RBI cybersecurity compliance now reaches almost every regulated financial company, and the rules have tightened significantly in recent years. This guide gives you the full picture: what is required, who it applies to, and how banks, non-banking financial companies, payment aggregators, and the fintechs serving them can approach compliance.
TL;DR
RBI cybersecurity compliance rests on three things: protection (real security controls), compliance (the governance and evidence that prove it), and cyber insurance (the financial backstop). The rules have become legally binding and board-owned, with a framework for commercial banks and a separate one for non-banking financial companies, while payment aggregators stay under their own directions and fintech vendors are scoped through the partners they serve.
Across almost every entity, the common obligations are board-level governance with an independent Chief Information Security Officer, a fixed VAPT cadence, six-hour incident reporting via DAKSH, round-the-clock monitoring, and data localisation. This page maps the whole landscape so you can see how the pieces fit together.
On this page
The three pillars of RBI cybersecurity compliance
It helps to start with the shape of the problem. RBI cybersecurity compliance is really three connected obligations, and treating them as one is where teams go wrong. Protection is the security itself, the controls, testing, and monitoring that actually defend your systems. Compliance is the proof, the governance, policies, audits, and evidence that show a regulator your protection is real. Cyber insurance is the backstop, financial cover for the risk that gets through despite everything else. The order matters: real protection comes first, compliance documents it, and insurance covers the remainder.
Who these rules apply to
RBI cybersecurity rules are not a single framework applied uniformly. Different kinds of regulated entities sit under different, sometimes overlapping, sets of directions, and knowing which apply to you is the first step.
Commercial banks, including the State Bank of India, fall under the current cybersecurity Directions. Non-banking financial companies are covered by their own separate framework, tiered by regulatory layer and asset size, with heavier obligations on larger entities. Payment aggregators remain under the Payment Aggregator Directions, which require an annual system audit by a CERT-In empanelled auditor. Cooperative banks are graded by levels based on the digital services they offer. And fintech or SaaS vendors that sell into these institutions are scoped indirectly, through the security requirements their regulated partners are obliged to enforce. If you build software for a bank or an NBFC, their compliance becomes your requirement.
How the rules recently changed
The latest frameworks were a turning point. They moved cybersecurity from advisory guidance to legally binding requirements, and from a technical, IT-owned function to a board-level governance responsibility. Boards are now expected to own cyber risk on the same footing as credit and market risk. Scattered circulars were consolidated into coherent rulebooks, incident reporting was tightened to a six-hour clock through the named DAKSH platform, and the Chief Information Security Officer was required to be independent of the head of IT. The direction of travel is clear: what applies to commercial banks today tends to reach non-banking financial companies within roughly 12 to 18 months, so even entities not yet in scope should be preparing.
The core obligations at a glance
Depth and timing vary by entity, but a recognisable core runs through the whole framework. If you are in scope in any form, expect to address most of these.
In practice that means board-level governance through an IT Strategy Committee and an Information Security Committee, a Chief Information Security Officer independent of the head of IT, a fixed testing cadence with vulnerability assessments roughly every six months and penetration testing at least annually on critical systems, incident reporting within six hours through DAKSH, round-the-clock security monitoring through a security operations capability, and data localisation for payment data. Around these sit supporting requirements like encryption, access control, vendor and third-party risk management, business continuity and disaster-recovery testing, and secure software development.
The lean-team path to RBI compliance
Meeting all of this, protection, compliance, and insurance readiness at once, is a heavy lift, especially for smaller regulated entities and the fintechs that serve them. The obligations span testing, monitoring, data handling, governance evidence, and vendor risk, and assembling that from separate tools and consultants is slow and hard to keep audit-ready. The efficient path is a single platform that delivers the security work and organises the evidence together.
Meet RBI cybersecurity compliance without a big team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the required testing, speed up incident detection, secure your data, and keep audit-ready evidence, on one platform. No security team required.
Frequently asked questions
What is RBI cybersecurity compliance?
It is the set of security, governance, and reporting obligations the Reserve Bank of India requires of regulated financial entities. These are now legally binding and board-owned, and they span protection (real controls), compliance (governance and evidence), and increasingly cyber insurance as a backstop.
Who has to comply with RBI cybersecurity rules?
Commercial banks, non-banking financial companies, payment aggregators, and cooperative banks, each under their own directions. Fintech and SaaS vendors selling into these institutions are scoped indirectly, through the security requirements their regulated partners must enforce on them.
What are the main RBI cybersecurity requirements?
Board-level governance with an independent Chief Information Security Officer, a fixed VAPT cadence (vulnerability assessment roughly every six months, penetration testing at least annually on critical systems), six-hour incident reporting via DAKSH, round-the-clock monitoring, data localisation, and supporting controls like encryption, access control, and vendor-risk management.
How have the RBI cybersecurity rules recently changed?
Cybersecurity became legally binding and board-owned rather than advisory and IT-owned. Commercial banks and non-banking financial companies came under separate frameworks, incident reporting was tightened to six hours via DAKSH, and the Chief Information Security Officer was required to be independent of the head of IT.
How does RBI compliance relate to the DPDP Act?
They are parallel. RBI rules govern cybersecurity and technology risk for financial entities, while the Digital Personal Data Protection Act governs personal data more broadly. The obligations overlap but are not identical, so most entities map controls to both together rather than separately.
Can Osto make my company RBI compliant?
Osto gets you compliance-ready, it runs the required security work (VAPT, monitoring, data controls) and organises the audit-ready evidence, mapped to the RBI expectations and other frameworks. Formal audits, such as the payment aggregator system audit, are performed by the relevant accredited or CERT-In empanelled auditor. Osto complements that work rather than replacing the auditor.

