RBI cybersecurity compliance for NBFCs now starts with one question most checklists skip: which NBFC layer are you in? The controls expected from a small Base Layer NBFC are not identical to those expected from a Middle, Upper or Top Layer institution.
TL;DR
The RBI’s Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 apply to RBI-registered NBFCs and came into force immediately on 31 July 2026. Every NBFC needs board-approved technology and cybersecurity strategies and policies, reviewed at least annually.
What comes next depends on classification. Base Layer NBFCs below ₹500 crore and CICs follow baseline requirements under Chapter III. Base Layer NBFCs at ₹500 crore and above follow the fuller Chapter IV framework. Middle, Upper and Top Layer NBFCs, excluding CICs, follow Chapter V. Digital lending, outsourcing and other activity-specific rules may apply alongside this framework.
What changed for NBFC cybersecurity compliance in 2026?
RBI consolidated the earlier IT framework and IT governance instructions into an entity-specific direction for NBFCs. These RBI cybersecurity guidelines for NBFCs create a clearer structure built around cybersecurity, technology risk, resilience and assurance rather than a disconnected set of circulars. The direction also formally repeals the previous NBFC IT framework instructions while preserving actions and liabilities already created under them.
The board remains the first line of regulatory accountability. It must approve technology and cybersecurity strategies and policies and review them at least annually. For larger NBFCs, the framework becomes more prescriptive about governance committees, information security responsibility, risk management, technical safeguards, resilience testing and independent assurance.
Which RBI cybersecurity rules apply to your NBFC?
Base Layer below ₹500 crore + CICs
Baseline IT, security and resilience: access controls, defined roles, maker-checker, cybersecurity controls, regulatory reporting capability, board-approved BCP and tested backups.
Base Layer at ₹500 crore and above
Expanded IT governance, IT policy, information security, operations, IS audit, BCP/DR and IT outsourcing requirements.
Middle, Upper and Top Layer
Fuller governance, IT and information-security risk management, baseline cyber-resilience controls and risk-based IS audit. CICs are excluded from this chapter.
Base Layer below ₹500 crore and CICs
The baseline is proportionate, but it is not optional. The NBFC should digitise and secure primary business databases, maintain a board-approved IT/IS policy, define user roles, apply physical and logical access controls, enforce a password policy and use maker-checker controls. Systems should support management reporting and regulatory returns. The board-approved business continuity policy must receive periodic oversight at least annually, and backup arrangements must be tested.
Base Layer at ₹500 crore and above
Chapter IV expects an integrated IT governance framework and defined responsibility across the board, senior management and technology leaders. An IT Strategy Committee must be formed; its chair is an independent director, the CIO and CTO are members, and no more than six months should elapse between meetings. Requirements extend across security policy, access, operations, audit, resilience and outsourcing.
Middle Layer and above
Middle, Upper and Top Layer NBFCs face more developed governance and security requirements. The IT Strategy Committee is board-level, has at least three directors, is chaired by an independent director with substantial IT expertise and meets at least quarterly. A senior executive is designated as CISO with appropriate independence, expertise and resources. The CISO’s office manages and monitors the SOC, drives cyber initiatives and places a cybersecurity review before relevant board-level governance at least quarterly.
The core NBFC cybersecurity requirements to operationalise
Know and classify the technology estate
Maintain a detailed inventory of information assets and map security classification to confidentiality, integrity, availability and business criticality. The inventory should cover on-premise systems, cloud accounts, applications, APIs, databases, endpoints, network devices and material vendor dependencies. A current information security risk assessment should connect these assets to threats, vulnerabilities, impact and treatment decisions.
Control identities and privileged access
Access should exist only for a valid business need. Use defined roles, segregate conflicting duties and log and periodically review elevated activity. For Middle Layer and above, RBI explicitly expects two-factor or multi-factor authentication for privileged users of critical systems and for critical activities based on risk assessment, as well as MFA for enterprise access to critical systems in teleworking environments.
Monitor logs and respond to incidents
Audit trails must be detailed enough for audit, forensic evidence and dispute resolution, and logs should be regularly monitored for unauthorised activity or attack. Incident arrangements need defined classification, escalation, containment, communication, forensic analysis and recovery procedures. For the NBFCs covered by the relevant Chapter V requirement, cyber incidents are reported to RBI through DAKSH within six hours of detection, with proactive notification to CERT-In; HFC reporting continues to NHB as specified by RBI.
Test vulnerabilities throughout the system lifecycle
For Middle Layer and above, critical information systems and customer-facing systems in the DMZ require vulnerability assessment at least once every six months and penetration testing at least once every 12 months. Testing also applies before implementation, after implementation and after changes. It must extend to relevant cloud-hosted systems, use independent and appropriately trained experts, and lead to time-bound remediation that prevents recurrence.
Scanning and penetration testing answer different questions. The Osto guide to VAPT types explains how web, API, mobile, network and cloud testing should be scoped to the real attack surface.
Prove resilience, not just backup completion
Resilience means secure resumption of critical operations, not merely that a backup job displayed “successful.” For Middle Layer and above, critical-system DR drills are required at least half-yearly and should include running normal business operations from the alternate site for at least a full working day. Backups must be restored periodically to test usability, protected from unauthorised access and aligned to approved RTO and RPO.
Key RBI cybersecurity frequencies for NBFCs
Not every control has the same cadence. Treat these as specific requirements where applicable, not a universal schedule for every NBFC layer.
| Requirement | Applies where stated | Important detail |
|---|---|---|
| Board review of technology and cybersecurity strategies/policies | All NBFCs under Chapter II | At least annually |
| ITSC meeting | Base Layer ₹500 crore and above | No more than six months between meetings |
| ITSC meeting | Middle Layer and above | At least quarterly |
| CISO cyber-preparedness review | Middle Layer and above | Presented at least quarterly to the applicable board-level forum |
| VA and PT | Middle Layer and above | VA six-monthly and PT annually for critical/customer-facing DMZ systems; lifecycle tests also apply |
| DR drill | Middle Layer and above | At least half-yearly for critical information systems |
| Cyber incident reporting | As prescribed under Chapter V | RBI through DAKSH within six hours of detection; note the HFC exception |
A practical NBFC cyber security compliance checklist
The RBI NBFC cybersecurity framework 2026 is easiest to implement as a continuous programme: establish applicability, translate clauses into controls, operate those controls, collect evidence and independently test the result.
- Confirm the NBFC classification. Document regulatory layer, asset size, CIC/HFC status, products, digital channels and outsourced activities.
- Build an applicability register. Map Chapter II and the applicable Chapter III, IV or V provisions, then add digital lending, outsourcing, payment and data-protection requirements.
- Map obligations to controls. For every clause, identify the control, accountable owner, technology source, review frequency and expected evidence.
- Establish the governance structure. Approve policies, constitute the required committees and formalise board, ITSC, CISO, CIO, risk and audit responsibilities.
- Inventory and classify assets. Include cloud, applications, APIs, endpoints, data, identities and vendors; flag critical systems and customer-facing DMZ assets.
- Implement and tune security controls. Cover access, MFA, endpoints, cloud, applications, data, logs, vulnerabilities, patches, incidents and resilience.
- Test operation. Run access reviews, VA/PT, restoration tests, DR exercises, incident simulations and independent IS audits at the applicable cadence.
- Keep a regulatory evidence trail. Store dated, attributable proof and report exceptions, overdue remediation and residual risk to the correct governance forum.
What evidence should an NBFC retain?
| Control area | Examples of defensible evidence |
|---|---|
| Governance | Board-approved policies, ITSC constitution, meeting packs, minutes, risk acceptance and budget decisions |
| Assets and risk | Asset inventory, classification, risk register, critical-system list and treatment records |
| Access | Approvals, MFA configuration, privileged logs, joiner-mover-leaver records and signed access reviews |
| Security operations | Log-source coverage, alert tickets, patch records, change approvals and configuration exceptions |
| VA/PT | Scope, independence, results, risk ratings, remediation tickets, retest proof and recurrence checks |
| Incidents | Timeline, classification, containment actions, forensic records, RBI/CERT-In reporting and lessons learned |
| Resilience | BCP/DR plans, RTO/RPO approvals, backup logs, restore proof, full-day DR exercise and corrective retest |
| Vendors | Due diligence, contracts, materiality rating, concentration analysis, monitoring, audit and exit plans |
The strongest evidence is generated while the control operates. A policy shows design; logs, tickets, approvals, reviews and test results show that the control worked. This is the same principle behind a mature information security management system, but RBI compliance still requires direct mapping to the applicable direction.
Run NBFC cybersecurity and compliance from one place.
Osto is a one-stop platform for cybersecurity and compliance. Its 21+ native modules—including WAF, EDR, CSPM, IAM, DLP and SAST—connect the security controls an NBFC operates with the evidence its compliance programme needs.
Map RBI obligations to owners, monitor endpoints, cloud, applications, identities and data, manage findings and retain continuous proof without stitching together separate security and compliance workflows. That unified operating model is why Osto is becoming the default for cybersecurity and compliance.
Book a demo →Frequently asked questions
What is RBI cybersecurity compliance for NBFCs?
It is the governance, technology risk, security, resilience and assurance programme required under the RBI’s NBFC-specific 2026 directions, together with any other rules triggered by the NBFC’s products and outsourcing arrangements.
Do the RBI cybersecurity directions apply to every NBFC?
They apply to RBI-registered NBFCs unless specified otherwise, but the detailed chapter depends on the NBFC’s layer, asset size and CIC status. The requirements are therefore proportionate rather than identical.
What applies to a Base Layer NBFC below ₹500 crore?
Chapter III applies, as it does to CICs. It establishes baseline requirements for secure business databases, a board-approved IT/IS policy, access and password controls, user roles, maker-checker, cybersecurity, reporting capability, BCP oversight and tested backups.
How often must an NBFC conduct VAPT?
For Middle Layer and above, vulnerability assessment is required at least once every six months and penetration testing at least once every 12 months for critical information systems and customer-facing systems in the DMZ. Lifecycle testing and a risk-based approach for non-critical systems also apply.
How quickly must an NBFC report a cyber incident to RBI?
Under the applicable Chapter V requirement, the NBFC must report cyber incidents to RBI through DAKSH within six hours of detection and proactively notify CERT-In. Housing Finance Companies continue reporting to NHB as specified in the direction.
Is ISO 27001 sufficient for RBI NBFC cybersecurity compliance?
No. ISO 27001 can provide a strong management system and control foundation, but it does not replace the RBI’s layer-specific requirements, frequencies, governance structure or reporting obligations. A direct RBI clause-to-control mapping is still required.

