Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
UR
- Applies toFinance companies
- StatusIn force
- ImportanceMUST READ
- IssuedJul 31, 2026
- Amendmentsnone tracked
- Length80 points in 5 sections · 8 min read
The four dates on this rule
- PublishedJul 31, 2026The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actNot statedNo date to act by was found in this document. Other dates may sit inside single paragraphs.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
Show me the points about
79 of the 80 points name no product and bind every product. All products.
Numbers to remember
| Rs 500 crore | Chapter three binds a base layer company below Rs 500 crore in assets. RBI Para 3(2) |
| six months | For a smaller company, no more than six months may pass between committee meetings. RBI Para 15(3) |
| six hours | A cyber incident must be reported on the DAKSH platform within six hours of detection. RBI Para 28 |
| seven years | Real IT skill here means at least seven years of running or guiding IT work. RBI Para 71(2) |
| three months | The IT Strategy Committee must meet at least once every three months. RBI Para 72 |
| 12 months | Critical systems need a scan every six months and an attack test every 12 months. RBI Para 121 |
What it says
Chapter I. Preliminary
Must know
1. Below 500 crore
Chapter three binds a base layer company below Rs 500 crore in assets.
BankPulse example. A base layer company with ₹300 crore of assets is under ₹500 crore. Chapter three applies to it. A company at ₹700 crore is not covered by that chapter.
2. At 500 crore and above
Chapter four binds a base layer company of Rs 500 crore in assets and above.
BankPulse example. A base layer company with ₹700 crore of assets is at ₹500 crore or above. Chapter four applies to it. One at ₹300 crore is not covered by that chapter.
Background
3. Cyber rules for NBFCs
This paper sets the cyber and technology risk rules for non-banking financial companies.
4. Start date
These Directions took effect at once.
5. Split by asset size
Which chapter binds a finance company turns on its asset size and its layer.
6. Who is covered
These Directions apply to every non-banking financial company.
7. Middle layer and above
Chapter five binds middle, upper and top layer companies, but not core investment ones.
Chapter II. Role of the Board
1. Board approves the policies
The Board must approve the plans and policies for technology and cyber security.
Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)
Must know
1. Six months between meetings
For a smaller company, no more than six months may pass between committee meetings.
2. Six hours to report
A cyber incident must be reported on the DAKSH platform within six hours of detection.
Do it
3. Reports to the Board
What the IT Strategy Committee decides must be placed before the Board.
4. Chief information officer
The company must name a senior executive as chief information officer for IT work.
5. Assess IT training needs
The company must check its IT training needs so that skill matches the work.
6. Support IPv6 traffic
Public facing systems of the NBFC must be able to carry IPv6 traffic.
7. Split IT from security
The IT function and the information security function must be kept apart.
8. Check the privileged staff
Staff with access to critical systems must pass a strict background check.
9. Two people to approve
A maker and checker control must require two people before a transaction is done.
10. Use public key methods
The company must widen the use of public key methods to keep data safe and provable.
11. Four steps in a crisis
The crisis plan must cover four steps: detection, containment, response and recovery.
12. Yearly risk assessment
The company must run a full risk assessment of its IT systems at least once a year.
13. Board approved change policy
The company must have a Board approved policy for handling changes to its systems.
14. Test the continuity plan
The company must test its continuity plan at least once a year and after big changes.
Background
15. IS audit once a year
The audit of information systems may be run at least once a year.
Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)
Must know
1. Seven years of skill
Real IT skill here means at least seven years of running or guiding IT work.
2. Committee meets each quarter
The IT Strategy Committee must meet at least once every three months.
3. A steering committee too
A steering group of senior staff must also meet at least once every three months.
4. Keep the two apart
The security officer must not report to the head of IT and gets no business target.
5. Quarterly cyber review
The security officer must place a cyber risk review before the Board every three months.
6. No unsupported software
The NBFC must not run outdated hardware or software that the maker no longer backs.
7. Put the code in escrow
Where the source code cannot be had, the NBFC must place it in escrow.
8. No manual data changes
Data moving between critical systems must not be changed by hand on the way.
9. Six months, then a year
Critical systems need a scan every six months and an attack test every 12 months.
BankPulse example. Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.
10. Drill every six months
Recovery drills for critical systems must be held at least once every six months.
11. Housing companies tell NHB
A housing finance company keeps reporting cyber incidents to NHB and not to RBI.
Do it
12. IT risk sits inside
The wider risk policy must also test IT risk from time to time.
13. Board sees them yearly
These plans and policies must go to the Board for review at least once a year.
14. Three directors at least
The IT Strategy Committee must have at least three directors as members.
15. Chair must be independent
The chair of that committee must be an independent director with real IT skill.
16. Security committee under it
An information security committee must sit under the IT Strategy Committee.
17. Name a head of IT
The NBFC must name a senior officer with real IT skill as head of the IT work.
18. Head of IT duties
The head of IT must keep projects in line with policy and set up the backup site.
19. Name a security officer
A senior officer, best of general manager rank, must be named security officer.
20. Staff and budget for security
The security office must be well staffed and its budget set by the threats seen.
21. Have a security policy
The NBFC must have an information security policy that sets scope, owner and penalty.
22. A separate cyber policy
The cyber security policy must be kept apart from the wider IT policy.
23. Risk committee reviews yearly
The risk committee must review and update the risk policy at least once a year.
24. Security check each year
The NBFC must review its security set up and policies at least once a year.
25. Data migration policy
The NBFC must have a data migration policy that keeps data whole and correct.
26. Keep a data dictionary
The NBFC must keep a data dictionary so that systems share one meaning of data.
27. Guard the data centre
Physical controls must protect the data centre and the backup site from harm.
28. Keep the sites apart
The data centre and the backup site must be far apart in place.
29. Vendors must support it
The NBFC must tie down software support from its vendors by formal agreement.
30. Get the source code
The NBFC must get the source code for every critical application from the vendor.
31. Written word from the vendor
The vendor must confirm in writing that the software carries no known flaw or malware.
32. Check capacity each year
The NBFC must check how much IT capacity it needs at least once a year.
33. Log every critical system
Every system that touches critical or sensitive data must keep an audit trail.
34. Trails must stand as proof
Audit trails must be full enough to serve as proof and to settle a dispute.
35. Watch the audit trails
The NBFC must watch audit trails and system logs to find any attack or misuse.
36. Use strong encryption
Key length, methods and protocols used to send and hold data must be strong.
37. Independent testers only
Scans and attack tests must be run by trained and independent security experts.
38. Follow the ISO standard
The continuity and recovery policy must follow best practice such as ISO 22301.
39. Run on the backup site
A recovery test must run the backup site as the main site for a full working day.
40. Test your backups
The NBFC must back data up and restore it now and then to prove it works.
41. Near zero data loss
The NBFC must aim for the least recovery time and near zero data loss.
42. Both sites must match
The settings and security patches at the main and backup sites must be the same.
43. Have a response policy
The NBFC must have a written policy on how it answers and recovers from an incident.
44. Have an IS audit policy
The NBFC must have an information systems audit policy.
45. Audit policy reviewed yearly
The audit committee must approve that policy and review it at least once a year.
46. Separate IS audit function
The NBFC must have a separate information systems audit function with the right skill.
47. Plan audits by risk
Audit planning must follow a risk based approach.
Background
48. First line of defence
The head of IT is the first line of defence for IT controls and IT risk.
49. Always invited
The security officer is a standing invitee to both the IT committees.
50. Reports to the top
The security officer reports to the executive director who looks after risk.
51. Plan the technology refresh
The NBFC must plan to replace hardware and software before support runs out.
52. Access on business need
Access to information assets is allowed only where there is a real business need.
53. Two factor for privilege
A second factor is needed to sign in for privileged users of critical systems.
54. Rules for remote work
Remote work needs safe systems, a second sign in factor and a list of remote devices.
55. Audit committee oversees IS
The audit committee of the Board oversees the audit of information systems.
Chapter VI. Repeal and Other Provisions
1. Other laws still apply
These Directions add to other laws and rules and do not replace them.
BankPulse example. A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.
2. RBI has the last word
RBI may issue clarifications, and its reading of these Directions is final.
BankPulse example. Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for NBFCs
Every rule page on BankPulse · Questions bankers ask, answered