The Reserve Bank of India (RBI) on July 31, 2026, issued the Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
These Directions shall come into effect on July 31, 2026.
The following has been stated:
• The Directions establish a comprehensive framework to strengthen cybersecurity, technology risk management, operational resilience, and IT governance in Payments Banks.
• The Directions require banks to implement a Board-approved cybersecurity and technology risk management policy, establish effective governance and oversight mechanisms, conduct periodic cyber risk assessments, maintain secure IT infrastructure and data protection measures, and adopt controls for identity and access management, network security, application security, third-party and cloud risk management, and incident response.
• They also provide for business continuity and disaster recovery planning, cyber resilience testing, security monitoring, vulnerability assessments, penetration testing, independent audits, employee awareness programmes, and timely reporting of cyber incidents to the RBI.
• The Directions further encourage continuous monitoring and improvement of cybersecurity practices to safeguard critical banking systems, customer data, and digital payment services while enhancing the overall resilience of Payments Banks against evolving cyber threats.
[Notification no. – RBI/DoS/2026-27/428 DoS.CO.CSITEG.22/31.01.015/2026-27]