India's cybersecurity regulatory landscape in 2026 is governed by four overlapping mandatory frameworks: the horizontal CERT-In Directions under Section 70B(6) of the Information Technology Act, 2000, and three sector-specific layers from RBI (banks and payment operators), SEBI (capital markets intermediaries), and IRDAI (insurance entities). Every regulated financial and technology entity sits inside at least two of these frameworks simultaneously. Understanding how the four stacks interact — and where their obligations conflict or compound — is the central compliance challenge of 2026.
TL;DR for founders
If your company operates a fintech, insurtech, or regulated financial platform in India, you are inside multiple mandatory cybersecurity frameworks at once. CERT-In's 6-hour incident clock applies to everyone. If you hold an RBI licence, the IT Governance Master Direction 2023 applies. If you are SEBI-registered, the CSCRF (phase-in complete as of August 2025) applies. If you hold an IRDAI licence, the Information and Cyber Security Guidelines 2023 apply. These are NOT alternatives — you comply with all that attach to your regulatory licences. The practical output is three parallel incident-reporting clocks (CERT-In 6h, SEBI 6h–48h, IRDAI 24h) running simultaneously for the same incident, separate VAPT cadences, distinct Board-reporting templates, and independent third-party audit requirements.
Layer 1 — CERT-In: The Horizontal Baseline
The CERT-In Directions issued under Section 70B(6) of the Information Technology Act, 2000 on 28 April 2022 established India's first binding horizontal cyber-incident mandate. The Directions apply to "service providers, intermediaries, data centres, body corporate, and government organisations" — language broad enough to capture every incorporated company operating digital infrastructure or processing user data in India.
Six core obligations under the Directions:
1. 6-hour incident reporting. Direction (ii) requires reporting any of 20 specified incident categories to CERT-In within 6 hours of noticing the incident. The clock starts on awareness, not confirmed attribution. The 20 categories span targeted scanning, compromise of critical systems, malware deployment, ransomware, data breach, DDoS, website defacement, DNS hijack, supply-chain attack, and rogue mobile application, among others. Reporting is via the CERT-In portal or email; the initial report may be preliminary with a 30-day follow-up for root-cause analysis.
2. Log retention for 180 days. All ICT systems must retain logs — including application, network device, system, and access logs — for a minimum of 180 rolling days within Indian jurisdiction. CERT-In can extend this to 365 days by specific direction in an active incident investigation. Cloud logs stored by AWS, Azure, or GCP in Indian regions qualify; logs held exclusively offshore do not.
3. NTP time synchronisation. ICT systems must synchronise clocks to the National Informatics Centre (NIC) or NPTEL NTP servers, or to traceable NTP servers. This is an evidentiary requirement: without consistent time-stamps, incident timelines are unreliable for both internal forensics and CERT-In reporting.
4. Virtual Asset Service Provider (VASP) and VPN registration. Data centres, VPN service providers, and VASPs must register with CERT-In and maintain subscriber records (name, IP addresses, KYC, purpose of hire) for 5 years.
5. CERT-In empanelment for government audits. Government bodies and critical sector entities are expected to use CERT-In empanelled auditors for cybersecurity audits. The empanelment list is published at cert-in.org.in.
6. Penalty ceiling under Section 70B(7). The Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023), effective 30 November 2023, substituted the penalty ceiling under Section 70B(7) from ₹1 lakh to rupees one crore. This is a civil penalty; CERT-In has not publicly issued any adjudication orders as of May 2026, but the ceiling increase substantially changes the risk calculus for compliance officers.
Practitioner note — CERT-In SBOM and AIBOM obligations: CERT-In's Guidelines for SBOM (Software Bill of Materials) and AIBOM (AI Bill of Materials) of October 2024 extend the foundational Directions into supply-chain transparency. Entities subject to CERT-In that are also government technology vendors must maintain component inventories. The SEBI CSCRF (Layer 3) requires MIIs to conduct third-party vendor risk assessments — CERT-In SBOM obligations and SEBI vendor risk requirements reinforce each other. See Veritect's companion explainer on CERT-In SBOM/AIBOM guidelines.
Layer 2 — RBI: Banks and Payment Operators
The RBI cybersecurity stack for banks has evolved through three instruments, each superseding or layering on the last.
RBI Cyber Security Framework 2016 (DBS.CO/CSITE/BC.11/33.01.001/2015-16, dated 2 June 2016) was the first structured mandate for scheduled commercial banks. It introduced the concept of a cyber-crisis management plan, information security governance at Board level, 24×7 SOC capabilities, and real-time threat-intelligence sharing. The 2016 Framework has been materially superseded by the 2023 MD (below) but the legal obligation to maintain the 2016 Framework's controls remained in force until entities mapped to the 2023 MD.
RBI Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21, dated 18 February 2021, effective 18 August 2021) covers scheduled commercial banks (excluding RRBs), SFBs, Payment Banks, and credit card issuers. Key controls:
- Board-level digital payment security policy (Para 4): a documented policy signed off at Board level, not merely IT-department level.
- Half-yearly Vulnerability Assessment + Annual Penetration Test (Para 24): VA must cover all payment infrastructure; PT must include external and internal attack surfaces.
- Source-code escrow (Para 23): core banking and payment application source code must be held in escrow accessible to RBI in the event of vendor insolvency.
- Multi-factor authentication with dynamic factor (Para 33): static passwords are not compliant for payment authorisation; the second factor must be non-replicable (OTP, biometric, hardware token).
- Customer protection framework (Paras 42–50): zero-liability for customers reporting fraud within specified windows; 24-hour reversal timelines for disputed transactions — cross-referenced with RBI Limited Liability Circular of 6 July 2017.
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/99, dated 7 November 2023) is the current definitive IT governance framework for scheduled commercial banks and select NBFCs. It supersedes and expands on the 2016 Framework. Principal obligations:
- IT Strategy Committee at Board level with at least one independent director having IT expertise; meets at least quarterly.
- Chief Information Security Officer (CISO) with direct reporting line to the Board Risk Management Committee, not the CIO or CTO. CISO cannot hold a dual role in IT operations.
- IT Risk Assessment tied to the overall risk appetite framework, reviewed annually and updated upon material system change.
- Vendor risk management: third-party IT service providers must be assessed against security standards; contracts must include CERT-In reporting flow-down clauses.
- Para 7.9 — Board-level cyber incident reporting: the Board must receive a cyber incident report within 24 hours of a material incident. RBI's prescribed timeline for external reporting to RBI is in the companion CERT-In-aligned format.
The 2023 MD and the 2021 Digital Payment Security MD run in parallel for covered entities — they are not alternatives. Large banks comply with both simultaneously.
Layer 3 — SEBI: Capital Markets Cybersecurity
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), released on 20 August 2024 via circular SEBI/HO/ITD/ITD_VAPT/P/CIR/2024/113, established a risk-tiered cyber mandate for capital market entities. The framework introduced three tiers:
Market Infrastructure Institutions (MIIs) — stock exchanges (NSE, BSE), clearing corporations (CCIL, NSE Clearing), and depositories (NSDL, CDSL). MIIs face the most stringent controls: mandatory 24×7 Security Operations Centre (SOC), real-time event correlation (SIEM), quarterly penetration testing, dedicated CISO, and 6-hour incident reporting to SEBI.
Qualified Stock Brokers (QSBs) — brokers above SEBI-notified trading-volume and client-count thresholds. QSBs must maintain a documented cybersecurity policy, designated CISO, annual VAPT, and 24-hour incident reporting to SEBI. The SEBI FAQ of 11 June 2025 (para 3.4) confirmed that QSB classification is reviewed annually; a broker crossing the threshold mid-year has 3 months to implement QSB-level controls.
All other SEBI-registered entities — asset management companies, portfolio managers, investment advisors, registrars and transfer agents, credit rating agencies. These face a baseline framework: annual self-assessment against the CSCRF checklist, documented incident response plan, 48-hour incident reporting to SEBI, and Board-level cybersecurity review at least annually.
Phase-in timeline (fully complete as of May 2026):
- 31 December 2024: MIIs + large intermediaries (Phase 1)
- 30 April 2025: Mid-tier intermediaries (Phase 2)
- 28 August 2025: All remaining entities above thresholds (Phase 3 — Final)
A regulated entity covered by both RBI's IT Governance MD 2023 and SEBI's CSCRF (e.g., a bank running a broking subsidiary) must maintain compliance with both simultaneously. The frameworks share common vocabulary (VAPT, SOC, CISO) but differ in reporting timelines, audit frequency, and Board-reporting format.
Veritect Legal AI — Deep Research on This Topic
Veritect's private legal-research corpus covers the full text of the CERT-In Directions, RBI IT Governance MD 2023, RBI Digital Payment Security Controls MD, SEBI CSCRF and all three clarification circulars, IRDAI ICSG 2023 with all 24 policy domains, and NCIIPC Guidelines V2. Queries like "what is the CERT-In Direction on encrypted traffic inspection?" or "does the SEBI CSCRF SOC obligation extend to third-party SOC vendors?" return paragraph-cited answers from primary regulator documents. Explore Veritect Legal AI
Layer 4 — IRDAI: Insurance Cyber Compliance
The IRDAI Information and Cyber Security Guidelines 2023 (IRDAI/GA&HR/GDL/MISC/82/4/2023), dated 24 April 2023, established a 24-security-domain governance framework for the insurance sector. The Guidelines apply to:
- Life, general, standalone health insurers, and reinsurers
- Insurance brokers, corporate agents, web aggregators, insurance marketing firms (IMFs), and direct brokers
- Third-party administrators (TPAs), repositories, and surveyors/loss assessors
Governance architecture under IRDAI ICSG 2023:
The ICSG requires a three-tier governance structure: Board (cybersecurity policy sign-off annually), Risk Management Committee (RMC) with at least 2 independent directors as members, and an Information Security Risk Management Committee (ISRMC) with a full-time CISO who reports to the Board RMC — and specifically not to the CIO or CTO. This separation mirrors the RBI requirement but is independently specified by IRDAI.
24 Security Domain Policies (Policies 2.1–2.24): These span network security, endpoint protection, identity and access management, application security, cloud security, third-party risk, data classification and handling, business continuity, physical security, and incident management. Each policy domain has minimum-standard clauses. IRDAI mandates an ISO/IEC 27001 certification for the entity's information security management system.
Dual incident reporting clock (Policy 2.10, Clause 3.5):
- 6 hours to CERT-In (consistent with CERT-In Direction (ii))
- 24 hours to the IRDAI Chairperson directly (by email to the designated address)
An insurer who also holds a corporate agency or web-aggregator registration faces this dual clock for any cybersecurity incident affecting its digital distribution channels.
Audit and assurance requirements:
- Annual information and cyber security audit by a CERT-In empanelled auditor
- Audit report submitted to IRDAI via Annexures III, V, and VI within the prescribed timeline
- Annual VAPT (Vulnerability Assessment and Penetration Testing) by a CERT-In empanelled vendor; findings to be remediated within 30 days (critical) and 90 days (high)
Penalties: Section 102 of the Insurance Act, 1938 provides for penalties up to ₹1 crore per violation for non-compliance with IRDAI directions. Combined with the CERT-In Section 70B(7) ceiling of ₹1 crore, an insurer that fails to report an incident faces parallel penalty exposure from two regulators for the same event.
Cross-Regulator Interaction Matrix
The four layers create compounding obligations. The table below maps the six most common interaction scenarios:
| Entity type | CERT-In | RBI | SEBI | IRDAI | Key conflict points |
|---|---|---|---|---|---|
| Scheduled commercial bank | Yes | Yes (IT Governance MD 2023 + DPSC MD 2021) | If holds broker/AMC licence | No (unless insurance subsidiary) | Parallel VAPT requirements (RBI annual, no SEBI requirement unless broker); separate Board reporting formats |
| Payment bank / small finance bank | Yes | Yes (DPSC MD 2021 applies to PBs; IT Governance MD 2023 applies to SFBs) | No | No | CERT-In 6h runs parallel to RBI 24h Board report |
| SEBI-registered MII (exchange/depository) | Yes | No (unless also banking licence) | Yes — SOC, quarterly PT, 6h SEBI reporting | No | CERT-In 6h and SEBI 6h run simultaneously for the same incident; separate portals and formats |
| SEBI-registered broker (QSB) | Yes | No | Yes — annual VAPT, designated CISO, 24h SEBI reporting | No | CERT-In 6h runs faster than SEBI 24h; initial report to CERT-In, follow-on to SEBI |
| Life/general insurer | Yes | No (unless RBI-licensed co.) | No (unless SEBI-registered subsidiary) | Yes — ISRMC, 24h IRDAI, ISO 27001 | Dual CERT-In 6h + IRDAI 24h clock for every incident; single incident response template must address both formats |
| Fintech with SEBI + RBI licences | Yes | Yes | Yes | No | Triple compliance: CERT-In + RBI IT Governance MD + SEBI CSCRF. VAPT: annual (RBI), quarterly if MII-tier (SEBI). CISO must satisfy both regulator governance specs |
NCIIPC — The Fifth Overlay for Critical Infrastructure
Beyond the four primary layers, entities designated as Critical Information Infrastructure (CII) by the National Critical Information Infrastructure Protection Centre (NCIIPC) under Section 70A of the IT Act, 2000 face an additional incident-reporting obligation directly to NCIIPC. NCIIPC's Guidelines Version 2 (published at nciipc.gov.in) establish:
- Separate incident reporting to NCIIPC (distinct from CERT-In portal)
- Mandatory participation in NCIIPC's vulnerability disclosure and advisory ecosystem
- Sector-specific threat intelligence sharing through NCIIPC's Information Sharing and Analysis Centres (ISACs)
Most large scheduled commercial banks, stock exchanges, and payment clearing infrastructure would qualify as potential CII. The NCIIPC designation threshold assessment is initiated by NCIIPC itself or by application from the entity's sector regulator (RBI, SEBI, IRDAI can recommend); there is no self-designation mechanism. CII designation is not publicly disclosed.
Practical Compliance Architecture: What to Build in 2026
For a fintech or regulated entity managing all four framework layers, the following architecture minimises duplication:
Single unified cybersecurity policy: drafted to satisfy the highest-common-denominator requirement across CERT-In, RBI, SEBI, and IRDAI. The RBI IT Governance MD 2023 para 4.1 Board-approved policy template is the strongest baseline; augment with SEBI CSCRF Section 3 and IRDAI ICSG 2023 Policy 2.1 requirements.
Unified incident response plan with regulator-specific notification annexures: a single IRP that triggers the master process, then routes to notification sub-processes for each regulator (CERT-In portal — 6h, SEBI portal — 6h/24h/48h by entity tier, IRDAI email — 24h, RBI format — para 7.9 Board report — 24h). Timelines indexed to the fastest clock.
One VAPT programme, multiple report derivations: annual baseline VAPT satisfies RBI. Quarterly PT required by SEBI MII obligation; QSB entities can run annual and submit for SEBI. The VAPT vendor must be CERT-In empanelled (required by IRDAI; recommended by SEBI).
Single CISO governance structure with dual reporting lines: RBI requires CISO to report to Board RMC; IRDAI requires the same. A single CISO role with a clearly documented reporting line to the Board RMC satisfies both; the SEBI CSCRF does not specify the CISO reporting chain for non-MII entities.
Unified third-party risk register: CERT-In SBOM obligations, SEBI vendor risk requirements, RBI outsourcing directions (Master Directions on Outsourcing, 2023), and IRDAI's third-party risk domain (ICSG Policy 2.19) all require vendor inventory and risk assessment. A single registry with regulator-specific metadata fields reduces duplication.
Beyond this brief Preview — Full Compliance Mapping in Veritect Legal AI
The analysis above covers approximately 30% of the documented material across these four frameworks. Veritect Legal AI's private research corpus contains the full text of the CERT-In Directions, RBI IT Governance MD 2023 with all Board-level templates, SEBI CSCRF with June 2025 FAQs, IRDAI ICSG 2023 with all 24 policy domain clauses, NCIIPC Guidelines V2, and the Jan Vishwas amendment chain — with paragraph-level citations and an automated cross-regulator conflict mapper. Practitioners can query "does para 7.9 of RBI IT Governance MD supersede the CERT-In log-retention requirement?" and receive a cited, synthesised answer. Access Veritect Legal AI
FAQ
Q1: Does every regulated entity in India need to comply with CERT-In, RBI, SEBI, and IRDAI cyber rules simultaneously? Not all four at once. CERT-In applies horizontally to all entities. RBI, SEBI, and IRDAI each apply to entities within their respective licensing perimeter. A fintech with an RBI payment aggregator licence and a SEBI broker licence faces CERT-In + RBI + SEBI — all three. An insurer without any capital markets licence faces CERT-In + IRDAI. A technology company that is neither a licensed financial entity nor a payment operator faces CERT-In only. The key question is: how many regulatory licences does your entity hold?
Q2: What is the key difference between the CERT-In 6-hour clock and the RBI/SEBI/IRDAI incident reporting obligations? CERT-In starts the clock from "noticing" the incident — awareness triggers the obligation, not confirmed attribution. RBI's 24-hour Board-level reporting and SEBI's 6-hour / 24-hour / 48-hour (by entity tier) SEBI-portal reporting run in parallel, not instead of, CERT-In. For an insurer, the CERT-In 6-hour clock and the IRDAI 24-hour Chairperson-email clock run simultaneously from the same incident trigger. All three notifications for the same incident must be independently filed to separate portals and recipients in different formats.
Q3: When does the SEBI CSCRF phase-in complete? Phase 3 (28 August 2025) was the final phase. As of May 2026, the SEBI CSCRF is fully in force for all entities above applicable thresholds. SEBI FAQs (11 June 2025) confirmed that no further phase-in dates remain.
Q4: What are the Section 70B penalties for non-compliance with CERT-In Directions? Up to ₹1 crore per violation under Section 70B(7) as amended by the Jan Vishwas Act, 2023 (effective 30 November 2023). This is a civil penalty; criminal exposure may arise separately if the non-compliance enables or constitutes a cybercrime.
Q5: Does the SEBI CSCRF apply to fund managers and investment advisors in India? Yes, at the baseline tier. All SEBI-registered entities (including AMCs, PMS managers, investment advisors, and RTA entities) above applicable thresholds face the CSCRF baseline framework: annual self-assessment, documented IRP, 48-hour incident reporting to SEBI, and annual Board review. The SOC and quarterly PT obligations apply only to MIIs.
Q6: How does NCIIPC CII designation interact with the four-layer stack? CII designation adds a fifth overlay: separate incident reporting to NCIIPC (distinct from CERT-In portal), participation in NCIIPC ISACs, and NCIIPC advisory compliance. Most large banks, exchanges, and payment clearing infrastructure would qualify. CII designation is initiated by NCIIPC, not self-declared.
Q7: What is the best starting point for building a multi-regulator cyber compliance architecture? Begin with the CERT-In Directions as the horizontal baseline and build the log-retention, time-synchronisation, and incident-reporting infrastructure first. Then layer RBI IT Governance MD 2023 governance architecture (CISO, Board IT Strategy Committee, risk assessment), SEBI CSCRF (entity-tier determination, IRP, VAPT programme), and IRDAI ICSG 2023 (24 domain policies, ISO 27001, dual notification). Design the incident response plan with regulator-specific notification annexures triggered from the same root IRP — one process, multiple output formats.
Founder Checklist — India Cyber Compliance 2026
- Map your licences — identify every RBI, SEBI, and IRDAI licence your entity holds; this determines which framework layers apply.
- Build a unified CERT-In incident response process — the 6-hour clock starts at awareness; your IRP must trigger immediately on noticing an incident, before confirmation.
- Determine your SEBI entity tier — MII, QSB, or baseline; the SEBI FAQ of 11 June 2025 clarifies the thresholds. QSB determination triggers CISO and annual VAPT requirements.
- Implement the CISO governance structure — for RBI and IRDAI covered entities, the CISO must report to the Board Risk Management Committee, not the CIO. Document the reporting line explicitly.
- Commission a CERT-In empanelled VAPT vendor — required by IRDAI for the annual ICS audit; recommended by SEBI; aligned with RBI half-yearly VA requirement. One empanelled vendor can service all four framework obligations.