Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

UR

The four dates on this rule

At a glanceThis paper sets the cyber and technology risk rules for non-banking financial companies. Chapter three binds a base layer company below Rs 500 crore in assets. For a smaller company, no more than six months may pass between committee meetings.

Official RBI page

Numbers to remember

Rs 500 croreChapter three binds a base layer company below Rs 500 crore in assets. RBI Para 3(2)
six monthsFor a smaller company, no more than six months may pass between committee meetings. RBI Para 15(3)
six hoursA cyber incident must be reported on the DAKSH platform within six hours of detection. RBI Para 28
seven yearsReal IT skill here means at least seven years of running or guiding IT work. RBI Para 71(2)
three monthsThe IT Strategy Committee must meet at least once every three months. RBI Para 72
12 monthsCritical systems need a scan every six months and an attack test every 12 months. RBI Para 121

What it says

Chapter I. Preliminary

Must know

1. Below 500 crore

Chapter three binds a base layer company below Rs 500 crore in assets.

BankPulse example. A base layer company with ₹300 crore of assets is under ₹500 crore. Chapter three applies to it. A company at ₹700 crore is not covered by that chapter.

2. At 500 crore and above

Chapter four binds a base layer company of Rs 500 crore in assets and above.

BankPulse example. A base layer company with ₹700 crore of assets is at ₹500 crore or above. Chapter four applies to it. One at ₹300 crore is not covered by that chapter.

Background

3. Cyber rules for NBFCs

This paper sets the cyber and technology risk rules for non-banking financial companies.

4. Start date

These Directions took effect at once.

5. Split by asset size

Which chapter binds a finance company turns on its asset size and its layer.

6. Who is covered

These Directions apply to every non-banking financial company.

7. Middle layer and above

Chapter five binds middle, upper and top layer companies, but not core investment ones.

Chapter II. Role of the Board

1. Board approves the policies

The Board must approve the plans and policies for technology and cyber security.

Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)

Must know

1. Six months between meetings

For a smaller company, no more than six months may pass between committee meetings.

2. Six hours to report

A cyber incident must be reported on the DAKSH platform within six hours of detection.

Do it

3. Reports to the Board

What the IT Strategy Committee decides must be placed before the Board.

4. Chief information officer

The company must name a senior executive as chief information officer for IT work.

5. Assess IT training needs

The company must check its IT training needs so that skill matches the work.

6. Support IPv6 traffic

Public facing systems of the NBFC must be able to carry IPv6 traffic.

7. Split IT from security

The IT function and the information security function must be kept apart.

8. Check the privileged staff

Staff with access to critical systems must pass a strict background check.

9. Two people to approve

A maker and checker control must require two people before a transaction is done.

10. Use public key methods

The company must widen the use of public key methods to keep data safe and provable.

11. Four steps in a crisis

The crisis plan must cover four steps: detection, containment, response and recovery.

12. Yearly risk assessment

The company must run a full risk assessment of its IT systems at least once a year.

13. Board approved change policy

The company must have a Board approved policy for handling changes to its systems.

14. Test the continuity plan

The company must test its continuity plan at least once a year and after big changes.

Background

15. IS audit once a year

The audit of information systems may be run at least once a year.

Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)

Must know

1. Seven years of skill

Real IT skill here means at least seven years of running or guiding IT work.

2. Committee meets each quarter

The IT Strategy Committee must meet at least once every three months.

3. A steering committee too

A steering group of senior staff must also meet at least once every three months.

4. Keep the two apart

The security officer must not report to the head of IT and gets no business target.

5. Quarterly cyber review

The security officer must place a cyber risk review before the Board every three months.

6. No unsupported software

The NBFC must not run outdated hardware or software that the maker no longer backs.

7. Put the code in escrow

Where the source code cannot be had, the NBFC must place it in escrow.

8. No manual data changes

Data moving between critical systems must not be changed by hand on the way.

9. Six months, then a year

Critical systems need a scan every six months and an attack test every 12 months.

BankPulse example. Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.

10. Drill every six months

Recovery drills for critical systems must be held at least once every six months.

11. Housing companies tell NHB

A housing finance company keeps reporting cyber incidents to NHB and not to RBI.

Do it

12. IT risk sits inside

The wider risk policy must also test IT risk from time to time.

13. Board sees them yearly

These plans and policies must go to the Board for review at least once a year.

14. Three directors at least

The IT Strategy Committee must have at least three directors as members.

15. Chair must be independent

The chair of that committee must be an independent director with real IT skill.

16. Security committee under it

An information security committee must sit under the IT Strategy Committee.

17. Name a head of IT

The NBFC must name a senior officer with real IT skill as head of the IT work.

18. Head of IT duties

The head of IT must keep projects in line with policy and set up the backup site.

19. Name a security officer

A senior officer, best of general manager rank, must be named security officer.

20. Staff and budget for security

The security office must be well staffed and its budget set by the threats seen.

21. Have a security policy

The NBFC must have an information security policy that sets scope, owner and penalty.

22. A separate cyber policy

The cyber security policy must be kept apart from the wider IT policy.

23. Risk committee reviews yearly

The risk committee must review and update the risk policy at least once a year.

24. Security check each year

The NBFC must review its security set up and policies at least once a year.

25. Data migration policy

The NBFC must have a data migration policy that keeps data whole and correct.

26. Keep a data dictionary

The NBFC must keep a data dictionary so that systems share one meaning of data.

27. Guard the data centre

Physical controls must protect the data centre and the backup site from harm.

28. Keep the sites apart

The data centre and the backup site must be far apart in place.

29. Vendors must support it

The NBFC must tie down software support from its vendors by formal agreement.

30. Get the source code

The NBFC must get the source code for every critical application from the vendor.

31. Written word from the vendor

The vendor must confirm in writing that the software carries no known flaw or malware.

32. Check capacity each year

The NBFC must check how much IT capacity it needs at least once a year.

33. Log every critical system

Every system that touches critical or sensitive data must keep an audit trail.

34. Trails must stand as proof

Audit trails must be full enough to serve as proof and to settle a dispute.

35. Watch the audit trails

The NBFC must watch audit trails and system logs to find any attack or misuse.

36. Use strong encryption

Key length, methods and protocols used to send and hold data must be strong.

37. Independent testers only

Scans and attack tests must be run by trained and independent security experts.

38. Follow the ISO standard

The continuity and recovery policy must follow best practice such as ISO 22301.

39. Run on the backup site

A recovery test must run the backup site as the main site for a full working day.

40. Test your backups

The NBFC must back data up and restore it now and then to prove it works.

41. Near zero data loss

The NBFC must aim for the least recovery time and near zero data loss.

42. Both sites must match

The settings and security patches at the main and backup sites must be the same.

43. Have a response policy

The NBFC must have a written policy on how it answers and recovers from an incident.

44. Have an IS audit policy

The NBFC must have an information systems audit policy.

45. Audit policy reviewed yearly

The audit committee must approve that policy and review it at least once a year.

46. Separate IS audit function

The NBFC must have a separate information systems audit function with the right skill.

47. Plan audits by risk

Audit planning must follow a risk based approach.

Background

48. First line of defence

The head of IT is the first line of defence for IT controls and IT risk.

49. Always invited

The security officer is a standing invitee to both the IT committees.

50. Reports to the top

The security officer reports to the executive director who looks after risk.

51. Plan the technology refresh

The NBFC must plan to replace hardware and software before support runs out.

52. Access on business need

Access to information assets is allowed only where there is a real business need.

53. Two factor for privilege

A second factor is needed to sign in for privileged users of critical systems.

54. Rules for remote work

Remote work needs safe systems, a second sign in factor and a list of remote devices.

55. Audit committee oversees IS

The audit committee of the Board oversees the audit of information systems.

Chapter VI. Repeal and Other Provisions

1. Other laws still apply

These Directions add to other laws and rules and do not replace them.

BankPulse example. A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.

2. RBI has the last word

RBI may issue clarifications, and its reading of these Directions is final.

BankPulse example. Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.

The same subject for other kinds of institution

The same subject for other kinds of institution.

Other RBI rules for NBFCs

Every rule page on BankPulse  ·  Questions bankers ask, answered