---
title: "RBI Just Rewrote Its Cybersecurity Rulebook: What Banks & NBFCs Need to Know (2026)"
description: Learn why supply-chain cybersecurity is becoming critical for CyFun compliance and how organizations can improve third-party risk visibility and continuous assurance.
image: https://quantarra.io/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Briefing%20In%20Modern%20Office.png
---

[Skip to content](https://quantarra.io/blog/rbi-just-rewrote-its-cybersecurity-rulebook-what-banks-nbfcs-need-to-know-2026#main-content)

[![logo-2-2](https://quantarra.io/hs-fs/hubfs/logo-2-2.png?width=200&height=44&name=logo-2-2.png "logo-2-2")](https://www.quantarra.io?hsLang=en)

- Products 
  
    - Frameworks 
      
          - [ISO](https://quantarra.io/iso?hsLang=en)
          - [SOC 2](https://quantarra.io/soc-2?hsLang=en)
          - [HIPAA](https://quantarra.io/hipaa?hsLang=en)
          - [PCI DSS](https://quantarra.io/pci?hsLang=en)
          - [GDPR](https://quantarra.io/gdpr?hsLang=en)
          - [NIST](https://quantarra.io/nist?hsLang=en)
          - [CyFun](https://quantarra.io/cyfun?hsLang=en)
          - [NABH](https://quantarra.io/nabh?hsLang=en)
    - Segment 
      
          - [Startups](https://quantarra.io/startup?hsLang=en)
          - [Small & medium](https://quantarra.io/smb?hsLang=en)
          - [Enterprises](https://quantarra.io/enterprise?hsLang=en)
- Resources 
  
    - [Blog](https://quantarra.io/blogs?hsLang=en)
- Company 
  
    - [About](https://quantarra.io/about-us?hsLang=en)
- Select Language 
  
    - [French](https://quantarra.io/fr/?hsLang=fr)
    - [Portuguese](https://quantarra.io/pt/?hsLang=pt)
    - [Spanish](https://quantarra.io/es/?hsLang=es)
    - [Dutch](https://quantarra.io/nl/?hsLang=nl)
    - [Hindi](https://quantarra.io/hi/?hsLang=hi)
    - [English](https://quantarra.io?hsLang=en)

- [Login](https://app.quantarra.io/)

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

# RBI Just Rewrote Its Cybersecurity Rulebook: What Banks & NBFCs Need to Know (2026)

by [Deepak Xavier, chief product officer](https://quantarra.io/blog/author/deepak-xavier-chief-product-officer) on September 24, 2026

On July 31, 2026, the Reserve Bank of India quietly did one of the biggest regulatory clean-outs in its recent history: it repealed roughly 627 legacy circulars in one stroke, including the 2016 [**Cyber Security Framework**](https://quantarra.io/cyfun?hsLang=en) and the 2023 Master Direction on IT Governance, Risk, Controls and Assurance Practices. In their place came a new, entity-specific set of Directions with a six-hour incident-reporting clock and zero transition period.

If you're a bank, NBFC, or an auditor working with regulated financial entities in India, this is the single most consequential compliance change of the year. Here's what actually changed, who it hits, and what to do about it before your next audit.

## **What RBI actually did**

RBI's Department of Supervision repealed the 2016 Cyber Security Framework and the November 2023 IT Governance Master Direction, and replaced them with a new umbrella titled **"Cybersecurity, Technology: Risk, Resilience and Assurance Framework,"** alongside a companion **Digital Payment Security Controls Directions**. Rather than one document for everyone, the RBI issued separate, entity-specific Directions:

1. Commercial Banks — RBI/DoS/2026-27/410
2. Small Finance Banks — RBI/DoS/2026-27/419
3. Payments Banks — RBI/DoS/2026-27/428
4. Urban Co-operative Banks — RBI/DoS/2026-27/437
5. All India Financial Institutions — RBI/DoS/2026-27/456
6. Non-Banking Financial Companies (NBFCs) — RBI/DoS/2026-27/461
7. Credit Information Companies — RBI/DoS/2026-27/470

Five of the seven are structurally near-identical. NBFCs and Urban Co-operative Banks get proportionate, tiered requirements instead of NBFCs split by asset size at ₹500 crore; UCBs are graded across four levels by the digital services they offer.

Work and approvals completed under the old framework aren't voided a savings clause keeps them valid, but every new activity from July 31, 2026 onward is governed by the new Directions.

## **What's actually new, operationally**

The new Directions aren't a light refresh; they tighten reporting speed, testing rigor, and who's accountable:

- **Six-hour incident reporting** to RBI's DAKSH supervisory platform — matching CERT-In's existing six-hour breach-reporting window, so there's no longer a separate, slower clock for RBI.
- **Mandatory cloud security testing** — previously optional or ad hoc, now a standing requirement.
- **Vulnerability assessments at least every six months** and **penetration testing at least annually** for critical systems (not the once-a-year VA some early commentary assumed).
- **Quarterly closure reporting** on outstanding VA/PT findings — open findings can't just sit on a list until the next audit cycle.
- **Semi-annual disaster-recovery drills** for critical systems, with mandatory re-testing of anything that fails.
- **Expanded Security Operations Centre requirements**, including 24/7 SIEM-based monitoring for higher-tier entities.
- **Application security assessments must exceed OWASP Top 10 coverage** — the old baseline is now a floor, not a target.
- **Auditor credentials and competency are formally assessed** at appointment and renewal, not just the audit firm's accreditation.

## **New governance requirements**

The Directions push cybersecurity accountability up to the board, not just the security team:

- **Annual board approval** of the IT, cybersecurity, and business-continuity strategy.
- A dedicated **IT Strategy Committee** of at least three directors, chaired by someone with seven or more years of information-systems experience.
- A **senior CISO reporting directly** to the executive who owns risk management — not buried several layers under IT.
- A **cybersecurity policy kept distinct** from the general IT policy, not folded into it.
- An **Information Systems Audit function** operating under Audit Committee oversight, not just management's own review.

## **Who this applies to, and the zero-transition rollout**

The new Directions cover commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs (scaled by asset size), credit information companies, and all-India financial institutions. Foreign bank branches operate under a "comply or explain" model for certain chapters.

The most disruptive detail is the timing: **every Direction took effect immediately on July 31, 2026, with no grace period.** There was no phased rollout, no six-month runway the old framework was repealed, and the new one was live the same day. The one cushion is a savings clause: work completed and approvals already granted under the old framework remain valid, so an audit finished in, say, March 2026 still counts. Only how you demonstrate compliance going forward changes.

## **What compliance and security teams should do now?**

1. **Gap-map your current program** against the Direction that applies to your entity type — don't assume the 2016 framework's controls carry over one-to-one.
2. **Check your incident-response playbook can actually produce a six-hour DAKSH report** — not just detect an incident in six hours, but have it documented and filed.
3. **Confirm your CISO reporting line and IT Strategy Committee composition** meet the new bar (direct reporting to the risk-owning executive; a committee chair with 7+ years of information-systems experience).
4. **Re-baseline your testing calendar**: VA at least every six months, PT at least annually, DR drills semi-annually, all for critical systems specifically.
5. **Document auditor credentials formally** at appointment and renewal, not just the firm's accreditation.
6. **Treat this as an ongoing evidence problem, not a one-time project** — quarterly closure reporting on VA/PT findings means your evidence trail needs to stay current between audits, not get reconstructed for them.

**How Quantarra fits into this**

Regulatory resets like this one expose the same weakness every time: programs built for annual, point-in-time proof struggle the moment a regulator asks for evidence on a faster clock. [Quantarra's](https://quantarra.io/?hsLang=en) continuous-compliance model an always-current audit trail, automated evidence collection across 300+ connectors, and cross-mapped controls you maintain once and reuse everywhere is built precisely for this kind of shift, regardless of which regulation changes next.

We're actively extending Quantarra's framework coverage to track India-specific regulation, including the frameworks covered in this piece — if RBI's new Directions or [DPDP compliance](https://quantarra.io/blog/dpdp-compliance-is-no-longer-optional-the-business-risks-of-waiting-too-long?hsLang=en) are on your roadmap,[get in touch](https://quantarra.io/about-us?hsLang=en), and we'll walk you through where our coverage stands today.

Spread the word:

[Share this blog post on Twitter](https://twitter.com/intent/tweet?text=I+found+this+interesting+blog+post&url=https://quantarra.io/blog/rbi-just-rewrote-its-cybersecurity-rulebook-what-banks-nbfcs-need-to-know-2026) [Share this blog post on Facebook](http://www.facebook.com/share.php?u=https://quantarra.io/blog/rbi-just-rewrote-its-cybersecurity-rulebook-what-banks-nbfcs-need-to-know-2026) [Share this blog post on LinkedIn](http://www.linkedin.com/shareArticle?mini=true&url=https://quantarra.io/blog/rbi-just-rewrote-its-cybersecurity-rulebook-what-banks-nbfcs-need-to-know-2026)

### Leave a comment:

## Related Articles

#### Segment

- [Startups](https://quantarra.io/startup)
- [Small & medium business](https://quantarra.io/smb)
- [Enterprise](https://quantarra.io/enterprise)

<https://x.com/quantarra_io> <https://www.instagram.com/quantarra_io/> <https://www.linkedin.com/company/quantarra/>

#### Resources

- [Blog](https://quantarra.io/blogs)

#### Community

- [LinkedIn](https://www.linkedin.com/company/quantarra/)
- [Youtube](https://www.youtube.com/@Quantarra_io)
- [Twitter](https://x.com/quantarra_io)
- [Instagram](https://www.instagram.com/quantarra_io/)

---

© Copyright 2025. All rights reserved.

- [Privacy](https://quantarra.io/privacy-policy)
- [Terms](https://quantarra.io/terms-of-service)
- [About](https://quantarra.io/about-us)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Deepak Xavier, chief product officer",
    "url" : "https://quantarra.io/blog/author/deepak-xavier-chief-product-officer"
  },
  "dateModified" : "2026-09-24T11:58:15.773Z",
  "datePublished" : "2026-09-24T11:58:15.000Z",
  "headline" : "RBI Just Rewrote Its Cybersecurity Rulebook: What Banks & NBFCs Need to Know (2026)",
  "image" : [ "https://quantarra.io/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Briefing%20In%20Modern%20Office.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://quantarra.io/blog/rbi-just-rewrote-its-cybersecurity-rulebook-what-banks-nbfcs-need-to-know-2026",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://quantarra.io/hubfs/logo-2.png"
    },
    "name" : "Quantarra"
  }
}
```