Skip to content
RBI · India · Banking

RBI Cybersecurity Framework Checklist

Compliance checklist reflecting the RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, which repealed the 2016 Cybersecurity Framework for Banks and the 2023 Master Direction on IT Governance effective 31 July 2026. Sibling Directions cover SFBs, payments banks, UCBs, NBFCs and CICs. Covers 32 controls across six areas (governance, SOC, incident reporting, technical controls, third-party risk, business continuity) representing practices that carry forward under the new framework — not every clause of the current Directions is represented individually.

24×7

SOC

Required for banks

2-6 hrs

Incident Report

To CSITE/RBI

Quarterly

VAPT

Vulnerability testing

Annual

BCP Drill

Including cyber crisis

0%0/32 controls implemented
IT Governance: 0/6
Security Operations Centre (SOC): 0/5
Incident Reporting: 0/4
Technical Controls: 0/8
Third-Party Risk Management: 0/5
Business Continuity & Recovery: 0/4

Frequently Asked Questions

Who does the RBI Cybersecurity Framework apply to?

The RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 apply to commercial banks — banking companies, corresponding new banks and SBI. Five sibling Directions issued the same day (31 July 2026) cover small finance banks, payments banks, UCBs, NBFCs and credit information companies, each with entity-specific requirements.

What is the RBI's incident reporting requirement?

Regulated entities must report cybersecurity incidents to RBI promptly, in specified formats and timelines under the applicable circulars — separate from, but often alongside, CERT-In reporting obligations.

Does RBI require a dedicated SOC?

The framework expects regulated entities to have real-time monitoring capability appropriate to their risk profile; larger banks are generally expected to run or contract a Security Operations Centre.

How does RBI's framework relate to CERT-In Directions?

They are complementary and both apply — CERT-In sets India-wide incident reporting and log-retention baselines under IT Act Section 70B, while RBI's framework adds sector-specific banking governance, risk and reporting requirements.