The Reserve Bank of India (RBI) on July 31, 2026, exercising powers under Section 27 and Section 35-A read with Section 56 of the Banking Regulation Act, 1949, issued the "Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026" with immediate effect. These Directions apply to all Primary (Urban) Co-operative Banks (UCBs) and replace the existing cybersecurity framework circular. UCBs are categorised into four levels (Level I to Level IV) based on their digital depth and interconnectedness with payment systems—ranging from basic UCBs (Level I) to those with direct CPS membership, own ATM Switch, or SWIFT interface (Level IV)—with graded compliance obligations applicable to each level.
The framework mandates Board-approved cybersecurity and IT policies, formation of governance structures such as the IT Strategy Committee, IT Steering Committee, Chief Information Security Officer (CISO), and Information Security Committee (for higher-level UCBs), along with baseline controls covering IT architecture, cyber crisis management, asset inventory, data protection, cryptographic controls, network security, patch management, user access control, secure mail systems, removable media handling, staff/customer awareness, backup and restoration, and vendor/outsourcing risk management. Higher-level UCBs face additional requirements including application security lifecycle controls, periodic VA/PT, centralised IAM systems, Security Operations Centres (CSOC), advanced threat defence, forensics readiness, and risk-based transaction monitoring. UCBs must report cyber incidents within six hours via the DAKSH platform and may notify CERT-In and share threat intelligence with IB-CART.
The Directions repeal all prior cybersecurity guidelines for UCBs (communicated via circular dated July 31, 2026) while preserving rights, liabilities, and proceedings arising under the repealed framework, and operate in addition to other applicable laws. RBI retains final authority to interpret and clarify any provision of these Directions.
[Notification No. RBI/DoS/2026-27/437, DoS.CO.CSITEG.31/31.01.015/2026-27]