{"id":1003,"date":"2026-08-24T18:08:28","date_gmt":"2026-08-24T18:08:28","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1003"},"modified":"2026-08-24T18:08:28","modified_gmt":"2026-08-24T18:08:28","slug":"rbi-cybersecurity-compliance-for-nbfcs","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/rbi-cybersecurity-compliance-for-nbfcs\/","title":{"rendered":"RBI Cybersecurity Compliance for NBFCs"},"content":{"rendered":"\n<!-- Osto blog body for WordPress. Page title intentionally excluded. -->\n<style>\n.osto-nbfc{--brand:#1c267a;--brand2:#4655c5;--ink:#15172d;--muted:#62677a;--line:#e5e7f0;--pale:#f5f6ff;--teal:#09bfa9;max-width:840px;margin:0 auto;color:var(--ink);font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-size:17px;line-height:1.75}.osto-nbfc *{box-sizing:border-box}.osto-nbfc h2{font-size:clamp(26px,3vw,32px);font-weight:700;line-height:1.2;margin:44px 0 16px;letter-spacing:-.5px}.osto-nbfc h3{font-size:clamp(20px,2.5vw,24px);font-weight:700;line-height:1.3;margin:32px 0 12px}.osto-nbfc p{margin:0 0 24px}.osto-nbfc a{color:var(--brand);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.3)}.osto-nbfc ul,.osto-nbfc ol{padding-left:24px;margin:0 0 24px}.osto-nbfc li{margin-bottom:8px}.osto-nbfc .tldr,.osto-nbfc .note{background:var(--pale);border:1px solid #dfe3ff;border-radius:18px;padding:28px;margin:30px 0}.osto-nbfc .tldr h2{margin:0 0 10px}.osto-nbfc .toc{border-top:1px solid var(--line);border-bottom:1px solid var(--line);padding:24px 0;margin:38px 0}.osto-nbfc .toc h3{font-size:15px;text-transform:uppercase;letter-spacing:.12em;margin:0 0 12px}.osto-nbfc .key{border-left:4px solid var(--brand);padding:4px 0 4px 20px;margin:28px 0}.osto-nbfc .key strong{display:block;color:var(--brand);font-size:13px;text-transform:uppercase;letter-spacing:.08em}.osto-nbfc .fig{margin:30px 0;border:1px solid var(--line);border-radius:16px;overflow:hidden;background:#fff;box-shadow:0 10px 34px rgba(28,38,122,.10)}.osto-nbfc .fig-head{padding:20px 22px 5px}.osto-nbfc .fig-head strong{display:block;color:var(--brand);font-size:14px;text-transform:uppercase;letter-spacing:.08em}.osto-nbfc .fig-head span{display:block;color:var(--muted);font-size:14px;margin-top:3px}\n.osto-nbfc .layer-grid{display:grid;grid-template-columns:repeat(3,1fr);gap:1px;background:var(--line);padding:1px}.osto-nbfc .layer{background:#fff;padding:22px 18px;min-height:190px}.osto-nbfc .layer:nth-child(2){background:#f7f8ff}.osto-nbfc .layer:nth-child(3){background:#effaf8}.osto-nbfc .layer .badge{display:inline-block;padding:4px 9px;border-radius:999px;background:#e8eaff;color:var(--brand);font-size:11px;font-weight:800;letter-spacing:.05em}.osto-nbfc .layer h4{font-size:16px;line-height:1.3;margin:12px 0 7px}.osto-nbfc .layer p{font-size:12.5px;line-height:1.5;color:var(--muted);margin:0}\n.osto-nbfc .control-grid{display:grid;grid-template-columns:repeat(3,1fr);gap:1px;background:var(--line);padding:1px}.osto-nbfc .control{background:#fff;padding:18px 16px;min-height:112px}.osto-nbfc .control b{display:block;font-size:14px;color:var(--brand)}.osto-nbfc .control small{display:block;font-size:12.5px;line-height:1.45;color:var(--muted);margin-top:5px}.osto-nbfc .control i{display:grid;place-items:center;width:28px;height:28px;border-radius:8px;background:#eef0ff;color:var(--brand);font-size:12px;font-style:normal;font-weight:800;margin-bottom:9px}\n.osto-nbfc .flow{display:flex;align-items:stretch;gap:7px;padding:20px}.osto-nbfc .flow-step{flex:1;padding:16px 11px;border-radius:13px;text-align:center;background:#eef0ff}.osto-nbfc .flow-step:nth-of-type(3){background:#f5f6fb}.osto-nbfc .flow-step:nth-of-type(5){background:#eaf9f6}.osto-nbfc .flow-step:nth-of-type(7){background:#fff3e8}.osto-nbfc .flow-step b{display:block;font-size:13px;color:var(--brand)}.osto-nbfc .flow-step small{display:block;font-size:11.5px;line-height:1.4;color:var(--muted);margin-top:4px}.osto-nbfc .arrow{align-self:center;color:#aeb5d9;font-weight:800}\n.osto-nbfc .cadence{padding:20px 22px}.osto-nbfc .c-row{display:grid;grid-template-columns:155px 1fr;gap:14px;align-items:center;margin:11px 0}.osto-nbfc .c-label{font-size:13px;font-weight:700}.osto-nbfc .c-track{height:34px;background:#f0f2f8;border-radius:8px;overflow:hidden}.osto-nbfc .c-bar{height:100%;display:flex;align-items:center;padding:0 11px;color:#fff;background:linear-gradient(90deg,var(--brand),var(--brand2));font-size:12px;font-weight:700}.osto-nbfc .c-bar.six{width:72%}.osto-nbfc .c-bar.year{width:100%;background:linear-gradient(90deg,var(--brand),#6875d9)}.osto-nbfc .c-bar.incident{width:32%;background:linear-gradient(90deg,#0c7c70,var(--teal))}\n.osto-nbfc .table-wrap{overflow-x:auto;margin:25px 0 34px;border:1px solid var(--line);border-radius:16px;box-shadow:0 10px 34px rgba(28,38,122,.08)}.osto-nbfc table{width:100%;border-collapse:collapse;font-size:14.5px;line-height:1.5}.osto-nbfc th{background:var(--brand);color:#fff;text-align:left;padding:14px}.osto-nbfc td{vertical-align:top;padding:14px;border-top:1px solid var(--line)}.osto-nbfc tr:nth-child(even) td{background:#fafbff}.osto-nbfc .steps{counter-reset:s;list-style:none;padding:0}.osto-nbfc .steps li{counter-increment:s;position:relative;padding:19px 0 19px 52px;border-top:1px solid var(--line)}.osto-nbfc .steps li:before{content:counter(s);position:absolute;left:0;top:17px;width:33px;height:33px;border-radius:50%;display:grid;place-items:center;background:var(--brand);color:#fff;font-weight:800;font-size:13px}\n.osto-nbfc .cta{background:linear-gradient(135deg,#0e1444,var(--brand) 60%,#303da8);color:#fff;border-radius:20px;padding:36px;margin:52px 0;box-shadow:0 18px 50px rgba(14,20,68,.24)}.osto-nbfc .cta h2{color:#fff;margin:0 0 12px}.osto-nbfc .cta a{display:inline-block;background:#fff;color:var(--brand);border:0;border-radius:999px;padding:11px 19px;font-weight:700;margin-top:6px}.osto-nbfc .faq{border-top:1px solid var(--line);margin-top:8px;padding-top:8px}.osto-nbfc .faq details{border-bottom:1px solid var(--line);padding:6px 0}.osto-nbfc .faq summary{cursor:pointer;list-style:none;padding:16px 4px;font-weight:600;font-size:17px;display:flex;justify-content:space-between;align-items:center;gap:16px}.osto-nbfc .faq summary::-webkit-details-marker{display:none}.osto-nbfc .faq summary:after{content:'+';color:var(--brand2);font-size:22px;font-weight:400}.osto-nbfc .faq details[open] summary:after{content:'\u2013'}.osto-nbfc .faq details p{padding:0 4px 18px;color:var(--muted);margin:0}.osto-nbfc .sources{font-size:14px;color:var(--muted)}\n@media(max-width:640px){.osto-nbfc .tldr,.osto-nbfc .note,.osto-nbfc .cta{padding:22px}.osto-nbfc .layer-grid,.osto-nbfc .control-grid{grid-template-columns:1fr}.osto-nbfc .flow{flex-direction:column}.osto-nbfc .arrow{transform:rotate(90deg);align-self:center}.osto-nbfc .flow-step{width:100%}.osto-nbfc .c-row{grid-template-columns:1fr;gap:5px}.osto-nbfc .c-bar{min-width:110px}}\n<\/style>\n<article class=\"osto-nbfc\">\n<p>RBI cybersecurity compliance for NBFCs now starts with one question most checklists skip: <strong>which NBFC layer are you in?<\/strong> The controls expected from a small Base Layer NBFC are not identical to those expected from a Middle, Upper or Top Layer institution.<\/p>\n<section class=\"tldr\"><h2>TL;DR<\/h2><p>The RBI\u2019s <em>Non-Banking Financial Companies \u2013 Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026<\/em> apply to RBI-registered NBFCs and came into force immediately on 31 July 2026. Every NBFC needs board-approved technology and cybersecurity strategies and policies, reviewed at least annually.<\/p><p>What comes next depends on classification. Base Layer NBFCs below \u20b9500 crore and CICs follow baseline requirements under Chapter III. Base Layer NBFCs at \u20b9500 crore and above follow the fuller Chapter IV framework. Middle, Upper and Top Layer NBFCs, excluding CICs, follow Chapter V. Digital lending, outsourcing and other activity-specific rules may apply alongside this framework.<\/p><\/section>\n<nav class=\"toc\" aria-label=\"On this page\"><h3>On this page<\/h3><ol><li><a href=\"#what-changed\">What changed in 2026<\/a><\/li><li><a href=\"#which-rules\">Which rules apply to your NBFC<\/a><\/li><li><a href=\"#controls\">Core cybersecurity controls<\/a><\/li><li><a href=\"#cadence\">Deadlines and control frequencies<\/a><\/li><li><a href=\"#roadmap\">Implementation roadmap<\/a><\/li><li><a href=\"#evidence\">Evidence to retain<\/a><\/li><li><a href=\"#osto\">How Osto helps NBFCs<\/a><\/li><\/ol><\/nav>\n\n<h2 id=\"what-changed\">What changed for NBFC cybersecurity compliance in 2026?<\/h2>\n<p>RBI consolidated the earlier IT framework and IT governance instructions into an entity-specific direction for NBFCs. These <strong>RBI cybersecurity guidelines for NBFCs<\/strong> create a clearer structure built around cybersecurity, technology risk, resilience and assurance rather than a disconnected set of circulars. The direction also formally repeals the previous NBFC IT framework instructions while preserving actions and liabilities already created under them.<\/p>\n<div class=\"key\"><strong>The practical change<\/strong>Do not begin with a generic \u201cRBI cybersecurity checklist.\u201d Begin with the chapter that applies to your NBFC, then add requirements triggered by your products, outsourcing arrangements and digital channels.<\/div>\n<p>The board remains the first line of regulatory accountability. It must approve technology and cybersecurity strategies and policies and review them at least annually. For larger NBFCs, the framework becomes more prescriptive about governance committees, information security responsibility, risk management, technical safeguards, resilience testing and independent assurance.<\/p>\n\n<h2 id=\"which-rules\">Which RBI cybersecurity rules apply to your NBFC?<\/h2>\n<div class=\"fig\" role=\"img\" aria-label=\"RBI cybersecurity requirements by NBFC layer\"><div class=\"fig-head\"><strong>The applicability map<\/strong><span>Asset size and regulatory layer determine the applicable chapter.<\/span><\/div><div class=\"layer-grid\">\n<div class=\"layer\"><span class=\"badge\">CHAPTER III<\/span><h4>Base Layer below \u20b9500 crore + CICs<\/h4><p>Baseline IT, security and resilience: access controls, defined roles, maker-checker, cybersecurity controls, regulatory reporting capability, board-approved BCP and tested backups.<\/p><\/div>\n<div class=\"layer\"><span class=\"badge\">CHAPTER IV<\/span><h4>Base Layer at \u20b9500 crore and above<\/h4><p>Expanded IT governance, IT policy, information security, operations, IS audit, BCP\/DR and IT outsourcing requirements.<\/p><\/div>\n<div class=\"layer\"><span class=\"badge\">CHAPTER V<\/span><h4>Middle, Upper and Top Layer<\/h4><p>Fuller governance, IT and information-security risk management, baseline cyber-resilience controls and risk-based IS audit. CICs are excluded from this chapter.<\/p><\/div>\n<\/div><\/div>\n<h3>Base Layer below \u20b9500 crore and CICs<\/h3><p>The baseline is proportionate, but it is not optional. The NBFC should digitise and secure primary business databases, maintain a board-approved IT\/IS policy, define user roles, apply physical and logical access controls, enforce a password policy and use maker-checker controls. Systems should support management reporting and regulatory returns. The board-approved business continuity policy must receive periodic oversight at least annually, and backup arrangements must be tested.<\/p>\n<h3>Base Layer at \u20b9500 crore and above<\/h3><p>Chapter IV expects an integrated IT governance framework and defined responsibility across the board, senior management and technology leaders. An IT Strategy Committee must be formed; its chair is an independent director, the CIO and CTO are members, and no more than six months should elapse between meetings. Requirements extend across security policy, access, operations, audit, resilience and outsourcing.<\/p>\n<h3>Middle Layer and above<\/h3><p>Middle, Upper and Top Layer NBFCs face more developed governance and security requirements. The IT Strategy Committee is board-level, has at least three directors, is chaired by an independent director with substantial IT expertise and meets at least quarterly. A senior executive is designated as CISO with appropriate independence, expertise and resources. The CISO\u2019s office manages and monitors the SOC, drives cyber initiatives and places a cybersecurity review before relevant board-level governance at least quarterly.<\/p>\n<div class=\"note\"><strong>Digital lenders need a second mapping.<\/strong> If the NBFC operates through a Digital Lending App or engages a Lending Service Provider, the DLA and LSP model introduces additional technology, privacy and third-party obligations under the RBI Digital Lending Directions, 2025.<\/div>\n\n<h2 id=\"controls\">The core NBFC cybersecurity requirements to operationalise<\/h2>\n<div class=\"fig\" role=\"img\" aria-label=\"Core RBI cybersecurity control areas for NBFCs\"><div class=\"fig-head\"><strong>The operating control stack<\/strong><span>Policies establish intent; these controls create daily protection and evidence.<\/span><\/div><div class=\"control-grid\">\n<div class=\"control\"><i>01<\/i><b>Governance<\/b><small>Board oversight, ITSC, CISO, ownership and risk reporting<\/small><\/div><div class=\"control\"><i>02<\/i><b>Asset visibility<\/b><small>Inventory, classification, criticality and business ownership<\/small><\/div><div class=\"control\"><i>03<\/i><b>Identity<\/b><small>Role-based access, MFA, privileged monitoring and reviews<\/small><\/div><div class=\"control\"><i>04<\/i><b>Secure operations<\/b><small>Logs, changes, patches, configurations and audit trails<\/small><\/div><div class=\"control\"><i>05<\/i><b>Vulnerability<\/b><small>VA, penetration testing, remediation and recurrence prevention<\/small><\/div><div class=\"control\"><i>06<\/i><b>Data protection<\/b><small>Strong cryptography, controlled transfer and customer-data safeguards<\/small><\/div><div class=\"control\"><i>07<\/i><b>Incident response<\/b><small>Detection, classification, containment, reporting and recovery<\/small><\/div><div class=\"control\"><i>08<\/i><b>Resilience<\/b><small>Backups, restore tests, DR drills, RTO and RPO<\/small><\/div><div class=\"control\"><i>09<\/i><b>Third parties<\/b><small>Due diligence, concentration risk, continuity and exit planning<\/small><\/div>\n<\/div><\/div>\n<h3>Know and classify the technology estate<\/h3><p>Maintain a detailed inventory of information assets and map security classification to confidentiality, integrity, availability and business criticality. The inventory should cover on-premise systems, cloud accounts, applications, APIs, databases, endpoints, network devices and material vendor dependencies. A current <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">information security risk assessment<\/a> should connect these assets to threats, vulnerabilities, impact and treatment decisions.<\/p>\n<h3>Control identities and privileged access<\/h3><p>Access should exist only for a valid business need. Use defined roles, segregate conflicting duties and log and periodically review elevated activity. For Middle Layer and above, RBI explicitly expects two-factor or multi-factor authentication for privileged users of critical systems and for critical activities based on risk assessment, as well as MFA for enterprise access to critical systems in teleworking environments.<\/p>\n<h3>Monitor logs and respond to incidents<\/h3><p>Audit trails must be detailed enough for audit, forensic evidence and dispute resolution, and logs should be regularly monitored for unauthorised activity or attack. Incident arrangements need defined classification, escalation, containment, communication, forensic analysis and recovery procedures. For the NBFCs covered by the relevant Chapter V requirement, cyber incidents are reported to RBI through DAKSH within six hours of detection, with proactive notification to CERT-In; HFC reporting continues to NHB as specified by RBI.<\/p>\n<h3>Test vulnerabilities throughout the system lifecycle<\/h3><p>For Middle Layer and above, critical information systems and customer-facing systems in the DMZ require vulnerability assessment at least once every six months and penetration testing at least once every 12 months. Testing also applies before implementation, after implementation and after changes. It must extend to relevant cloud-hosted systems, use independent and appropriately trained experts, and lead to time-bound remediation that prevents recurrence.<\/p>\n<p>Scanning and penetration testing answer different questions. The <a href=\"https:\/\/www.osto.one\/resources\/blog\/types-of-vapt\/\">Osto guide to VAPT types<\/a> explains how web, API, mobile, network and cloud testing should be scoped to the real attack surface.<\/p>\n<h3>Prove resilience, not just backup completion<\/h3><p>Resilience means secure resumption of critical operations, not merely that a backup job displayed \u201csuccessful.\u201d For Middle Layer and above, critical-system DR drills are required at least half-yearly and should include running normal business operations from the alternate site for at least a full working day. Backups must be restored periodically to test usability, protected from unauthorised access and aligned to approved RTO and RPO.<\/p>\n\n<h2 id=\"cadence\">Key RBI cybersecurity frequencies for NBFCs<\/h2>\n<p>Not every control has the same cadence. Treat these as specific requirements where applicable, not a universal schedule for every NBFC layer.<\/p>\n<div class=\"fig\" role=\"img\" aria-label=\"Selected RBI cybersecurity compliance frequencies for NBFCs\"><div class=\"fig-head\"><strong>The compliance clock<\/strong><span>Selected minimum or maximum intervals under the applicable 2026 chapters.<\/span><\/div><div class=\"cadence\">\n<div class=\"c-row\"><div class=\"c-label\">Cyber incident reporting<\/div><div class=\"c-track\"><div class=\"c-bar incident\">Within 6 hours<\/div><\/div><\/div>\n<div class=\"c-row\"><div class=\"c-label\">VA: critical systems<\/div><div class=\"c-track\"><div class=\"c-bar six\">At least every 6 months<\/div><\/div><\/div>\n<div class=\"c-row\"><div class=\"c-label\">DR: critical systems<\/div><div class=\"c-track\"><div class=\"c-bar six\">At least half-yearly<\/div><\/div><\/div>\n<div class=\"c-row\"><div class=\"c-label\">Penetration testing<\/div><div class=\"c-track\"><div class=\"c-bar year\">At least every 12 months<\/div><\/div><\/div>\n<div class=\"c-row\"><div class=\"c-label\">Board policy review<\/div><div class=\"c-track\"><div class=\"c-bar year\">At least annually<\/div><\/div><\/div>\n<\/div><\/div>\n<div class=\"table-wrap\"><table><thead><tr><th>Requirement<\/th><th>Applies where stated<\/th><th>Important detail<\/th><\/tr><\/thead><tbody>\n<tr><td>Board review of technology and cybersecurity strategies\/policies<\/td><td>All NBFCs under Chapter II<\/td><td>At least annually<\/td><\/tr><tr><td>ITSC meeting<\/td><td>Base Layer \u20b9500 crore and above<\/td><td>No more than six months between meetings<\/td><\/tr><tr><td>ITSC meeting<\/td><td>Middle Layer and above<\/td><td>At least quarterly<\/td><\/tr><tr><td>CISO cyber-preparedness review<\/td><td>Middle Layer and above<\/td><td>Presented at least quarterly to the applicable board-level forum<\/td><\/tr><tr><td>VA and PT<\/td><td>Middle Layer and above<\/td><td>VA six-monthly and PT annually for critical\/customer-facing DMZ systems; lifecycle tests also apply<\/td><\/tr><tr><td>DR drill<\/td><td>Middle Layer and above<\/td><td>At least half-yearly for critical information systems<\/td><\/tr><tr><td>Cyber incident reporting<\/td><td>As prescribed under Chapter V<\/td><td>RBI through DAKSH within six hours of detection; note the HFC exception<\/td><\/tr>\n<\/tbody><\/table><\/div>\n\n<h2 id=\"roadmap\">A practical NBFC cyber security compliance checklist<\/h2>\n<p>The RBI NBFC cybersecurity framework 2026 is easiest to implement as a continuous programme: establish applicability, translate clauses into controls, operate those controls, collect evidence and independently test the result.<\/p>\n<ol class=\"steps\"><li><strong>Confirm the NBFC classification.<\/strong> Document regulatory layer, asset size, CIC\/HFC status, products, digital channels and outsourced activities.<\/li><li><strong>Build an applicability register.<\/strong> Map Chapter II and the applicable Chapter III, IV or V provisions, then add digital lending, outsourcing, payment and data-protection requirements.<\/li><li><strong>Map obligations to controls.<\/strong> For every clause, identify the control, accountable owner, technology source, review frequency and expected evidence.<\/li><li><strong>Establish the governance structure.<\/strong> Approve policies, constitute the required committees and formalise board, ITSC, CISO, CIO, risk and audit responsibilities.<\/li><li><strong>Inventory and classify assets.<\/strong> Include cloud, applications, APIs, endpoints, data, identities and vendors; flag critical systems and customer-facing DMZ assets.<\/li><li><strong>Implement and tune security controls.<\/strong> Cover access, MFA, endpoints, cloud, applications, data, logs, vulnerabilities, patches, incidents and resilience.<\/li><li><strong>Test operation.<\/strong> Run access reviews, VA\/PT, restoration tests, DR exercises, incident simulations and independent IS audits at the applicable cadence.<\/li><li><strong>Keep a regulatory evidence trail.<\/strong> Store dated, attributable proof and report exceptions, overdue remediation and residual risk to the correct governance forum.<\/li><\/ol>\n<div class=\"fig\" role=\"img\" aria-label=\"RBI cybersecurity compliance lifecycle for NBFCs\"><div class=\"fig-head\"><strong>From direction to evidence<\/strong><span>A repeatable programme, not a pre-inspection scramble.<\/span><\/div><div class=\"flow\"><div class=\"flow-step\"><b>Classify<\/b><small>Choose the applicable chapter<\/small><\/div><div class=\"arrow\">\u2192<\/div><div class=\"flow-step\"><b>Map<\/b><small>Clause, control, owner, cadence<\/small><\/div><div class=\"arrow\">\u2192<\/div><div class=\"flow-step\"><b>Operate<\/b><small>Run and monitor safeguards<\/small><\/div><div class=\"arrow\">\u2192<\/div><div class=\"flow-step\"><b>Assure<\/b><small>Test, evidence and improve<\/small><\/div><\/div><\/div>\n\n<h2 id=\"evidence\">What evidence should an NBFC retain?<\/h2>\n<div class=\"table-wrap\"><table><thead><tr><th>Control area<\/th><th>Examples of defensible evidence<\/th><\/tr><\/thead><tbody><tr><td>Governance<\/td><td>Board-approved policies, ITSC constitution, meeting packs, minutes, risk acceptance and budget decisions<\/td><\/tr><tr><td>Assets and risk<\/td><td>Asset inventory, classification, risk register, critical-system list and treatment records<\/td><\/tr><tr><td>Access<\/td><td>Approvals, MFA configuration, privileged logs, joiner-mover-leaver records and signed access reviews<\/td><\/tr><tr><td>Security operations<\/td><td>Log-source coverage, alert tickets, patch records, change approvals and configuration exceptions<\/td><\/tr><tr><td>VA\/PT<\/td><td>Scope, independence, results, risk ratings, remediation tickets, retest proof and recurrence checks<\/td><\/tr><tr><td>Incidents<\/td><td>Timeline, classification, containment actions, forensic records, RBI\/CERT-In reporting and lessons learned<\/td><\/tr><tr><td>Resilience<\/td><td>BCP\/DR plans, RTO\/RPO approvals, backup logs, restore proof, full-day DR exercise and corrective retest<\/td><\/tr><tr><td>Vendors<\/td><td>Due diligence, contracts, materiality rating, concentration analysis, monitoring, audit and exit plans<\/td><\/tr><\/tbody><\/table><\/div>\n<p>The strongest evidence is generated while the control operates. A policy shows design; logs, tickets, approvals, reviews and test results show that the control worked. This is the same principle behind a mature <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">information security management system<\/a>, but RBI compliance still requires direct mapping to the applicable direction.<\/p>\n\n<section class=\"cta\" id=\"osto\"><h2>Run NBFC cybersecurity and compliance from one place.<\/h2><p><strong>Osto is a one-stop platform for cybersecurity and compliance.<\/strong> Its 21+ native modules\u2014including WAF, EDR, CSPM, IAM, DLP and SAST\u2014connect the security controls an NBFC operates with the evidence its compliance programme needs.<\/p><p>Map RBI obligations to owners, monitor endpoints, cloud, applications, identities and data, manage findings and retain continuous proof without stitching together separate security and compliance workflows. That unified operating model is why Osto is becoming the default for cybersecurity and compliance.<\/p><a href=\"https:\/\/www.osto.one\/contact-us\/\">Book a demo \u2192<\/a><\/section>\n\n<h2>Frequently asked questions<\/h2><section class=\"faq\">\n<details><summary>What is RBI cybersecurity compliance for NBFCs?<\/summary><p>It is the governance, technology risk, security, resilience and assurance programme required under the RBI\u2019s NBFC-specific 2026 directions, together with any other rules triggered by the NBFC\u2019s products and outsourcing arrangements.<\/p><\/details>\n<details><summary>Do the RBI cybersecurity directions apply to every NBFC?<\/summary><p>They apply to RBI-registered NBFCs unless specified otherwise, but the detailed chapter depends on the NBFC\u2019s layer, asset size and CIC status. The requirements are therefore proportionate rather than identical.<\/p><\/details>\n<details><summary>What applies to a Base Layer NBFC below \u20b9500 crore?<\/summary><p>Chapter III applies, as it does to CICs. It establishes baseline requirements for secure business databases, a board-approved IT\/IS policy, access and password controls, user roles, maker-checker, cybersecurity, reporting capability, BCP oversight and tested backups.<\/p><\/details>\n<details><summary>How often must an NBFC conduct VAPT?<\/summary><p>For Middle Layer and above, vulnerability assessment is required at least once every six months and penetration testing at least once every 12 months for critical information systems and customer-facing systems in the DMZ. Lifecycle testing and a risk-based approach for non-critical systems also apply.<\/p><\/details>\n<details><summary>How quickly must an NBFC report a cyber incident to RBI?<\/summary><p>Under the applicable Chapter V requirement, the NBFC must report cyber incidents to RBI through DAKSH within six hours of detection and proactively notify CERT-In. Housing Finance Companies continue reporting to NHB as specified in the direction.<\/p><\/details>\n<details><summary>Is ISO 27001 sufficient for RBI NBFC cybersecurity compliance?<\/summary><p>No. ISO 27001 can provide a strong management system and control foundation, but it does not replace the RBI\u2019s layer-specific requirements, frequencies, governance structure or reporting obligations. A direct RBI clause-to-control mapping is still required.<\/p><\/details>\n<\/section>\n<div class=\"note sources\"><strong>Primary regulatory sources:<\/strong> RBI\u2019s <a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=13592&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">NBFC Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026<\/a>; <a href=\"https:\/\/www.rbi.org.in\/Scripts\/BS_ViewMasDirections.aspx?id=12486\" target=\"_blank\" rel=\"noopener\">Outsourcing of Information Technology Services Directions, 2023<\/a>; and <a href=\"https:\/\/www.rbi.org.in\/scripts\/NotificationUser.aspx?Id=12848&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Digital Lending Directions, 2025<\/a>. Confirm applicability for the entity and current date. This article is not legal advice.<\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>RBI cybersecurity compliance for NBFCs now starts with one question most checklists skip: which NBFC layer are you in? The\u2026<\/p>\n","protected":false},"author":8,"featured_media":1004,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[454,455,456],"class_list":["post-1003","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-nbfc-cyber-security-compliance-checklist","tag-rbi-cybersecurity-compliance-for-nbfcs","tag-rbi-cybersecurity-guidelines-for-nbfcs"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1003"}],"version-history":[{"count":2,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1003\/revisions"}],"predecessor-version":[{"id":1006,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1003\/revisions\/1006"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1004"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}