RBI’s New Cybersecurity Rulebook: From Advice to Law

India’s central bank has replaced its decade-old cybersecurity circular with a binding 233-paragraph framework that makes banking’s IT governance subject to board-level accountability.

The Reserve Bank of India has issued the (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, dated July 31, 2026, formally replacing the 2016 Cyber Security Framework circular. According to a gap-analysis report comparing the two documents, the shift is not merely an update — it’s a change in legal character. The 2016 circular used the word “should.” The 2026 Directions use “shall” and are issued under Sections 27 and 35-A of the Banking Regulation Act, making compliance mandatory rather than advisory.

Governance Takes Centre Stage

While the 2016 rules focused narrowly on technical controls, roughly a third of the new document — three entire chapters — addresses something the old framework barely touched: governance. Boards must now approve cybersecurity policy annually. A dedicated IT Strategy Committee, chaired by an independent director with at least seven years of technology experience, must meet quarterly. The Chief Information Security Officer role, mentioned only once in 2016, is now tightly defined: General Manager rank, no reporting line to the IT head, no business targets, and direct escalation to the Executive Director overseeing risk.

Deadlines Replace Vague Timelines

The report highlights a recurring theme: specificity. Vulnerability assessments are now required every six months for critical systems, penetration tests annually, disaster recovery drills twice a year, and cyber incidents must be reported within six hours on RBI’s DAKSH platform — replacing the old circular’s loosely worded “two to six hours.”

New Ground: Vendors, Cloud, and ATM Networks

Several requirements have no precedent in 2016 at all. Banks must now maintain a source code escrow arrangement for critical applications, implement DMARC to fight email spoofing, and ensure public-facing infrastructure supports IPv6. A particularly detailed addition targets third-party ATM Switch service providers, imposing 24 specific contractual controls covering everything from password hygiene to PCI-DSS compliance.

What Got Dropped

Not everything survived. The 2016 circular’s one-time incident-reporting template, its severity classification system, and its one-off 2016 compliance deadlines are gone, replaced by the DAKSH platform’s own reporting structure. Some narrower provisions — like the express prohibition on macros in office documents — were quietly dropped, seemingly folded into broader controls.

The Bottom Line

For banks that were fully compliant with the 2016 rules, the report notes that technical controls likely remain largely adequate. The real compliance burden lies in the governance apparatus, the new Information Systems Audit chapter, and the sharper periodicities now attached to existing controls — work that will require board time, not just IT budgets.

Author