Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/437 DoS.CO.CSITEG.31/31.01.015/2026-27 July 31, 2026 Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 Table of Contents Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter I…
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
RBI/DoS/2026-27/437 DoS.CO.CSITEG.31/31.01.015/2026-27 July 31, 2026
Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
Table of Contents
- Chapter I - Preliminary
- A. Short Title and Commencement
- B. Applicability
- C. Definitions
- Chapter II - Role of the Board
- A. Board Approved Policies
- B. Committees of the Board
- Chapter III - Level I Baseline Cybersecurity and Resilience Requirements
- A. Self-Assessment
- B. Cybersecurity Policy
- C. Information Technology Architecture
- D. Cyber Crisis Management Plan
- E. Role of the Board of Directors and Senior Management
- F. Inventory Management of Information Assets
- G. Protection of Customer / Payment Information
- H. Cryptographic Controls
- I. Preventing Access of Unauthorised Software
- J. Environmental Controls
- K. Network Management and Security
- L. Secure Configuration
- M. Anti-virus
- N. Change and Patch Management
- O. User Access Control / Management
- P. Secure Mail and Messaging Systems
- Q. Removable Media
- R. User / Employee / Management / Board Awareness
- S. Customer Education and Awareness
- T. Backup and Restoration
- U. Vendor / Outsourcing Risk Management
- V. Cyber Incident Response and Recovery Management
- W. Deployment of New Application / System
- X. Information Systems Audit
- Chapter IV – Level II Baseline Cybersecurity and Resilience Requirements
- A. Information Technology Resource Planning
- B. Chief Information Security Officer or Equivalent Official
- C. Network Management and Security
- D. Secure Configuration
- E. Application Security Life Cycle
- F. Change and Patch Management
- G. Periodic Testing
- H. User Access Control / Management
- I. Authentication Framework for Customers
- J. Anti-Phishing
- K. Data Leak Prevention Strategy
- L. Database Integrity
- M. Audit Logs
- N. Incident Response and Management
- Chapter V - Level III Baseline Cybersecurity and Resilience Requirements
- A. Network Management and Security
- B. Secure Configuration
- C. Application Security Life Cycle
- D. User Access Control
- E. Advanced Real-time Threat Defence and Management
- F. Maintenance, Monitoring, and Analysis of Audit Logs
- G. Incident Response and Management
- H. User / Employee / Management Awareness
- I. Risk - based Transaction Monitoring System
- Chapter VI - Level IV Baseline Cybersecurity and Resilience Requirements
- A. Cyber Security Operations Centre
- B. Participation in Cyber Drills
- C. Incident Response and Management
- D. Metrics
- E. Forensics
- F. Information Technology Strategy and Policy
- G. Information Technology and Information Systems Governance Framework
- Chapter VII - Repeal and Other Provisions
- A. Repeal and Saving
- B. Application of Other Laws Not barred
- C. Interpretations
In exercise of the powers conferred by Section 27 and Section 35-A read with Section 56 of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
-
These Directions shall be called the Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
-
These Directions shall come into force with immediate effect.
B. Applicability
- These Directions shall be applicable to Urban Co-operative Banks, hereinafter collectively referred to as 'UCBs' and individually as 'UCB'.
For the purpose of these Directions, ‘urban co-operative banks’ means Primary Co-operative Banks as defined under Section 5(ccv) read with Section 56 of Banking Regulation Act, 1949.
- For the purpose of these Directions, a UCB is categorised into one of the four levels based on its digital depth and interconnectedness to the payment systems landscape. Depending on the UCB category, the applicability of Chapter II to Chapter VI of these Directions is as given below:
| Level | Criteria | Applicable Chapters |
|---|---|---|
| Level I | Applicable to the UCB irrespective of digital services / products offered by it. | Chapter II and Chapter III |
| Level II | The UCB which is a sub-member of Centralised Payment Systems (CPS) and satisfies at least one of the criteria given below: (1) offers internet banking facility to its customers (either view or transaction based) (2) provides Mobile Banking facility through an application (Smartphone usage) (3) is a direct member of Cheque Truncation System (CTS) / Immediate Payment Service (IMPS) / Unified Payments Interface (UPI) As per Master Directions on Access Criteria for Payment Systems, 2017, the CPS will include Real Time Gross Settlement (RTGS) System and National Electronic Fund Transfer (NEFT) system and any other system as may be decided by RBI from time to time. | Chapter II, Chapter III and Chapter IV |
| Level III | The UCB which satisfies at least one of the criteria given below: (1) direct member of CPS; (2) has its own Automated Teller Machine (ATM) Switch; (3) has Society for Worldwide Interbank Financial Telecommunication (SWIFT) interface. | Chapter II, Chapter III, Chapter IV, and Chapter V |
| Level IV | The UCB which is a direct member / sub-member of CPS and satisfies at least one of the criteria given below: (1) has its own ATM Switch and SWIFT interface; (2) hosts data centre or provides software support to other banks on its own or through its wholly owned subsidiaries. | Chapter II, Chapter III, Chapter IV, Chapter V, and Chapter VI |
C. Definitions
- The following definitions are sourced from FSB Cyber Lexicon unless explicitly mentioned otherwise. In these Directions, unless the context states otherwise, the terms herein shall bear the meanings assigned to them below:
(1) ‘Audit Trail’ - A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result. (Source: NIST SP 800-53r5 on Security and Privacy Controls for Information Systems and Organizations)
(2) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity.
(3) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems.
(4) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems.
(5) ‘Cyber Event’ - Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring.
(6) ‘Cyber Incident’ - A cyber event that adversely affects the cybersecurity of an information asset whether resulting from malicious activity or not. (Source: Cyber incident definition is adapted from FSB Cyber Lexicon. By the definition, it includes cybersecurity incidents as well as IT incidents)
(7) ‘Cyber Resilience’ - The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing and rapidly recovering from cyber incidents.
(8) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved.
(9) ‘Cyber Threat’ - A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity.
(10) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt or gain unauthorised access to assets.
(11) ‘De-militarised Zone or DMZ’ - A perimeter network segment that is logically between internal and external networks. (Source: NIST SP 800-82 Rev. 2)
(12) ‘Digital Forensics’ - The process used to acquire, preserve, analyse, and report on evidence using scientific methods that are demonstrably reliable, accurate, and repeatable. (Source: adapted from NIST Cloud Computing Forensic Science Challenges)
(13) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously.
(14) ‘Framework’ - A structured set of strategies, policies, processes, methods, and best practices that guides organisational activities, enables governance and control, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary and ISO 22340:2024)
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period