---
title: "Cybersecurity, Technology Risk, Resilience and Assurance Framework, July 31, 2026"
date: 2026-08-20
author: "King Stubb &amp; Kasiva"
url: https://ksandk.com/newsletter/rbi-cybersecurity-technology-risk-resilience-framework-2026/
---

# Cybersecurity, Technology Risk, Resilience and Assurance Framework, July 31, 2026

Posted On - 20 August, 2026 • By - King Stubb & Kasiva

RBI issued separate entity-specific Directions on the **Cybersecurity, Technology: Risk, Resilience and Assurance Framework**. The Directions consolidate and update requirements relating to IT governance, information security, cybersecurity, technology risk management, operational resilience and information-systems audit.

## Scope and Purpose of the Directions

The Directions apply to a wide range of **regulated entities**, each covered by its own entity-specific framework:

- Commercial Banks
- Small Finance Banks
- Payments Banks
- Urban Co-operative Banks
- Non-Banking Financial Companies (“NBFCs”)
- All India Financial Institutions (“AIFIs”)

## Board and Senior Management Responsibilities

The Directions place greater responsibility on **Boards and senior management** for technology and cybersecurity governance. Depending on the regulated entity and applicable framework, requirements include:

- Board-approved IT and information-security policies
- Appropriate IT/security committees
- Defined responsibilities for senior technology and security personnel, including the Chief Information Security Officer (“CISO”)
- Systematic identification and assessment of technology and cybersecurity risks

## Key Areas Covered by the Framework

The framework addresses a broad set of **technology and security domains**, including:

- Information-asset protection and classification
- Access controls
- Application and network security
- Vulnerability management
- Audit logs
- Incident response
- Business continuity and disaster recovery
- Third-party technology arrangements
- Information-systems audit

## Differentiated Requirements for NBFCs

For **NBFCs**, the requirements are differentiated based on the applicable regulatory layer and asset size. Enhanced governance and technology-risk requirements apply to larger and higher-layer entities.

## Effective Date

The Directions came into effect **immediately upon issuance**.

## Key Takeaway

Regulated entities and their technology-service providers will need to review the following areas against the **applicable 2026 framework**:

- Governance structures
- Cybersecurity controls
- Incident-response arrangements
- Outsourcing arrangements
- Technology-risk documentation

*Last Updated on 21 August, 2026*

Get King Stubb & Kasiva’s legal updates in your Google feed[![Add King Stubb & Kasiva as a preferred source on Google](https://ksandk.com/wp-content/uploads/google_preferred_source_badge_light_en@2x.png)](https://www.google.com/preferences/source?q=https://ksandk.com/)

---

## Office Locations                                                                                                                                                     
                                               
  - [New Delhi](https://ksandk.com/locations/top-corporate-law-firm-in-delhi/) (HQ): +91-11-41318190 | info@ksandk.com                                                    
  - [Mumbai](https://ksandk.com/locations/top-corporate-law-firm-in-mumbai/): 3 offices (Nariman Point, Lower Parel, Andheri) | mumbai@ksandk.com
  - [Bangalore](https://ksandk.com/locations/top-corporate-law-firm-in-bangalore/): bangalore@ksandk.com                                                                  
  - [Chennai](https://ksandk.com/locations/chennai/): chennai@ksandk.com                                                                                                  
  - [Hyderabad](https://ksandk.com/locations/hyderabad/): hyderabad@ksandk.com                                                                                            
  - [Pune](https://ksandk.com/locations/pune/): pune@ksandk.com                                                                                                           
  - [Kochi](https://ksandk.com/locations/kochi/): kochi@ksandk.com
                                                                                                                                                                          
  ## Contact                                   
                                                                                                                                                                          
  - [Contact Page](https://ksandk.com/contact-us/)
  - General: info@ksandk.com | +91-11-41318190
  - WhatsApp: +91-7428567444
  - [Privacy Statement](https://ksandk.com/privacy-statement/)                                                                                                            
  - [Terms of Use](https://ksandk.com/terms-of-use/)