- New Direction
- RBI/DoS/2026-27/437
- Effective
- 31 July 2026
- Cybersecurity Levels
- Level I → IV
- Immediate Action
- Review & Map
A significant change for Urban Co-operative Banks
On 31 July 2026, the Reserve Bank of India issued the Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
The Directions came into force with immediate effect. The earlier cybersecurity directions applicable to UCBs, including the 2018 Basic Cyber Security Framework and the 2019 Comprehensive Cyber Security Framework, have been repealed.
- RBI Directions 2026Cybersecurity • Technology • Risk • Resilience • Assurance
- UCB Cyber Security Framework 2019Repealed
- UCB Cyber Security Framework 2018Repealed
For banks, this means the regulatory baseline has changed. It does not, however, mean that every assessment or audit completed before 31 July 2026 automatically becomes invalid.
What has changed?
The new Directions consolidate cybersecurity, technology risk, resilience and assurance requirements for Urban Co-operative Banks. Requirements are cumulative: a bank falling within a higher Level is also required to comply with applicable requirements of the preceding Levels.
- Level IBaseline
- Level IIAdditional
- Level IIIEnhanced
- Level IVHighest applicable
Tier and Cybersecurity Level are not the same
A UCB's regulatory Tier and its Cybersecurity Level are separate classifications and should not be used interchangeably when determining cybersecurity applicability.
The Cybersecurity Level should be independently determined under the 2026 Cybersecurity Directions.
What if your IS Audit was already completed?
This is particularly relevant for banks that completed their annual IS Audit or Cybersecurity Gap Assessment before the new Directions were issued.
Does the entire IS Audit need to be repeated?
Not necessarily.
An IS Audit conducted before 31 July 2026 would have been performed against the regulatory requirements applicable during that audit period. A practical next step is to map the existing assessment against the requirements applicable under RBI/DoS/2026-27/437 and identify the regulatory delta.
- 01Existing IS AuditReview scope & evidence
- 022026 MappingMap applicable requirements
- 03Delta ReviewIdentify changed areas
- Already CoveredExisting evidence remains relevant.
- Requires RemappingControl exists; mapping changes.
- Additional AssessmentNew requirement needs validation.
What should UCBs review now?
Confirm the applicable Cybersecurity Level
Reassess the bank against Para 4 and formally document the determination.
Review regulatory references
Review Cyber Security Policy, IT/IS policies, Board documents, audit templates and compliance trackers.
Map recently completed audits
Map recent IS Audit and Gap Assessment work against the 2026 Directions.
Review cybersecurity responsibility
Verify applicable senior cybersecurity official / CISO responsibilities and reporting arrangements.
Review incident reporting
Validate applicable RBI and CERT-In cyber incident reporting processes and timelines.
Identify evidence gaps
Verify required controls are implemented and supported by sufficient evidence.
Updating a policy reference is not the same as becoming compliant.
A practical transition approach
- Determine Level
- Build 2026 Baseline
- Map Existing Controls
- Identify Gaps
- Validate
- Remediate
“Where does our bank stand against the new RBI framework today?”
Already completed your IS Audit?
You may not need to repeat the entire exercise. We can map your existing assessment against the 2026 Directions and identify what is already covered, what requires remapping and what needs additional validation.
- Regulatory Gap Assessment
- IS Audit
- Regulatory Mapping
- Policy Review
- Delta Assessment
Regulatory Reference
Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI/DoS/2026-27/437
DoS.CO.CSITEG.31/31.01.015/2026-27
Dated: 31 July 2026
This advisory is intended for cybersecurity and regulatory awareness purposes. Applicability should be determined by each bank based on its operations, technology environment and regulatory classification. This content should not be considered legal advice.
