RBI · India

Staff awareness evidence for
RBI’s 2026 Directions.

On 31 July 2026 the RBI replaced its earlier cyber security circulars with the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, which for commercial banks make awareness programmes mandatory for all new recruits and require annual training for management, the Board and senior management.

Framework
Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (31 July 2026)
Applies to
Separate versions for commercial, small finance and payments banks, UCBs, NBFCs, AIFIs and credit information companies
People
Awareness for new recruits, annual training for management and the Board, periodic evaluation of staff awareness
Incidents
Report to the RBI within 6 hours; vendors must report in time for the bank to meet it

What the 2026 Directions say

People are written
into the Directions.

Paragraph numbers are from the commercial bank version.

TopicWhat RBI saysReference
New recruits and managementCybersecurity awareness programmes are mandatory for all new recruits, with annual training for lower and middle management.Para 203
Board and senior managementAnnual training for all Board members and senior management on IT and cybersecurity risks and evolving best practices.Para 204
Measuring awarenessEvaluate the awareness level of employees periodically, and track the extent of user awareness training.Paras 202 and 194
CustomersEncourage customers to report phishing mails and phishing sites, and take effective remedial action on every report.Para 206
IncidentsReport cyber incidents to the RBI within 6 hours.Para 182

Where fraud actually starts

Genuine bank email now
ends in .bank.in.

Banks were required to move to the .bank.in domain by 31 October 2025, to cut phishing that copies bank websites and email. That only helps if staff and customers know to check it.

Expectation to record

The records your
inspectors ask for.

TRAINING

New recruits and annual training.

LMS completions, assessments and certificates per person, including induction.

BOARD

Board and senior management sessions.

Attendance and completion records for leadership training.

AWARENESS LEVEL

Periodic evaluation.

Simulation results by team and channel over time.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (commercial banks)31 July 2026 · RBI/DoS/2026-27/410 · in force
  2. The same Directions for NBFCs31 July 2026 · RBI/DoS/2026-27/461 · duties vary by layer
  3. The same Directions for urban co-operative banks31 July 2026 · RBI/DoS/2026-27/437 · graded by level
  4. Repeal of 628 circulars on consolidation into Master Directions31 July 2026 · RBI/DoS/2026-27/221
  5. Digital Payment Security Controls Directions, 2026 (commercial banks)31 July 2026 · caution customers against phishing and vishing, train fraud-control staff
  6. Managing Risks in Outsourcing Directions, 2025 (commercial banks)28 November 2025 · para 56, vendor incident reporting
  7. Migration to the .bank.in domain22 April 2025 · RBI/2025-26/28 · deadline 31 October 2025
  8. Master Direction on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs30 July 2024 · training for employees, vendors and the Board

Questions buyers ask

Frequently asked questions.

Which RBI cyber security rules apply now?

The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued on 31 July 2026 in separate versions by entity type. The 2016 Cyber Security Framework, the 2023 IT Governance Master Direction and the UCB cyber frameworks were repealed the same day.

Do the Directions require phishing simulation?

They do not use the words. Commercial banks must evaluate the awareness level of employees periodically, and larger NBFCs must measure and track the effectiveness of training. Simulation results are one practical way to show both.

Do the rules apply to our vendors?

Yes, in part. Under the 2025 outsourcing Directions a service provider must report incidents without undue delay, so the bank can report to the RBI within 6 hours of the provider detecting it.

Does KeenSec make us compliant with RBI requirements?

No tool makes you compliant on its own. KeenSec helps you run staff awareness and produce evidence; your auditors and the RBI decide compliance.

Let’s connect the dots

Show the RBI your people
are trained, not just told.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo