Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI Update
7 August 2026
Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued on July 31, 2026, establish a comprehensive framework to strengthen cybersecurity, technology risk management, and operational resilience of Commercial Banks. The Directions require banks to implement robust IT and cybersecurity governance through Board-approved policies, dedicated governance committees, and a Chief Information Security Officer (CISO). They prescribe minimum standards for information security, cyber risk management, secure IT infrastructure, third-party risk management, business continuity, disaster recovery, cyber incident response, Cyber Security Operations Centres (CSOCs), information systems audits, and employee and customer awareness. Overall, the Directions aim to enhance cyber resilience, safeguard critical information assets, ensure regulatory compliance, and promote a secure and resilient banking ecosystem.