RBI notification RBI/DoS/2026-27/410 · 31 Jul 2026
Summary
Check the official recordThe Reserve Bank of India establishes a comprehensive framework for cybersecurity, technology risk, and resilience for commercial banks. The directions mandate robust IT governance, including board-level oversight through an IT Strategy Committee and an Information Security Committee. Banks must implement baseline cybersecurity requirements, including inventory management, data leak prevention, secure configuration, and continuous surveillance via a Cyber Security Operations Centre. The framework requires periodic vulnerability assessments, penetration testing, and business continuity planning. Banks must report cyber incidents to the RBI within six hours of detection. Foreign banks operating in India through branch mode may follow a comply-or-explain approach for specific chapters and paragraphs. These directions replace previous cybersecurity and IT governance guidelines.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
RBI/DoS/2026-27/410 DoS.CO.CSITEG.4/31.01.015/2026-27 July 31, 2026
In exercise of the powers conferred by Section 27 and Section 35-A of the Banking Regulation Act, 1949, the Reserve Bank of India Act, 1934, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues Directions hereinafter specified.
These Directions shall be called the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
These Directions shall come into effect immediately upon issuance.
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949.
(1) Inventory Management of Information Assets – Paragraph 49 (2) Data Migration Controls – Paragraph 55 (3) Physical and Environmental Controls – Paragraphs 62, 63 (4) Capacity Management – Paragraphs 64 and 65 (5) Application Security Life Cycle – Paragraphs 89, 90, 92 (6) Maintenance, Monitoring, and Analysis of Audit Logs – Paragraphs 93 and 95 (7) Patch, Vulnerability and Change Management – Paragraph 98 (8) User Access Control / Management – Paragraphs 104, 105 and 110 (9) Controls on Teleworking – Paragraph 114 (10) Third-Party Arrangements – Paragraph 126 (11) Cryptographic Controls – Paragraph 140 (12) Straight Through Processing - Paragraphs 141 and 142 (13) Vulnerability Assessment (VA) and Penetration Test (PT) - Paragraphs 151 to 155 (14) Business Continuity (BCP) and Disaster Recovery (DR) – Paragraphs 163 to 174 (15) Cyber Incident Response and Recovery Management – Paragraphs 175, 181, 183, 187, and 190 (16) Metrics – Paragraphs 195 and 196
The ‘comply or explain’ approach shall allow such foreign bank to deviate from any specific part of the above referred Chapters and select paragraphs of Chapter V of these Directions subject to examination and acceptance by RBI of a reasonably justifiable explanation for the same, as part of the supervisory process.
(1) ‘Audit Trail’ - A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result. (Source: NIST SP 800-53r5 on Security and Privacy Controls for Information Systems and Organizations)
(2) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity.
(3) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems.
(4) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems.
(5) ‘Cyber Event’ – Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring.
(6) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved.
(7) ‘Cyber Incident’ - A cyber event that adversely affects the cybersecurity of an information asset whether resulting from malicious activity or not. (Source: Cyber incident definition is adapted from FSB Cyber Lexicon. By the definition, it includes cybersecurity incidents as well as IT incidents)
(8) ‘Cyber Resilience’ - The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing, and rapidly recovering from cyber incidents.
(9) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets.
(10) ‘Cyber Threat’ - A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity.
(11) ‘Data Dictionary’ - A description of data in business terms, including information about the data. It includes elements like data types, structure details, and security restrictions. (Source: ISACA glossary)
(12) ‘De-militarized Zone’ or ‘DMZ’ - A perimeter network segment that is logically between internal and external networks. (Source: NIST SP 800-82 Rev. 2)
(13) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously.
(14) ‘Digital Forensics’ - The process used to acquire, preserve, analyse, and report on evidence using scientific methods that are demonstrably reliable, accurate, and repeatable. (Source: adapted from NIST Cloud Computing Forensic Science Challenges)
(15) ‘Framework’ - A structured set of strategies, policies, processes, methods, and best practices that guides organisational activities, enables governance and control, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary and ISO 22340:2024)