Compliance

RBI Cyber Security Framework: What Regulated Entities Need to Know

The RBI's cyber expectations are spread across directions that differ by entity type. Here's what regulated entities need in place — and how proportionality works.

The Pelta Team8 min readUpdated Part of RBI Guidelines

The Reserve Bank of India sets cyber security and IT governance expectations for the entities it regulates — banks, NBFCs, cooperative banks and payment operators — through a series of directions and master circulars. There isn't one single document; there are several, and which applies depends on your entity type and size. But common threads run through all of them.

This is a general overview, not legal advice. The applicable directions depend on your entity category, and the RBI updates them over time — always confirm the current, applicable circulars for your institution.

Proportionality is the key idea

The RBI applies its expectations proportionately. A large commercial bank faces the most comprehensive requirements; smaller cooperative banks and NBFCs work to a graded baseline. Getting the scope right — knowing which directions apply to your category — is the first and most important step, because it determines everything that follows.

Recurring expectations across the directions

  • Governance: a board-approved cyber security policy and clear accountability.
  • A baseline of security controls appropriate to the entity's size and risk.
  • Continuous security monitoring, with stronger SOC expectations for larger entities.
  • Incident detection and reporting to the RBI within prescribed timelines.
  • Business continuity, disaster recovery and defined recovery objectives.
  • Governance and risk management of outsourced and third-party arrangements.
  • Periodic audits, VAPT and independent assurance.
A practical route to RBI readiness

Scope

Applicable directions

Assess

Gap analysis

Remediate

Close gaps

Evidence

Map to controls

Report

Within timelines

Don't rebuild for every mandate

Much of what the RBI expects overlaps with ISO 27001, PCI DSS and SEBI CSCRF. Rather than running each as a separate programme, map your controls once and reuse the evidence across all of them — which is how Pelta handles overlapping Indian and global frameworks, so an inspection becomes a demonstration rather than a scramble.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

RBI directions

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding SEBI CSCRF

~65% carried over
Carried over from RBI directions New work for your team

Auto-completed from your existing program

GovernanceRisk assessmentSecurity monitoringIncident reportingBusiness continuityThird-party risk

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

Frequently asked questions

Who do the RBI cyber security guidelines apply to?+

Entities regulated by the Reserve Bank of India — including banks, NBFCs, cooperative banks and payment system operators. The specific directions and depth of requirements vary by entity category and size.

Are RBI cyber requirements the same for all entities?+

No. The RBI applies expectations proportionately, with the most comprehensive requirements for large, systemically important entities and a graded baseline for smaller ones.

What does the RBI expect for incident reporting?+

Regulated entities are generally expected to detect and report cyber incidents to the RBI within prescribed timelines. Confirm the exact requirements in the directions applicable to you.

Do RBI guidelines overlap with SEBI CSCRF?+

Substantially. Both draw on the same security fundamentals, so controls and evidence can be reused across RBI directions, SEBI CSCRF, ISO 27001 and PCI DSS rather than rebuilt.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.