The Reserve Bank of India has notified the Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions, 2026 for Non-Banking Financial Companies (NBFCs). These directions establish guidelines for governance, reporting, and cybersecurity controls.
RBI Strengthens Cybersecurity for NBFCs
On August 6, 2026, the Reserve Bank of India (RBI) issued the Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions, 2026 aimed at enhancing cybersecurity protocols for Non-Banking Financial Companies (NBFCs). The directive emphasizes the need for comprehensive governance structures, robust reporting frameworks, and strict cyber control measures.
The newly implemented directions require NBFCs to adopt a structured governance framework that ensures accountability for cybersecurity at all levels of management. Key aspects of the framework include clearly defined roles and responsibilities, routine cyber risk assessments, and updates to risk management strategies in line with evolving technology threats.
“Cybersecurity is paramount in safeguarding customer data and maintaining trust in financial services,” stated the RBI Governor.
Moreover, the RBI has mandated that NBFCs enhance their resilience against cyber threats by implementing stringent monitoring systems. The framework aligns with international best practices and aims to fortify the financial sector's defenses.
Legal practitioners operating in the financial services sector should closely consider these directives in their compliance audits and risk management strategies, ensuring that their clients adapt effectively to the enhanced regulatory expectations.
Citations
- RBI Cybersecurity Directions (2026) 1 RBI Bulletin 23