RBI Cybersecurity Framework Checklist
Compliance checklist reflecting the RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, which repealed the 2016 Cybersecurity Framework for Banks and the 2023 Master Direction on IT Governance effective 31 July 2026. Sibling Directions cover SFBs, payments banks, UCBs, NBFCs and CICs. Covers 32 controls across six areas (governance, SOC, incident reporting, technical controls, third-party risk, business continuity) representing practices that carry forward under the new framework — not every clause of the current Directions is represented individually.
24×7
SOC
Required for banks
2-6 hrs
Incident Report
To CSITE/RBI
Quarterly
VAPT
Vulnerability testing
Annual
BCP Drill
Including cyber crisis
Related Compliance Frameworks
International ISMS standard — 93 controls across 4 themes. Widely recognised globally.
6-function framework (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) for any organisation size.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
Trust Service Criteria audit covering Security, Availability, Confidentiality, Integrity and Privacy.
India mandatory incident reporting: 6-hour reporting window, 180-day log retention, NTP sync.
Administrative, physical and technical safeguards for electronic Protected Health Information (ePHI).
Frequently Asked Questions
Who does the RBI Cybersecurity Framework apply to?
The RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 apply to commercial banks — banking companies, corresponding new banks and SBI. Five sibling Directions issued the same day (31 July 2026) cover small finance banks, payments banks, UCBs, NBFCs and credit information companies, each with entity-specific requirements.
What is the RBI's incident reporting requirement?
Regulated entities must report cybersecurity incidents to RBI promptly, in specified formats and timelines under the applicable circulars — separate from, but often alongside, CERT-In reporting obligations.
Does RBI require a dedicated SOC?
The framework expects regulated entities to have real-time monitoring capability appropriate to their risk profile; larger banks are generally expected to run or contract a Security Operations Centre.
How does RBI's framework relate to CERT-In Directions?
They are complementary and both apply — CERT-In sets India-wide incident reporting and log-retention baselines under IT Act Section 70B, while RBI's framework adds sector-specific banking governance, risk and reporting requirements.