The Reserve Bank of India (RBI) on July 31, 2026, issued the Reserve Bank of India (Payments Banks – Digital Payment Security Controls) Directions, 2026.
These Directions shall come into effect on July 31, 2026.
The following has been stated:
• The Directions provide a comprehensive framework for strengthening cybersecurity, technology governance, operational resilience, and IT risk management in Payments Banks.
• The Directions require banks to establish a Board-approved cybersecurity and technology risk management framework, implement robust governance and internal controls, identify and manage technology and cyber risks, and secure critical information systems and customer data.
• They also prescribe measures relating to identity and access management, network and application security, data protection, third-party and cloud service risk management, business continuity and disaster recovery planning, cyber incident response, vulnerability assessments, penetration testing, security audits, and continuous monitoring of IT systems.
• In addition, the Directions provide for periodic cyber resilience testing, employee awareness and training programmes, timely reporting of cyber incidents to the RBI, and regular review of the cybersecurity framework to address emerging threats and ensure the resilience and reliability of digital payment services.
[Notification No. – RBI/DoS/2026-27/429 DoS.CO.CSITEG.23/31.01.015/2026-27]