The 2016 framework is
officially history.
On July 31, 2026, the Reserve Bank of India issued what is arguably the most comprehensive cybersecurity regulatory document in Indian banking history. It doesn't amend the 2016 Cyber Security Framework — it replaces it entirely, along with every subsequent IT governance circular issued to commercial banks.
The RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 comes into effect immediately upon issuance. There is no transition period. Every commercial bank, from the State Bank of India to the newest private sector bank, is now governed by these 229 numbered obligations across 56 pages and 8 chapters.
What makes this different from previous iterations is its specificity. Where the 2016 framework used language like "banks should periodically…" or "it is advised that…", the 2026 Directions say "the bank shall" — repeatedly, precisely, and with defined frequencies, responsible persons, and committee structures.
The Directions are signed by N. Suganandh, Chief General Manager, Department of Supervision. They supersede all prior cybersecurity and IT governance directions, instructions and guidelines for commercial banks, as enumerated in a companion circular issued the same day.
"The bank shall ensure that the CISO shall not have any direct reporting relationship with the Head of IT Function and shall not be given any business targets."
RBI Directions 2026, Para 27 — effective immediatelyFor CISOs, that single paragraph is the most significant governance change in a decade. If your CISO currently reports to your CTO or CIO, that reporting line must change. If your CISO carries revenue or business targets, those must be removed. The structural independence of the security function is no longer a best practice — it is the law.
What actually changed
versus the 2016 framework
Not everything in the 2026 Directions is new. Many obligations codify supervisory expectations that have evolved through IT examination cycles since 2016. But several areas represent a material step-change.
| Area | 2016 Framework | 2026 Directions | Impact |
|---|---|---|---|
| CISO Position | Senior position recommended; no structural mandate | GM-level mandatory; independent of IT Head; reports to ED overseeing risk; quarterly Board reviews | Critical |
| Board IT Committee | Board awareness encouraged; no composition rules | ITSC mandatory; Chairperson must be independent director with min. 7 years IT experience; quarterly meetings | Critical |
| Incident Reporting Channel | Report to CSITE cell by email within 2–6 hours | Report on DAKSH platform (daksh.rbi.org.in) within 6 hours; also notify CERT-In proactively | Critical |
| C-SOC | C-SOC setup guidelines in an Annex; broadly advisory | Dedicated Chapter VI (12 paragraphs); 3-tier staff model; IOC collection; honeypot services; SIEM mandatory | Critical |
| VAPT Frequency | "Periodically" — no specific timelines | Critical systems: VA every 6 months, PT annually; closure reported to ITSC/ISC quarterly | High |
| Red Teaming | Not mentioned | Para 162 — banks may conduct red teaming exercises; defined in Chapter I definitions | High |
| Cyber Crisis Plan | BCP/DR guidance; CCMP not separately defined | Board-approved CCMP mandatory; covers 15+ threat scenarios including ransomware, DDoS, whaling, vishing | High |
| IT Maturity Metrics | General KPI guidance | Paras 194–197: scorecard mandatory; KPIs/KRIs defined; includes RPO/RTO metrics for all critical systems | High |
| Third-Party (ATM ASPs) | General vendor risk guidance | Para 136–138: 24 specific controls contractually mandated for ATM Switch ASPs including CSOC, VAPT, PCI-DSS | High |
| Transaction Monitoring | Fraud monitoring mentioned broadly | Para 209–210: risk-based transaction monitoring across ALL delivery channels; alternate-channel customer alerts | Medium |
All 8 chapters,
plain language
The Directions are structured across 8 chapters with 229 numbered paragraphs. Here is what each chapter requires and why it matters.
The CISO is now a
risk officer, not a tech officer
Paras 27–28 contain the most consequential governance shift in the Directions. They don't just recommend CISO seniority — they specify reporting lines, budget authority, board access, and independence in terms that are now legally enforceable.
Chapter VI gives the SOC
a regulatory specification
For the first time in an RBI direction, the Cyber Security Operations Centre gets its own chapter with specific governance, capability, and staffing requirements. The 2016 framework had a brief Annex on C-SOC; the 2026 Directions dedicate 12 paragraphs to it.
The bank must put in place a framework for the establishment and operation of a CSOC, commensurate with its technology risk profile, scale and complexity of operations, business requirements, and regulatory obligations. This is not a one-size-fits-all mandate — the Directions acknowledge that a cooperative bank and a large private sector bank have different risk profiles.
Governance arrangements must include Board/ITSC briefing on threat intelligence, establishment of dashboards for effective oversight, formulation of key metrics and reporting structures, and timely communication with all stakeholders.
The CSOC must enable: collection and correlation of logs through SIEM tools; continuous monitoring for anomalies; alert generation; root cause identification; attack classification; IOC collection; dynamic behaviour analysis; analytics dashboards with IP geo-location; and — notably — honeypot services (Para 216.7).
The CSOC's security analytics engine must be capable of processing logs in real time and delivering deep packet inspection. Para 220 requires the CSOC architecture to demonstrate compliance with internal guidelines as well as applicable regulations and laws — meaning CSOC outputs become regulatory evidence.
Level 1: Round-the-clock monitoring by trained personnel with relevant product and vendor certifications.
Level 2: Specialists in network, data, and endpoint security for root cause analysis and corrective actions.
Level 3: Advanced SOC analysts with deep packet analysis, IOC collection, forensic evidence gathering, malware reverse engineering, and custom script development capability.
Banks may use in-house staffing or managed service arrangements — but must define metrics to assess SOC performance and ensure capacity planning for continuity.
VAPT goes from
"periodically" to precisely
The 2026 Directions end the era of interpretation on VAPT frequency. Timelines, production-environment requirements, auditor accountability, and board reporting are now specific.
6 hours. One platform.
Personal liability.
Para 182 replaces the previous email-based cyber incident reporting system with a named digital platform — and the consequences for missing the window are unchanged: personal CISO liability.
Two parallel obligations. Six hours. No exceptions documented in the Directions.
DAKSH (daksh.rbi.org.in) is RBI's Advanced Supervisory Monitoring System. The Directions now formally embed it as the mandatory reporting channel for cyber incidents — replacing the CSITE cell email system that was the prior expectation.
This matters operationally because it means banks need automated incident management systems capable of generating DAKSH-format reports within 6 hours of detection. A CISO relying on manual incident documentation will struggle with this window, particularly for incidents detected outside business hours.
The DAKSH obligation works in parallel with the CERT-In 6-hour reporting window — two separate regulators, two separate reporting channels, same 6-hour clock. RiskSage's multi-regulator deadline engine was designed for exactly this scenario — one detection timestamp, multiple simultaneous compliance clocks.
IB-CART: Threat Intelligence Sharing
Para 184 encourages banks to actively participate in the CISO Forum coordinated by IDRBT and share threat intelligence to the Indian Banks-Centre for Analysis of Risks and Threats (IB-CART). This creates an ecosystem obligation — not just reporting to regulators, but contributing to the shared threat intelligence commons that protects the entire Indian banking system.
How RiskSage maps to
the 2026 Directions
RiskSage was designed around the regulatory obligations of Indian BFSI. Here is an honest assessment of current coverage, partial coverage, and gaps that are being closed now.
Your 90-day action plan
starts today
The Directions are effective immediately. There is no transitional period. Here is a prioritised sequence for CISO teams, ordered by regulatory urgency.
-
1Audit your CISO reporting line — this weekIf your CISO reports to the CTO/CIO or carries business targets, Para 27 is already in breach. Initiate a Board resolution to restructure. Document the transition timeline. RiskSage: CISO Governance Readiness Assessment produces the evidence pack.
-
2Register on DAKSH and test your incident reporting workflowAccess daksh.rbi.org.in and ensure your bank has credentials and a tested workflow to submit cyber incident reports within 6 hours. Your incident response runbook must be updated to include DAKSH as the first step. RiskSage: DAKSH integration in build — use the existing CERT-In automation as a template.
-
3Review ITSC composition against Para 17 requirementsThe ITSC Chairperson must be an independent director with 7 years' IT/cybersecurity experience. Review current Board committee composition. If the requirement is not met, table a proposal to the Board nominations committee. RiskSage: ITSC composition tracker being added to Board Dashboard.
-
4Map your VAPT calendar to the new frequenciesCritical systems need VA every 6 months and PT annually. List your critical systems, check when the last VA/PT was conducted, and schedule the next cycle to meet the new timelines. Ensure CERT-In empanelled auditors are used. RiskSage: VAPT Management module tracks this automatically with SLA alerts.
-
5Document or initiate your Cyber Crisis Management PlanIf you don't have a Board-approved CCMP that covers the 4 dimensions (Detection/Containment/Response/Recovery) and the specific threat scenarios in Para 193, this becomes a material gap in your next IT examination. RiskSage: CCMP Builder produces the document and the Board approval workflow.
-
6Assess your CSOC against Chapter VIChapter VI's 3-tier staffing model and capability requirements (SIEM, IOC, honeypot, deep packet inspection, forensics) are now the regulatory baseline. Conduct a gap assessment against each of Paras 214–223. RiskSage: CSOC Maturity Assessment module will be your structured tool for this.
-
7Schedule the quarterly CISO Board reviewPara 28.7 requires quarterly Board/RMCB/ITSC reviews of cybersecurity risk. If you currently do this annually, schedule three additional reviews for the remainder of the year. Each review needs documented minutes as evidence. RiskSage: Board Pack and Board Pillars generate the Board-ready materials automatically.
-
8Add ATM ASP contractual obligations to your vendor reviewsPara 136–138 mandates 24 specific controls that must be contractually included in ATM Switch ASP agreements — including CSOC setup, SIEM, VAPT, PCI-DSS compliance, and source code audits. Review and update your current ASP contracts. RiskSage: Vendor & Contract Risk module tracks DPA and contractual control compliance.