Blog

RBI Cybersecurity Compliance Checklist for NBFCs

Update: RBI released a new cybersecurity law for NBFCs on July 31, 2026.

It replaced all the older rules NBFCs followed. This blog is fully updated to match the new law, so you get the correct, current picture plus a full checklist and answers to the most common questions NBFCs are asking right now.

Cyber attacks on Indian financial companies are rising fast. NBFCs (Non-Banking Financial Companies) now handle huge amounts of digital money and customer data. This makes them a top target for hackers. Whether you run a small gold loan NBFC or a large digital lending platform, the rules that protect your systems just changed. This blog walks you through everything: why compliance matters, what the new law says, a full checklist you can use today, common mistakes to avoid, and answers to the questions NBFC teams keep asking.

Why Cybersecurity Compliance Matters for NBFCs

India’s digital payment growth is huge, and it keeps climbing every year. UPI alone is set to cross 130 billion transactions by the end of 2025, and it already makes up about 80% of retail payments in India, with over 13.5 billion transactions happening every month. NBFCs sit right in the middle of this digital wave. They run loan apps, disbursal systems, KYC databases, and payment integrations that touch millions of customers.

But growth brings risk. In FY 2024-25, UPI fraud caused losses of about ₹485 crore across 632,000 cases. Since FY 2022, total UPI fraud losses have reached ₹2,145 crore across 2.7 million reported cases. These are not small numbers, and NBFCs are a growing part of this digital ecosystem. A single data breach, a single ransomware attack, or a single failed audit can cost an NBFC its licence, its customers’ trust, and years of hard-earned reputation.

This is exactly why RBI keeps tightening its cybersecurity rules. Compliance is not just a legal box to tick. It is what keeps customer money and customer data safe. It is what keeps your NBFC in business.

The Big Change: RBI’s New NBFC Cybersecurity Law (July 2026)

On July 31, 2026, RBI issued the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. The official reference is RBI/DoS/2026-27/461, issued by the Department of Supervision.

This law came into force immediately, not from the next financial year. It replaces the older rules NBFCs used before, including the 2017 IT Framework Master Direction and the 2023/2024 IT Governance Master Direction. If your NBFC’s compliance team is still working off those older documents, your program is now out of date.

RBI did not stop at NBFCs. It issued seven separate versions of this same law on the same day, one for each type of regulated entity: commercial banks, small finance banks, payments banks, urban co-operative banks, all-India financial institutions, NBFCs, and credit information companies. Each version has its own chapters, thresholds, and requirements. Make sure your compliance team is reading the NBFC-specific Directions, and not accidentally applying the banking version, since the details differ.

Why RBI Made This Change

RBI’s Directions are built around a simple idea: technology risk is now business risk. NBFCs today run core lending, KYC, disbursement, and collections almost entirely through digital systems. A cyber incident is no longer just an IT problem. It can freeze loan disbursals, expose customer data, or bring an entire NBFC’s operations to a halt. RBI’s new law tries to make sure the Board of Directors, not just the IT team, owns this risk.

Who Falls Under Which Chapter

The new law does not treat every NBFC the same way. It sorts them by size, using the layers already defined under RBI’s Scale Based Regulation Directions, 2025:

  • Chapter III (light-touch, baseline rules) – NBFCs-Base Layer with assets below ₹500 crore, and Core Investment Companies. These NBFCs mainly need basic IT security, a Board-approved IT/IS policy, backup arrangements, and a basic Business Continuity Plan.
  • Chapter IV (fuller IT governance rules) – NBFCs-Base Layer with assets of ₹500 crore and above. These NBFCs step up into a full IT Governance framework, an IT Strategy Committee, formal Information Security and Cybersecurity policies, IS audits, and structured incident reporting.
  • Chapter V (the strictest, most detailed rules) – NBFCs in the Middle Layer, Upper Layer, and Top Layer (excluding Core Investment Companies). This is the most demanding chapter, covering a dedicated CISO, an Information Security Committee, strict access controls, cryptography standards, vulnerability testing schedules, and detailed disaster recovery metrics.

So a ₹480 crore NBFC and a ₹520 crore NBFC now sit under two very different rulebooks, even though the size gap between them looks small. Knowing your exact layer is the very first step to knowing which obligations apply to you. Get this wrong, and your entire compliance program could be built on the wrong foundation.

RBI Cybersecurity Compliance Checklist for NBFCs (2026)

Use this checklist to test how ready your NBFC really is under the new law. Not every item applies to every NBFC – check your chapter first, then work through the relevant sections.

Board and Governance

  • Get Board approval for your IT and cybersecurity policies, and review them at least once a year.
  • If you’re in Chapter IV or V, set up an IT Strategy Committee (ITSC) chaired by an independent director.
  • In Chapter V, the ITSC chair must have at least 7 years of IT or cybersecurity leadership experience, and the committee must meet at least once every quarter.
  • In Chapter IV, the ITSC must meet at least once every six months.
  • Set up an IT Steering Committee at the executive level to support the ITSC and track project delivery.
  • In Chapter V, form a separate Information Security Committee (ISC), headed by someone from the risk management function, working under the ITSC’s oversight.

CISO and IT Leadership

  • Appoint a Chief Information Security Officer (CISO), ideally at General Manager level or an equivalent senior position.
  • Make sure the CISO does not report to the Head of IT, and has no business sales targets attached to their role.
  • The CISO must report cybersecurity posture, risks, and preparedness to the Board, Risk Management Committee, or ITSC at least once a quarter.
  • Appoint a separate Head of IT Function (CIO or CTO) responsible for IT project execution and DR setup.
  • Keep the Head of IT and CISO roles clearly separate, with no overlapping reporting lines.

Risk Assessment and Audits

  • Run a full IT risk assessment at least once a year, and share the results with the CRO, CIO, and the Board.
  • Get an Information Systems (IS) audit done at least once a year, approved and overseen by your Audit Committee of the Board.
  • Adopt a risk-based audit approach and, where possible, use continuous auditing for your most critical systems.
  • Run vulnerability assessments at least every six months for critical information systems and systems facing customers directly.
  • Run penetration testing at least once every 12 months for those same critical and customer-facing systems.
  • Fix identified vulnerabilities in a time-bound way, and track them against known vulnerability databases (like the CVE database)

Incident Detection and Reporting

  • Build a written cyber incident response and recovery plan that covers classification, communication, and containment.
  • Report cyber incidents on RBI’s DAKSH platform (daksh.rbi.org.in) within six hours of detection – this replaces the older CIMS-based reporting process.
  • Also proactively notify CERT-In (the Indian Computer Emergency Response Team) about cyber incidents
  • Housing Finance Companies should note: cyber incidents still go to NHB, not RBI, even under this new framework.
  • Keep clear internal escalation paths so incidents reach the Board and senior management quickly.
  • Consider sharing threat intelligence with IB-CART (Indian Banks – Centre for Analysis of Risks and Threats), which is optional but encouraged.

Data Protection and Access Control

  • Use two-factor or multi-factor authentication for privileged users accessing critical systems.
  • Set clear role-based access, so no single person controls too much of any process.
  • Follow the maker-checker principle for key transactions and system changes.
  • Use strong, internationally accepted, non-deprecated encryption standards for data in transit and at rest.
  • Maintain full audit trails for every system that touches sensitive or regulatory data.
  • Apply strict controls for teleworking and remote access, including multi-factor authentication for remote logins.

Business Continuity and Disaster Recovery

  • Write a Board-approved Business Continuity Plan (BCP) built around a proper Business Impact Analysis.
  • For NBFCs in Chapter V, run Disaster Recovery (DR) drills at least every six months for critical systems.
  • Test your BCP at least once a year using worst-case scenarios, not just easy ones.
  • Test backups regularly to make sure they actually restore properly, and check the integrity of backed-up data
  • Keep your Data Centre and DR site geographically separated, so one disaster cannot hit both.
  • Define clear Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), and aim for near-zero RPO on your most critical systems.

Vendor and Outsourcing Controls

  • Put cybersecurity clauses in every vendor and outsourcing contract, vetted by legal counsel.
  • Keep the contractual right to audit your vendor’s security practices, and to access their records if RBI needs them.
  • Make sure RBI or its authorised representatives can access relevant vendor documents within a reasonable time.
  • Review vendor risk regularly, especially around concentration risk and single points of failure.
  • Ensure your business continuity plan is not weakened just because a function is outsourced.

Staff Training

  • Run regular cybersecurity awareness training for all staff, not just IT staff.
  • Make sure the Board and senior management also get briefed on emerging cyber threats and trends.
  • Track and measure how well training actually works using periodic assessments or tests
  • Keep an up-to-date record of who has completed training and when
  • Extend awareness efforts to customers, vendors, and other stakeholders where relevant.

Common Compliance Gaps NBFCs Should Fix

Many NBFCs struggle with the same recurring issues:

  • Not knowing their own layer– Getting your Scale Based Regulation layer wrong means you may be following the wrong chapter of the law entirely, either doing too little or wasting effort on rules that don’t apply to you.
  • Governance that exists only on paper – Committees like the ITSC or ISC get created on paper but never actually meet on the required schedule, which shows up quickly in an audit.
  • Mixing the CISO and IT head roles – This creates exactly the conflict of interest the new law tries to prevent, since the same person ends up both building systems and auditing their own security.
  • Missing the 6-hour DAKSH reporting window – Many teams are still mentally planning around the old CIMS process instead of the new DAKSH platform, which can lead to late or missed reporting.
  • Weak vendor oversight – Ignoring third-party and outsourcing risk remains one of the biggest blind spots, especially for NBFCs that rely heavily on fintech partners and loan service providers.
  • Treating VA/PT as a one-time task – Vulnerability assessments and penetration testing need to happen on a fixed schedule (six months and twelve months respectively for critical systems), not just once when a system first goes live.
  • Weak documentation – RBI’s auditors expect written policies, tested plans, and evidence, not just verbal assurances that “we take security seriously.”

Penalties for Non-Compliance

RBI does not take violations lightly. RBI can impose monetary penalties, demand corrective action plans, restrict business operations, stop new product launches, and in serious cases order board-level changes. Penalties depend on the type of entity and how serious the gap is. Beyond formal penalties, non-compliant NBFCs also face closer scrutiny during any future incident, more frequent inspections, and real reputational damage with customers, investors, and partners.

How NBFCs Should Get Started

If your NBFC has not yet reviewed itself against the 2026 Directions, here is a practical way to start:

  • Confirm your layer. Check your asset size and Scale-Based Regulation classification to know whether Chapter III, IV, or V applies to you.
  • Map your current policies against the new chapter. Compare your existing IT, information security, and cybersecurity policies line by line against what the relevant chapter requires.
  • Fix governance gaps first. Committees, reporting lines, and the CISO’s independence are usually the fastest wins and the first thing auditors check.
  • Update your incident reporting process. Make sure your team knows about DAKSH, the six-hour window, and the CERT-In notification requirement.
  • Build a testing calendar. Lock in fixed dates for VA (every six months), PT (every twelve months), and DR drills (every six months for Chapter V) so these don’t get missed.
  • Document everything. Keep records that the Board, auditors, and RBI supervisors can review at any time.

Final Thoughts

The rules just changed, and NBFCs need to update their compliance programs to match. Start by checking which Scale Based Regulation layer your NBFC falls in, since that decides which chapter of the new law applies to you. Then work through governance, the CISO role, incident reporting on DAKSH, vulnerability testing, and vendor oversight. A strong, current compliance program protects your customers, protects your business, and saves you from costly penalties down the line.

Need help updating your NBFC’s cybersecurity program for the RBI Directions, 2026? Talk to our NBFC Advisory team for a full readiness check.

Frequently Asked Questions (FAQs)

What are the RBI Cybersecurity Directions, 2026?

It is a new set of directions from the RBI. It came out on July 31, 2026. It is made just for NBFCs. It covers IT rules, cybersecurity policies, risk checks, incident reporting, backup plans, and IT audits. It replaces the older RBI rules NBFCs used before.

When did the new rules start?

The rules started the same day they were issued. That was July 31, 2026. There was no waiting period. NBFCs had to follow them right away.

Do all NBFCs follow the same rules?

No. The rules depend on your NBFC’s size. Small NBFCs (Base Layer, under ₹500 crore in assets) follow lighter rules. Bigger NBFCs (Base Layer above ₹500 crore, or Middle, Upper, and Top Layer) follow stricter rules.

Where do NBFCs report a cyber incident now?

NBFCs must report on RBI’s DAKSH platform. The website is daksh.rbi.org.in. You must report within six hours of finding the incident. This is new. The old system was called CIMS.

Do Housing Finance Companies report to RBI too?

No. Housing Finance Companies still report cyber incidents to the National Housing Bank (NHB). They do not report straight to the RBI.

Who handles cybersecurity inside an NBFC?

The Board of Directors is in charge overall. They must approve and check the cybersecurity policy every year. Day-to-day work goes to the CISO. The CISO must not report to the IT head. The CISO must update the Board often.

How often should NBFCs test their systems?

For key systems, run a vulnerability check every six months. Run a penetration test every twelve months. Systems that are less critical can follow a simpler schedule based on risk.

What happens if an NBFC breaks these rules?

RBI can fine the NBFC. RBI can also ask for a fix-it plan, limit business activity, or stop new product launches. In serious cases, RBI can push for changes at the board level. The penalty depends on how bad the issue is.

Does outsourcing IT work remove compliance duty?

No. Even if IT work is outsourced, the Board still owns the risk. NBFCs must sign strong contracts, check on vendors often, and keep backup plans strong even when work is outsourced.

Where can I read the full official rules?

RBI published the full text under the reference RBI/DoS/2026-27/461, dated July 31, 2026. Always check RBI’s own website for the exact legal wording. This blog is a simple guide, not a legal document.