RBI · India
Staff awareness evidence for
RBI’s 2026 Directions.
On 31 July 2026 the RBI replaced its earlier cyber security circulars with the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, which for commercial banks make awareness programmes mandatory for all new recruits and require annual training for management, the Board and senior management.
- Framework
- Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (31 July 2026)
- Applies to
- Separate versions for commercial, small finance and payments banks, UCBs, NBFCs, AIFIs and credit information companies
- People
- Awareness for new recruits, annual training for management and the Board, periodic evaluation of staff awareness
- Incidents
- Report to the RBI within 6 hours; vendors must report in time for the bank to meet it
What the 2026 Directions say
People are written
into the Directions.
Paragraph numbers are from the commercial bank version.
| Topic | What RBI says | Reference |
|---|---|---|
| New recruits and management | Cybersecurity awareness programmes are mandatory for all new recruits, with annual training for lower and middle management. | Para 203 |
| Board and senior management | Annual training for all Board members and senior management on IT and cybersecurity risks and evolving best practices. | Para 204 |
| Measuring awareness | Evaluate the awareness level of employees periodically, and track the extent of user awareness training. | Paras 202 and 194 |
| Customers | Encourage customers to report phishing mails and phishing sites, and take effective remedial action on every report. | Para 206 |
| Incidents | Report cyber incidents to the RBI within 6 hours. | Para 182 |
Where fraud actually starts
Genuine bank email now
ends in .bank.in.
Banks were required to move to the .bank.in domain by 31 October 2025, to cut phishing that copies bank websites and email. That only helps if staff and customers know to check it.
Treasury Operations <ops@xyzbank-secure.example>
Urgent: confirm today’s settlement file
The settlement file failed validation. Sign in to the treasury portal and re-upload it before 12:00 to avoid a penalty.
Open treasury portal- Not a .bank.in address
- Deadline and penalty pressure
- Sign-in link in an email
Expectation to record
The records your
inspectors ask for.
New recruits and annual training.
LMS completions, assessments and certificates per person, including induction.
Board and senior management sessions.
Attendance and completion records for leadership training.
Periodic evaluation.
Simulation results by team and channel over time.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (commercial banks)31 July 2026 · RBI/DoS/2026-27/410 · in force
- The same Directions for NBFCs31 July 2026 · RBI/DoS/2026-27/461 · duties vary by layer
- The same Directions for urban co-operative banks31 July 2026 · RBI/DoS/2026-27/437 · graded by level
- Repeal of 628 circulars on consolidation into Master Directions31 July 2026 · RBI/DoS/2026-27/221
- Digital Payment Security Controls Directions, 2026 (commercial banks)31 July 2026 · caution customers against phishing and vishing, train fraud-control staff
- Managing Risks in Outsourcing Directions, 2025 (commercial banks)28 November 2025 · para 56, vendor incident reporting
- Migration to the .bank.in domain22 April 2025 · RBI/2025-26/28 · deadline 31 October 2025
- Master Direction on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs30 July 2024 · training for employees, vendors and the Board
Questions buyers ask
Frequently asked questions.
Which RBI cyber security rules apply now?
The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued on 31 July 2026 in separate versions by entity type. The 2016 Cyber Security Framework, the 2023 IT Governance Master Direction and the UCB cyber frameworks were repealed the same day.
Do the Directions require phishing simulation?
They do not use the words. Commercial banks must evaluate the awareness level of employees periodically, and larger NBFCs must measure and track the effectiveness of training. Simulation results are one practical way to show both.
Do the rules apply to our vendors?
Yes, in part. Under the 2025 outsourcing Directions a service provider must report incidents without undue delay, so the bank can report to the RBI within 6 hours of the provider detecting it.
Does KeenSec make us compliant with RBI requirements?
No tool makes you compliant on its own. KeenSec helps you run staff awareness and produce evidence; your auditors and the RBI decide compliance.
Let’s connect the dots
Show the RBI your people
are trained, not just told.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo