Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
भारतीय įरज़वर् बैंक Reserve Bank of India पयर्वेक्षण ͪ वभाग, भारतीय ǐरज़वर् बैंक, केंद्रȣय कायार्लय, मेकर टावर-ई, 20वीं मंिजल, कफ परेड, कोलाबा, मुंबई-400 005 दूरभाष: 022-2216 1816 ई-मेल: csite@rbi.org.in Department of Supervision, Reserve Bank of India, Central Office, Maker Tower-E, 20th floor, Cuffe Parade, Colaba, Mum…
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
भारतीय रज़र्व बैंक Reserve Bank of India पयर्वेक्षण ͪ वभाग, भारतीय ǐरज़वर् बैंक, केंद्रȣय कायार्लय, मेकर टावर-ई, 20वीं मंिजल, कफ परेड, कोलाबा, मुंबई-400 005 दूरभाष: 022-2216 1816 ई-मेल: csite@rbi.org.in Department of Supervision, Reserve Bank of India, Central Office, Maker Tower-E, 20th floor, Cuffe Parade, Colaba, Mumbai- 400 005 Tel: 022- 2216 1816 Email: csite@rbi.org.in
Ǒहंदȣ आसान है इसका प्रयोग बढ़ाइए RBI/DoS/2026-27/461 DoS.CO.CSITEG. 55 /31.01.015/2026-27 July 31, 2026 Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
Table of Contents
Chapter I – Preliminary ............................................................................................ 3 A. Short Title and Commencement ..................................................................... 3 B. Applicability ..................................................................................................... 3 C. Definitions ........................................................................................................ 4 Chapter II - Role of the Board .................................................................................. 9 A. Board Approved Policies ................................................................................ 9 Chapter III - Requirements for NBFCs (Base Layer with asset size below ₹500 crore) and Core Investment Companies .............................................................. 10 A. Baseline Cybersecurity and Resilience Requirements .............................. 10 Chapter IV - Requirements for NBFCs (Base Layer with asset size ₹ 500 crore and above) .............................................................................................................. 12 A. IT Governance ................................................................................................ 12 B. IT Policy .......................................................................................................... 14 C. Information Security and Cybersecurity ...................................................... 15 D. IT Operations .................................................................................................. 20 E. Information Systems Audit ........................................................................... 22 F. Business Continuity Planning and Disaster Recovery............................... 24 G. IT Services Outsourcing ................................................................................ 25 Chapter V - Requirements for NBFCs (Middle Layer and above excluding CICs) ................................................................................................................................. 28 A. IT Governance ................................................................................................ 28 B. IT and Information Security Risk Management ........................................... 35 C. Baseline Cybersecurity and Resilience Requirements .............................. 36 D. Information Systems Audit ........................................................................... 45 Chapter VI Repeal and Other Provisions ............................................................. 46
RBI (NBFCs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
2 A. Repeal and Saving ......................................................................................... 46 B. Application of other laws Not barred ........................................................... 46 C. Interpretations ................................................................................................ 47
RBI (NBFCs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
3 In exercise of the powers conferred by Section 45-L and 45-M of the Reserve Bank of India Act, 1934, Section 3 read with Section 6 and 31A of the Factoring Regulation Act, 2011, and Sections 30, 30-A, 32 and 33 of the National Housing Bank Act, 1987, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues Directions hereinafter specified.
Chapter I – Preliminary
A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
- These Directions shall come into force with immediate effect.
B. Applicability
- The applicability of these Directions is as follows: (1) The provisions contained in these Directions shall be applicable to all Non- Banking Financial Companies (hereinafter collectively referred to as 'NBFCs' and individually as 'NBFC') registered with RBI under the provisions of the RBI Act, 1934, Factoring Regulation Act, 2011, National Housing Bank (NHB) Act, 1987, unless specified otherwise. (2) The provisions contained in Chapter III shall be applicable only for NBFCs- Base Layer (NBFCs-BL) with asset size below ₹500 crore, and Core Investment Companies (CICs) as defined in Reserve Bank of India (Non- Banking Financial Companies – Registration, Exemptions and Framework for Scale Based Regulation) Directions, 2025. (3) The provisions contained in Chapter IV shall be applicable only for NBFCs- BL with asset size ₹500 crore and above. (4) The provisions contained in Chapter V shall be applicable only for NBFCs- Top Layer (NBFCs-TL), NBFCs-Upper Layer (NBFCs-UL), and NBFCs-
RBI (NBFCs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
4 Middle Layer (NBFCs-ML) as defined in Reserve Bank of India (Non- Banking Financial Companies – Registration, Exemptions and Framework for Scale Based Regulation) Directions, 2025, excluding CICs.
C. Definitions
- The following definitions are sourced from FSB Cyber Lexicon unless explicitly mentioned otherwise. In these Directions, unless the context states otherwise, the terms herein shall bear the meanings assigned to them below. (1) ‘Audit Trail’ - A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result. (Source: NIST SP 800-53r5 on Security and Privacy Controls for Information Systems and Organizations) (2) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity. (3) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems. (4) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. (5) ‘Cyber Event’ – Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring. (6) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non- repudiation, and reliability can also be involved. (7) ‘Cyber Incident’ - A cyber event that adversely affects the cybersecurity of an information asset whether resulting from malicious activity or not.
RBI (NBFCs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
5
(Source: Cyber incident definition is adapted from FSB Cyber Lexicon. By the definition, it includes cybersecurity incidents as well as IT incidents.) (8) ‘Cyber Resilience’ - The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing, and rapidly recovering from cyber incidents. (9) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets. (10) ‘Cyber Threat’ - A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity. (11) ‘Data Dictionary’ - A description of data in business terms, including information about the data. It includes elements like data types, structure details, and security restrictions.
(Source: ISACA glossary) (12) ‘De-militarized Zone’ or ‘DMZ’ - A perimeter network segment that is logically between internal and external networks. (Source: NIST SP 800-82 Rev. 2) (13) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously. (14) ‘Digital Forensics’ - The process used to acquire, preserve, analyse, and report on evidence using scientific methods that are demonstrably reliable, accurate, and repeatable. (Source: adapted from NIST Cloud Computing Forensic Science Challenges) (15) ‘Framework’ - A framework is a structured set of strategies, policies, procedures, methods, and best practices that guides organisational
RBI (NBFCs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
6 activities, enables governance, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary and ISO 22340:2024) (16) ‘Information Asset’ - Any piece of data, device, or other component of the environment that supports information-related activities. Information assets include information system, data, hardware, and software. (Source: Information Asset definition is adapted from “Guidance on cyber resilience for financial market infrastructures” publication of Bank for International Settlements and International Organization of Securities Commissions of June 2016) (17) ‘Information Systems (IS)’ - Set of applications, services, information technology assets, or other information-handling components, which includes the operating environment and networks. (18) ‘Integrity’ - Property of accuracy and completeness. (19) ‘Information Technology (IT) Governance’ - The responsibility of executives and the board of directors; consists of the leadership, organisational structures, and processes that ensure that the enterprise’s IT sustains and extends the enterprise's strategies and objectives. (Source: ISACA glossary and COBIT) (20) ‘IT Risk’ - The business risk associated with the use, ownership, operation, involvement, influence, and adoption of IT within an enterprise. (Source: ISACA glossary) (21) ‘Malware’ - Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems.
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period