-drill
If your last VA is more than six months old you're already out of cadence — run it now. In parallel, table-top the six-hour DAKSH notification: who decides reportability, who drafts, who submits, what the template says at hour two when facts are still thin. Do the same for the CERT-In parallel notification.
Weeks 6–10 — Prove the DR drill can meet the new bar
Schedule the first DR exercise that runs the DR site as primary for a full business day. Expect the first attempt to surface application-level dependencies nobody documented — that's the point of doing it before the inspector asks for the drill report rather than after.
Weeks 8–12 — Close the new-coverage gaps with owners and dates
Crypto inventory, escrow agreements for critical vendored apps, cloud-security control mapping, teleworking policy refresh. None of these need to be finished in 90 days — they need to be owned, planned, and progressing, because "we identified it and here's the dated plan" audits entirely differently from silence.
Honest limitsWhat we don't know yet — and where the pain will actually land
Immediate effectivity meets supervisory reality. The Directions are effective on issue, but no inspector expects a mid-size bank to have re-papered a decade of compliance in a quarter. What they will expect — based on how ITGRCA rollouts were supervised through 2024-25 — is evidence of a structured transition: the gap assessment done, the governance changes made, the cadence calendar live. Banks that show up to the next inspection with the 2016-era matrix and no transition narrative are the ones that will collect findings.
Interpretation questions are open. What exactly qualifies as a "critical" system for the near-zero RPO expectation, how deep the source-code escrow requirement reaches into SaaS, how the Directions interact with the ITGRCA instrument for entities covered by both — these will get clarified through FAQs and inspection practice over the next few quarters, the way every RBI instrument matures. Where the text is ambiguous today, document your interpretation and the reasoning; a defensible reading beats a lucky one.
The cost curve is real and uneven. For the top-ten banks, most of this is formalisation of what already exists. The pain lands on mid-tier and smaller commercial banks where the CISO office is three people, the SOC is a vendor contract signed in 2021, and DR-as-primary-for-a-day has never actually been attempted. For that tier, the honest sequencing conversation — what to build, what to co-source, what to defer with a documented plan — matters more than any tool purchase. Anyone who responds to this circular by quoting you a product bundle before a gap assessment is selling, not advising.
Where Ogma fitsBrief, and deliberately vendor-neutral
Ogma works the assurance side of this equation for BFSI clients: VAPT programmes run to the new cadence with CERT-In-format reporting, breach-and-attack simulation that tests detection and response the way the assume-breach philosophy expects, firewall and configuration reviews against RBI baselines, a curated threat-intelligence feed, and vCISO engagements for entities that need the governance layer — the committee charters, the Board pack, the DAKSH playbook — stood up without a full-time hire. We're a VAR too, and candidly: we sell security products from multiple OEMs. But audit-readiness work is capability work, not procurement work, and we'd rather be the firm that told you what the gap assessment actually found.
Want a gap assessment against the 2026 Directions?
We'll map your current estate against the new framework — governance, testing cadence, DR depth, and the new coverage areas — and hand you a written gap register with owners, effort estimates, and a defensible 90-day sequence. Fixed scope, no product pitch attached.
Book a gap assessment +91 80 0979 0979 · [email protected]Common questionsFAQ
We're an NBFC — do the 2026 Directions apply to us?
Not directly. The 2026 Directions apply to commercial banks (banking companies, corresponding new banks, and SBI) and explicitly exclude small finance banks, payments banks, and local area banks. NBFCs continue under the ITGRCA Master Direction (November 2023, effective April 2024). That said, RBI's consistent pattern is to extend commercial-bank instruments to other regulated entities after a stabilisation cycle — treat the 2026 Directions as a preview of your own supervisory future, and harvest the cheap wins (CISO reporting line, cadence calendar, DR-drill depth) early.
Our last VAPT was eight months ago. Are we non-compliant right now?
Against the letter of the new cadence — vulnerability assessment at least every six months — yes, you're out of cycle. Practically, the right move is to run the VA now and set the standing six-monthly calendar, so that by the time of your next inspection the cadence is established and evidenced. An inspector reviewing a bank in transition looks for the trajectory; a VA run in August 2026 with the next one scheduled for February 2027 reads very differently from a VA that's simply stale.
What does the DR drill actually have to demonstrate now?
Three things that most legacy drill programmes don't: the drill happens at least every six months for critical systems; the DR site genuinely operates as primary for at least one full business day — meaning real transactions, real interfaces, real users, not an infrastructure failover validated by a ping; and critical systems work toward a near-zero recovery point objective. The first honest attempt at a full-business-day DR-as-primary run almost always surfaces undocumented application dependencies — which is precisely why you want that discovery to happen in your own drill, not in an actual disaster or an inspector's file review.
How does the 6-hour DAKSH reporting interact with the CERT-In 6-hour rule?
They're parallel obligations to different authorities: DAKSH is RBI's supervisory platform; CERT-In's reporting obligation stems from its 2022 directions and applies to Indian entities broadly. A reportable banking cyber incident will usually trigger both clocks at once. The operational answer is a single incident-notification workstream in your IR plan that drafts once and files twice — with pre-agreed templates, a designated decision-maker for reportability, and the discipline to file an initial report on partial facts rather than waiting for a complete picture that arrives at hour nine.
Does the CISO really have to stop reporting to the CIO?
The 2026 Directions place the CISO's reporting line with the executive overseeing risk management, explicitly not the head of IT, with quarterly preparedness reporting to the Board or its committee. For banks where the CISO currently sits under the CIO, this is an org-chart change to make now — it's visible, it's cheap relative to technical remediations, and it's the kind of structural finding an inspector can spot from the organogram alone.
We run significant workloads in cloud. What changes?
The 2026 Directions bring cloud security into the consolidated framework's explicit scope, alongside outsourcing controls, which means cloud estates get examined with direct regulatory language rather than through interpretive mapping of on-prem controls. Practical expectations: a cloud security posture you can evidence (configuration baselines, identity and key management, logging into your monitoring capability), the same testing cadence applied to cloud-hosted critical systems, and vendor-risk treatment of your cloud providers including concentration-risk analysis. If your cloud governance document was written as an annexe to an on-prem policy in 2021, it's due a rewrite.
Can Ogma help without pushing a specific vendor's stack?
Yes — that's deliberate in how this engagement is scoped. The audit tests capabilities, not logos, and most banks arrive with a multi-vendor estate that mostly works. Our audit-prep work is assessment and assurance: gap register against the 2026 Directions, VAPT to the new cadence, BAS exercises that test detection and response, configuration reviews, and vCISO support for the governance layer. Where a genuine capability gap needs a product to fill it, we'll say so and give you options — but the gap assessment comes first, and it stands on its own.
ReferencesSources
The 2026 Directions — coverage and analysis
- Medianama — Lowdown: RBI issues new cybersecurity framework for commercial banks (August 2026)
- VARINDIA — RBI's new cyber rules demand action
- RBI — Master Directions index (primary source for the Directions text)
The regulatory stack it sits in
- RBI — Cyber Security Framework in Banks (2 June 2016) — now superseded for commercial banks
- RBI — Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023)
- RBI — Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024)
- CERT-In — Directions under Section 70B(6), IT Act (April 2022) — the parallel 6-hour reporting obligation
Stay ahead of cyber threats
One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.