Everything Banks Need to Know About RBI’s Cybersecurity, Technology Risk, Resilience & Assurance Framework, 2026

The Reserve Bank of India (RBI) has issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, bringing into force a unified regulatory framework governing cybersecurity, technology risk, operational resilience and information systems assurance for commercial banks. Effective July 31, 2026, the Directions repeal the existing cybersecurity and IT governance framework and consolidate regulatory expectations into a single document comprising governance, technology management, cyber resilience, incident response, business continuity and audit requirements.

The Directions apply to all commercial banks, excluding Small Finance Banks, Payments Banks and Local Area Banks. Foreign banks operating in India have been provided a “comply or explain” approach for specified provisions where implementation may be constrained by group-level governance structures.

Governance Framework and Board Oversight

The Directions place technology governance under the direct oversight of the Board of Directors, the Risk Management Committee of the Board (RMCB), the Information Technology Strategy Committee (ITSC), and senior management. Banks are required to establish clearly defined governance structures covering technology strategy, cybersecurity, risk management and resilience.

The framework requires banks to adopt formal project management methodologies for technology initiatives, implement enterprise architecture frameworks while deploying new technologies, ensure technology adoption aligns with business strategy and risk appetite, and subject new IT applications to prescribed product approval and quality assurance processes. IT architecture is required to be reviewed annually by the ITSC, with documented justification for any risk-cost trade-off decisions.

Independence of the Chief Information Security Officer

Among the notable governance provisions is the reporting structure for the Chief Information Security Officer (CISO). The Directions mandate that the CISO report directly to the Executive Director or equivalent executive overseeing the risk management function. The CISO is required to present a quarterly review of cybersecurity risks, preparedness and arrangements before the Board, the Risk Management Committee and the IT Strategy Committee.

Technology Risk Management Framework

The Directions require banks to establish an integrated IT and Information Security Risk Management Framework covering information security governance, internal controls, identification of critical information systems, stakeholder responsibilities, secure processing and transmission of information and periodic review of implemented controls.

Banks are required to conduct periodic assessments of technology risks, classify inherent risks, evaluate security infrastructure annually, incorporate threat intelligence into risk management and ensure compliance with information security policies across employees and third-party service providers. Risk assessments are expected to consider business requirements, organisational culture, regulatory obligations, technologies adopted and internal as well as external threats.

Information Asset Management and Infrastructure Security

The framework prescribes comprehensive inventory management of information assets, including applications, infrastructure, business data, customer information, personnel and facilities. Banks are required to classify information based on confidentiality, integrity and availability, maintain enterprise data dictionaries and implement controls for protecting data throughout its lifecycle, including information managed by third-party vendors.

The Directions also prescribe data migration controls, remote wipe capabilities for mobile devices, centralised management of authorised software, timely deployment of security patches, emergency patch management procedures, secure configuration baselines, capacity planning, monitoring of end-of-support hardware and software and technology refresh plans.

Network, Infrastructure and Application Security

Banks are required to maintain updated network architecture diagrams, authorised device inventories, secure wireless infrastructure, multi-layered network defences, intrusion detection and prevention systems, real-time traffic filtering and mechanisms to detect unauthorised devices and abnormal network activity. Public-facing IT infrastructure is required to support Internet Protocol Version 6 (IPv6).

For application security, the Directions prescribe secure coding practices, threat modelling, segregation of development, testing and production environments, comprehensive application security testing throughout the software lifecycle, and assessments extending beyond OWASP Top 10 vulnerabilities. Vendor-developed critical applications must be supported through source code availability, escrow arrangements where necessary, certification confirming freedom from known vulnerabilities and source code audits for critical applications where considered appropriate.

Identity and Access Management

The Directions prescribe strict access governance based on business necessity. Banks are required to implement centralised authentication and authorisation systems, enforce strong password policies, apply the principles of least privilege and separation of duties, monitor privileged user activities, deactivate dormant accounts, and continuously monitor abnormal login behaviour.

Multi-factor authentication is mandatory for privileged users accessing critical information systems and performing critical activities. Administrative privileges on end-user workstations, personal computers and laptops are required to be disabled by default and granted only through defined approval processes for limited durations.

Secure Communications and Third-Party Risk

The Directions require secure email and messaging systems capable of preventing spoofing, malicious attachments, phishing attempts and look-alike domain abuse. Banks are required to implement Domain-based Message Authentication, Reporting and Conformance (DMARC) for their email domains and ensure similar protections are adopted by vendors and business partners.

The framework also prescribes detailed requirements for third-party technology arrangements. Banks remain accountable for outsourced technology risks and are required to undertake vendor due diligence, risk assessments, contractual controls, audit rights, regulatory access, supply-chain risk management and compliance monitoring. Specific baseline cybersecurity controls have been prescribed for third-party ATM Switch Application Service Providers covering infrastructure security, identity management, logging, vulnerability management, Security Operations Centres, source code assurance, incident management and forensic readiness.

Continuous Monitoring, Cyber Defence and Testing

Banks are required to establish Cyber Security Operations Centres (CSOCs) responsible for continuous monitoring of cyber threats. The framework specifies continuous log collection, Security Information and Event Management (SIEM), malware protection, behavioural detection, threat intelligence integration, secure web gateways, anti-phishing mechanisms and internet whitelisting as part of ongoing cyber defence measures.

The Directions prescribe periodic Vulnerability Assessment (VA) and Penetration Testing (PT) for critical systems. Critical customer-facing systems located in the Demilitarised Zone (DMZ) are required to undergo vulnerability assessments at least once every six months and penetration testing at least once every twelve months. The framework further prescribes documented testing methodologies, production-equivalent testing environments, competent and independent auditors, time-bound remediation of vulnerabilities, quarterly monitoring of observations, and periodic reporting to the IT Strategy Committee.

Business Continuity and Cyber Incident Management

The Directions require banks to maintain Business Continuity Plans (BCP) and Disaster Recovery (DR) frameworks aligned with recognised standards. Disaster recovery drills for critical information systems are required at least once every six months, including actual switchover to disaster recovery sites covering a complete business day. Banks are also required to define Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), periodically restore backup data to verify usability, and ensure configuration parity between primary and disaster recovery sites.

A dedicated chapter formalises cyber incident response and recovery management. Banks are required to establish documented incident response policies covering incident classification, responsibilities, reporting mechanisms, communication protocols, containment measures, recovery procedures and evidence preservation. Cyber incidents are required to be reported to RBI through the DAKSH platform within six hours of detection, alongside reporting to the Indian Computer Emergency Response Team (CERT-In), wherever applicable.

Information Systems Audit and Assurance

The Directions introduce a structured Information Systems Audit framework under Board oversight. The audit function is expected to adopt a risk-based approach, covering governance, technology controls, cybersecurity controls, audit trails, resilience measures and compliance with regulatory requirements. The framework also emphasises forensic readiness, continuous monitoring of audit observations and independent assurance over technology risk management processes.

A Consolidated Regulatory Framework

The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 consolidate governance, technology risk management, cybersecurity controls, operational resilience, third-party risk management, cyber incident response, business continuity and information systems assurance into a single regulatory framework for commercial banks. By replacing multiple earlier instructions with one comprehensive set of Directions, RBI has established uniform expectations covering the governance, implementation and assurance of technology and cybersecurity across India’s commercial banking sector.

Top