India compliance

RBI vs SEBI cybersecurity requirements: what changes for groups regulated by both

Banks with broking or depository arms answer to both RBI and SEBI. Here is how the RBI Directions of 31 July 2026 compare with SEBI CSCRF, and how to run one control set for both.

Short answer

RBI vs SEBI cybersecurity requirements differ by regulator and structure. RBI's Directions of 31 July 2026 apply to banks, NBFCs and other RBI-regulated entities, effective immediately. SEBI CSCRF applies to SEBI-regulated entities in five categories. Both require board oversight, a CISO, testing, SOC monitoring and six-hour incident reporting, so one control set can serve both.

Key takeaways

  • RBI's 2026 Directions are written per type of entity; SEBI CSCRF scales by five categories.
  • Both require reporting cyber incidents within six hours, alongside CERT-In.
  • Testing cadences differ: RBI sets VA every 6 months and PT every 12 months; CSCRF sets them by category.
  • Banks with a DP licence meet both: SEBI's FAQs confirm CISO reporting under RBI rules can be compliant.

Who each one covers

The Reserve Bank of India issued Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions on 31 July 2026, one set for each type of regulated entity, with immediate effect. They replace the 2016 cyber security framework. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued on 20 August 2024, applies to all SEBI-regulated entities, sorted into Market Infrastructure Institutions, Qualified, Mid-size, Small-size and Self-certification REs.

RBI Directions 2026SEBI CSCRF
Issued31 July 2026, effective immediately20 August 2024, with 2025 clarifications
StructureEntity-wise DirectionsFive categories, NIST CSF-style functions
Incident reportingWithin 6 hours via DAKSH, plus CERT-InTo SEBI and CERT-In within prescribed timelines
TestingVA every 6 months, PT every 12 months, DR drills half-yearlyVAPT by category; findings closed within 3 months
MonitoringCyber Security Operations CentreSOC or the NSE/BSE Market SOC
AssuranceInformation Systems auditCyber audit; Cyber Capability Index for MIIs and Qualified REs

Where they overlap

Both put the board and a CISO in charge, require asset inventories, access control, vulnerability testing, monitoring, incident reporting, business continuity and third-party oversight. Both build on CERT-In's 2022 Directions for six-hour reporting and 180-day log retention. Controls mapped once to ISO/IEC 27001 cover most of the shared ground; SEBI also expects ISO 27001 certification for key sites.

Dual-regulated groups

A bank that holds a depository participant licence is regulated by RBI as a bank and by SEBI for its DP activities. SEBI's June 2025 FAQs say the CSCRF controls apply to the infrastructure under SEBI's purview and that a CISO reporting line set under RBI rules can be compliant. In practice, keep one control library, tag each control with both regulators' references, and produce two reports from one evidence set.

Checklist

One programme for RBI and SEBI

0 of 5 done

Put this into practice on QULDEX

Frequently asked questions

Do banks with a SEBI licence need both RBI and SEBI cyber controls?

Yes, for the respective activities. RBI's Directions apply to the bank; CSCRF applies to infrastructure used for SEBI-regulated activities such as DP services. Most controls overlap.

How fast must cyber incidents be reported under RBI and SEBI rules?

RBI's 2026 Directions require reporting within six hours through DAKSH with notification to CERT-In; CERT-In's own Directions also require six-hour reporting. CSCRF sets reporting to SEBI and CERT-In within prescribed timelines.

Can one audit cover RBI and SEBI requirements?

Not one report, but one evidence set can support both the RBI Information Systems audit and the SEBI CSCRF cyber audit if controls are mapped to both.

Sources

  1. RBI's technology-focused master directions issued on 31 July 2026, KPMG India
  2. Reserve Bank of India: notifications and master directions, Reserve Bank of India
  3. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, SEBI
  4. FAQs on CSCRF and the Framework for Adoption of Cloud Services, SEBI