Short answer
RBI vs SEBI cybersecurity requirements differ by regulator and structure. RBI's Directions of 31 July 2026 apply to banks, NBFCs and other RBI-regulated entities, effective immediately. SEBI CSCRF applies to SEBI-regulated entities in five categories. Both require board oversight, a CISO, testing, SOC monitoring and six-hour incident reporting, so one control set can serve both.
Key takeaways
- RBI's 2026 Directions are written per type of entity; SEBI CSCRF scales by five categories.
- Both require reporting cyber incidents within six hours, alongside CERT-In.
- Testing cadences differ: RBI sets VA every 6 months and PT every 12 months; CSCRF sets them by category.
- Banks with a DP licence meet both: SEBI's FAQs confirm CISO reporting under RBI rules can be compliant.
Who each one covers
The Reserve Bank of India issued Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions on 31 July 2026, one set for each type of regulated entity, with immediate effect. They replace the 2016 cyber security framework. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued on 20 August 2024, applies to all SEBI-regulated entities, sorted into Market Infrastructure Institutions, Qualified, Mid-size, Small-size and Self-certification REs.
| RBI Directions 2026 | SEBI CSCRF | |
|---|---|---|
| Issued | 31 July 2026, effective immediately | 20 August 2024, with 2025 clarifications |
| Structure | Entity-wise Directions | Five categories, NIST CSF-style functions |
| Incident reporting | Within 6 hours via DAKSH, plus CERT-In | To SEBI and CERT-In within prescribed timelines |
| Testing | VA every 6 months, PT every 12 months, DR drills half-yearly | VAPT by category; findings closed within 3 months |
| Monitoring | Cyber Security Operations Centre | SOC or the NSE/BSE Market SOC |
| Assurance | Information Systems audit | Cyber audit; Cyber Capability Index for MIIs and Qualified REs |
Where they overlap
Both put the board and a CISO in charge, require asset inventories, access control, vulnerability testing, monitoring, incident reporting, business continuity and third-party oversight. Both build on CERT-In's 2022 Directions for six-hour reporting and 180-day log retention. Controls mapped once to ISO/IEC 27001 cover most of the shared ground; SEBI also expects ISO 27001 certification for key sites.
Dual-regulated groups
A bank that holds a depository participant licence is regulated by RBI as a bank and by SEBI for its DP activities. SEBI's June 2025 FAQs say the CSCRF controls apply to the infrastructure under SEBI's purview and that a CISO reporting line set under RBI rules can be compliant. In practice, keep one control library, tag each control with both regulators' references, and produce two reports from one evidence set.
Checklist
One programme for RBI and SEBI
0 of 5 done
Put this into practice on QULDEX
Frequently asked questions
Do banks with a SEBI licence need both RBI and SEBI cyber controls?
Yes, for the respective activities. RBI's Directions apply to the bank; CSCRF applies to infrastructure used for SEBI-regulated activities such as DP services. Most controls overlap.
How fast must cyber incidents be reported under RBI and SEBI rules?
RBI's 2026 Directions require reporting within six hours through DAKSH with notification to CERT-In; CERT-In's own Directions also require six-hour reporting. CSCRF sets reporting to SEBI and CERT-In within prescribed timelines.
Can one audit cover RBI and SEBI requirements?
Not one report, but one evidence set can support both the RBI Information Systems audit and the SEBI CSCRF cyber audit if controls are mapped to both.
Sources
- RBI's technology-focused master directions issued on 31 July 2026, KPMG India
- Reserve Bank of India: notifications and master directions, Reserve Bank of India
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, SEBI
- FAQs on CSCRF and the Framework for Adoption of Cloud Services, SEBI