India's digital-law week of 27 July to 2 August 2026 turned on a single day. On 31 July the Reserve Bank of India's Department of Supervision released 64 consolidated Directions and repealed 628 circulars in one exercise (RBI/DoS/2026-27/221). Inside that package sit entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and All India Financial Institutions — each in force with immediate effect, each requiring cyber-incident reporting to DAKSH within six hours of detection, a 24x7 Security Operations Centre, multi-factor authentication for privileged users and half-yearly disaster-recovery drills. The OGAI Rule 10 determination deadline of 30 July passed with no order published.
At a Glance — W31 Scoreboard
| # | Pillar | Development | Issuer | Date | Score |
|---|---|---|---|---|---|
| 1 | cybersecurity | Consolidation of Supervisory Instructions — 64 consolidated Directions released, 628 circulars repealed (RBI/DoS/2026-27/221) | RBI, Dept of Supervision | 31 Jul 2026 | 14 |
| 2 | cybersecurity | Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — entity-wise; six-hour DAKSH reporting, 24x7 SOC, independent CISO, half-yearly DR drills | RBI | 31 Jul 2026 | 14 |
| 3 | fintech-payments | Digital Payment Security Controls Directions, 2026 + Fraud Risk Management Directions, 2026 for NBFCs | RBI | 31 Jul 2026 | 11 |
| 4 | platforms-intermediaries | OGAI Rule 10 determination deadline passes with no published determination order or register entry | MeitY / OGAI | 30 Jul 2026 | 8 |
| 5 | platforms-intermediaries | Digital Accessibility Circulars compliance timelines extended; GARUDA green-channel AIF mechanism notified | SEBI | 30–31 Jul 2026 | 7 |
| 6 | cybersecurity | CIVN-2026-0381 — remote buffer overflow in DD-WRT router firmware (HIGH) | CERT-In | 29 Jul 2026 | 5 |
| 7 | data-protection | DPBI — no Tier 1 notification of Section 18(1) constitution traced; Rule 17 process continues | MeitY | 2 Aug 2026 | 5 |
| 8 | telecom-emerging | Press releases No. 104–105 — June 2026 subscription data, Godda drive test; no regulatory instrument in the week | TRAI | 28 Jul 2026 | 4 |
TL;DR for Founders
Three things to act on this week:
If you are a bank, NBFC, payments bank or AIFI — or you sell technology into one: your cybersecurity rulebook changed on 31 July, with no transition period. Six-hour DAKSH incident reporting, a 24x7 SOC, MFA for privileged users and half-yearly DR drills are now Direction-level obligations, not guidance. Vendor contracts are explicitly in scope.
If your incident-response runbook has one six-hour clock in it, it is now wrong. CERT-In under Section 70B of the Information Technology Act, 2000 and RBI via DAKSH are two separate filings from one detection event. Name a different owner for each.
If you run or bank a real-money gaming platform: the 30 July determination deadline passed without a published order. That is not relief. Liability under the Promotion and Regulation of Online Gaming Act, 2025 attaches to the game's characteristics, not to an order — so the absence of a determination changes nothing about exposure.
Top 3 Developments
1. How Did RBI Rewrite the Supervisory Rulebook in a Single Day — and What Happened to the 628 Repealed Circulars? (Cybersecurity)
What changed: On 31 July 2026 the Reserve Bank of India's Department of Supervision issued Consolidation of Supervisory Instructions - Repeal of Circulars, reference RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27. The circular announces the release of 64 consolidated Directions and the repeal of 628 circulars.
What it contains: The consolidated Directions absorb instructions issued by the Department of Supervision and by departments whose supervisory functions later merged into it. Obsolete instructions were excluded from the consolidation on the express footing that they are no longer relevant. The savings clause is the operative protection for pending matters: actions already taken under a repealed instruction continue to be governed by that instruction's provisions.
The 64 Directions are cut entity-wise rather than subject-wise, which is the structural change practitioners will feel most. Each regulated-entity class now has its own named instrument across supervisory subjects — for example, Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026 (RBI/DoS/2026-27/408, DoS.CO.PPG.2/11.01.005/2026-27), Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026 (RBI/DoS/2026-27/413, DoS.CO.PPG.7/11.01.005/2026-27), Reserve Bank of India (Non-Banking Financial Companies - Miscellaneous) Supervisory Directions, 2026 (RBI/DoS/2026-27/467), Reserve Bank of India (Credit Information Companies - Miscellaneous) Supervisory Directions, 2026 (RBI/DoS/2026-27/471), Reserve Bank of India (All India Financial Institutions - Supervisory Returns) Directions, 2026 (RBI/DoS/2026-27/458) and Reserve Bank of India (Local Area Banks - Statutory Audit) Directions, 2026 (RBI/DoS/2026-27/448). All carry the same issue date of 31 July 2026 and all take effect immediately upon issuance.
Why it matters: Every internal policy, board note, audit programme, vendor schedule and regulatory-mapping spreadsheet in an Indian regulated entity that cites a Department of Supervision circular by its old reference is now at risk of citing a repealed instrument. This is not a drafting nicety — supervisory correspondence, RFP compliance annexures and outsourcing agreements routinely quote circular numbers, and a wrong citation in a supervisory response is an avoidable finding. The re-mapping exercise is mechanical but large, and it has no announced grace period.
Practitioner takeaway: Three workstreams. Inventory every instrument citation across policies, contracts and audit programmes. Map each to the corresponding 2026 Direction for your entity class, noting that instruments are now class-specific — a Commercial Bank Direction does not govern a Payments Bank. Preserve the savings position: for any live inspection, enforcement or remediation matter, record which repealed instruction governed the action taken, because the savings clause fixes the applicable law by reference to the date of the action, not the date of the response.
Link: RBI — Consolidation of Supervisory Instructions (Id 13663)
Score: 14/15.
2. What Do the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 Actually Require? (Cybersecurity / Fintech-Payments)
What changed: The consolidation package includes a family of parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued 31 July 2026, one per regulated-entity class: Commercial Banks — RBI/DoS/2026-27/410; Non-Banking Financial Companies — RBI/DoS/2026-27/461, DoS.CO.CSITEG.55/31.01.015/2026-27; Payments Banks — RBI/DoS/2026-27/428; and a further instrument for All India Financial Institutions (EXIM Bank, NABARD, SIDBI, NHB and NaBFID). Each comes into force with immediate effect.
Scope: The Commercial Banks version applies to banking companies under the Banking Regulation Act, 1949, including corresponding new banks and the State Bank of India, and expressly excludes Small Finance Banks, Payments Banks and Local Area Banks — each of which has its own instrument. Foreign branches operate on a comply-or-explain approach for selected provisions. The NBFC version is tiered: Base Layer NBFCs below Rs 500 crore and Core Investment Companies; Base Layer NBFCs at Rs 500 crore and above; and Top, Upper and Middle Layer NBFCs excluding CICs, each carrying differentiated requirements across six chapters.
Why it matters: The obligations are specific and testable, which is what converts a framework into a supervisory finding. On governance — board-approved IT, cybersecurity, information-security and business-continuity policies reviewed at least annually; a board-level IT Strategy Committee; a Chief Information Security Officer independent of the IT function; and Audit Committee oversight of information-systems audit. On controls — asset inventory, multi-factor authentication for privileged users, a 24x7 Security Operations Centre, periodic vulnerability assessment, penetration testing of critical internet-facing systems, disaster-recovery drills at least half-yearly for critical systems, and detailed audit logging. On incidents — reporting to the DAKSH supervisory platform within six hours of detection. On third parties — baseline controls flow through to vendors, with ATM switch service providers named on the face of the instrument.
The strategic point for the wider digital-law stack: this is the second major sectoral instrument in eight days, after the Reserve Bank's model-risk consultation closed on 24 July, to move an area of technology practice from advisory guidance into a binding, auditable control set. India now has three parallel cyber-supervision regimes with materially different perimeters — RBI's Directions for regulated entities, SEBI's Cybersecurity and Cyber Resilience Framework of 20 August 2024 for its regulated entities, and CERT-In's cross-sectoral Directions of 28 April 2022 under Section 70B of the Information Technology Act, 2000. A payments company that is an NBFC, a SEBI-registered intermediary's technology partner, and a body corporate for CERT-In purposes will sit inside all three.
Practitioner takeaway: Re-baseline the control matrix against the named Direction for your entity class, not against the 2 June 2016 Cyber Security Framework circular or the November 2023 IT Governance Master Direction. Check CISO reporting lines against the independence requirement before the next board cycle. Reopen ATM switch, managed-SOC, cloud and core-banking vendor contracts for flow-down of baseline controls and audit rights.
Link: RBI — Commercial Banks Cybersecurity Directions, 2026 | NBFC version
Score: 14/15.
3. Which Digital-Payment and Fraud Obligations Now Bind NBFCs and Housing Finance Companies? (Fintech-Payments)
What changed: Two further instruments issued on 31 July 2026 with immediate effect. The Reserve Bank of India (Non-Banking Financial Companies - Digital Payment Security Controls) Directions, 2026 — RBI/DoS/2026-27/462, DoS.CO.CSITEG.56/31.01.015/2026-27 — and the Reserve Bank of India (Non-Banking Financial Companies - Fraud Risk Management) Directions, 2026 — RBI/DoS/2026-27/463, DoS.CO.FMG.57/23.04.001/2026-27.
Scope: The digital-payment instrument applies to credit-card-issuing NBFCs and to their digital payment products and services, expressly including products offered through RBI-authorised Payment System Operators. The fraud instrument applies to NBFCs registered under the Reserve Bank of India Act, 1934 or the Factoring Regulation Act, 2011 in the Upper, Middle and Base Layers with asset size of Rs 500 crore and above, plus Housing Finance Companies registered under the National Housing Bank Act, 1987 — with the reporting chapters (Chapters VI and VIII) excluding HFCs, which report to the National Housing Bank instead.
Why it matters: The PSO limb closes a structuring gap. Card and lending fintechs commonly deliver the payment leg of a product through an authorised Payment System Operator and treat the security perimeter as the PSO's problem; the Direction places the control obligation on the issuing NBFC irrespective of that routing. The split reporting line for HFCs is the second trap — a group running both an NBFC and an HFC now has two fraud-reporting destinations for structurally similar events, and a single group-level fraud policy that names only the Reserve Bank will be non-compliant for the HFC leg.
Practitioner takeaway: Run a perimeter test first — layer, asset size and registration statute decide which of the three 31 July instruments bind each group entity. Then reconcile fraud-reporting routing (RBI versus NHB) inside the group fraud policy before the next reporting cycle.
Link: RBI — NBFC Digital Payment Security Controls Directions, 2026 | NBFC Fraud Risk Management Directions, 2026
Score: 11/15.
Beyond this Brief Preview — Veritect Legal AI
The full 64-instrument map of the 31 July 2026 RBI consolidation, the repealed-circular concordance, entity-class applicability matrices across the Cybersecurity, Digital Payment Security Controls and Fraud Risk Management Directions, 2026, and a side-by-side of the RBI DAKSH, CERT-In Section 70B and SEBI CSCRF incident-reporting clocks are available in Veritect Legal AI.
Regulatory Action Log — Items 4-8
| Date | Regulator | Pillar | Action | Source |
|---|---|---|---|---|
| 30 Jul 2026 | MeitY / OGAI | platforms-intermediaries | Rule 10 determination deadline for 1-May filers passes. No determination order and no entry in the online register of online money games published on a Tier 1 source as at 2 Aug 2026. Rule 9 five-factor test still untested by published reasoning; appeals lie within 30 days to the Secretary, MeitY as Appellate Authority | meity.gov.in |
| 31 Jul 2026 | SEBI | platforms-intermediaries | Circular extending timelines for compliance with the Digital Accessibility Circulars — the accessibility obligation on SEBI-regulated digital interfaces slips again; relevant to any intermediary shipping a customer-facing app or web front end | sebi.gov.in |
| 30 Jul 2026 | SEBI | platforms-intermediaries | GARUDA (Green-channel: AIF Rollout Upon Document Acknowledgement) mechanism notified for processing AIF placement memoranda — acknowledgement-based digital filing route replacing sequential review for eligible filings | sebi.gov.in |
| 29 Jul 2026 | CERT-In | cybersecurity | CIVN-2026-0381 (severity HIGH) — remote buffer-overflow vulnerability in DD-WRT router firmware; consumer and branch-edge routing exposure, and a reminder that CPE devices sit inside the Section 70B reporting perimeter | cert-in.org.in |
| 28 Jul 2026 | TRAI | telecom-emerging | Press releases No. 104 (Telecom Subscription Data as on June 2026) and No. 105 (Independent Drive Test, Godda Lok Sabha constituency). No consultation paper, regulation or direction issued in the week; TCCCPR (Third Amendment) Regulations, 2026 remain under finalisation post-Open House | trai.gov.in |
Veritect daily-news cross-check: Veritect's daily-news output for 27 July to 2 August 2026 carried no technology-law items for this window. No duplication with this tracker.
What's Next
- 6 August 2026 — expected RBI amendment activity in the Responsible Business Conduct series; watch for digital-lending and recovery-conduct changes with 2027 effective dates.
- 17 August 2026 — RBI data-governance consultation closes (Press Release 2026-2027/677, 15 July 2026). Last date for regulated entities and technology vendors to shape the Data Function, Data Owner, Data Steward and Data Custodian architecture. Submissions to dor.datagovfed@rbi.org.in.
- 24 July 2026 (already passed) — CERT-In AI Blueprint Phase 3 closed at Day 60 of the CISG-2026-02 roadmap for 25-May starters: red-team exercises, adversarial AI simulations, continuous control validation and model-integrity validation. (Corrected 5 September 2026 — this edition originally gave a 23 August 2026 Phase 3 close and described Phase 3 as external AI supply-chain assessments and board reporting; neither is supported by Section 13 of CISG-2026-02. Third-party and supply-chain assurance is a Phase 2 item.)
- ~August–September 2026 — first OGAI Rule 10 determination orders and register entries; each will articulate the Rule 9 five-factor interpretation for every subsequent filer.
- Q3–Q4 2026 — RBI final Model Risk Management guidance following the 24 July consultation close; TRAI TCCCPR (Third Amendment) Regulations, 2026 final notification post-Open House, in force thirty days after Gazette publication.
- ~November 2026 — DPDP consent-manager registration window opens under Rule 4 of the Digital Personal Data Protection Rules, 2025; RBI Q-SAFE quantum-safe roadmap due.
- 1 January 2027 — RBI Customer Liability Amendment Directions go live: Rs 500 SMS alert threshold, 45/60-day fraud investigation windows, five-day credit-card shadow reversal.
- ~13 May 2027 — end of the 18-month DPDP phased-compliance runway.
Founder Action Items
- Re-baseline your cyber control matrix against the named 2026 Direction for your entity class. Citing the 2 June 2016 Cyber Security Framework circular or the November 2023 IT Governance Master Direction is no longer safe. Instruments are now class-specific: Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and AIFIs each have their own text.
- Split your six-hour incident clock into two. CERT-In under Section 70B of the Information Technology Act, 2000 and RBI via DAKSH are separate filings from one detection event, with different recipients and different measurement points. Assign a named owner to each in the escalation matrix.
- Check whether your CISO is independent of the IT function, and whether an IT Strategy Committee exists at board level. Both are express requirements and both are visible in a single board-minutes review — which makes them the cheapest supervisory findings to avoid and the most embarrassing to receive.
- Reopen technology vendor contracts for control flow-down. ATM switch service providers are named; managed-SOC, cloud, core-banking and card-processing agreements should be read for baseline-control flow-down, audit rights, incident-notification timing that supports a six-hour outward filing, and source-code escrow.
- If you are a group with an NBFC and an HFC, fix the fraud-reporting routing now. The Fraud Risk Management Directions, 2026 send HFC reporting to the National Housing Bank and NBFC reporting to the Reserve Bank. A single group policy naming only one recipient fails for the other leg.
- Gaming and payments: do not read the missing determination order as clearance. Liability under the Promotion and Regulation of Online Gaming Act, 2025 attaches to the game's characteristics. Continue to require registration evidence from gaming merchants and ring-fence settlement for money-game-characteristic products.
Practitioner Watch-List
- The repealed-circular concordance. The 31 July circular states the headline count — 628 repealed, 64 consolidated — but the mapping from old reference to new Direction is the artefact clients actually need. Build it before the next inspection cycle, and record for each live enforcement or remediation matter which repealed instruction governed the action taken, because the savings clause fixes applicable law by the date of the action.
- Comply-or-explain for foreign branches. The Commercial Banks Directions apply a comply-or-explain approach to selected provisions for foreign branches. Identify which provisions, document the explanation contemporaneously rather than at inspection, and check whether host-jurisdiction requirements (for example, EU DORA or a host regulator's outsourcing regime) conflict with the DAKSH six-hour filing.
- Vendor flow-down and the third-party perimeter. The naming of ATM switch service providers is indicative, not exhaustive. Expect supervisory attention to spread to managed SOC providers, cloud regions, core-banking vendors and card-processing partners, and expect model documentation duties from the pending Model Risk Management guidance to arrive in the same procurement cycle.
- Interaction with the DoT localisation rule. Rule 25(3) of the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026 (notified 20 July 2026) requires telecommunication network systems and all associated data, logs and information to sit inside India with no copy routed or shared abroad. A regulated entity operating an offshore SOC or global log-shipping pipeline may now face an in-India requirement from the telecom side and an audit-logging requirement from the RBI side at the same time.
- DPBI constitution. No Tier 1 notification of constitution under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 2 August 2026; the Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 continues, with Section 19(1) composition fixed at a Chairperson plus four Members by G.S.R. 845(E). Confirm against the Official Gazette before asserting Board status in any filing or client note.
FAQ
What exactly did RBI issue on 31 July 2026?
The Reserve Bank of India's Department of Supervision issued Consolidation of Supervisory Instructions - Repeal of Circulars (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27), releasing 64 consolidated Directions and repealing 628 circulars. The consolidated Directions absorb instructions from the Department of Supervision and from departments whose supervisory functions merged into it; obsolete instructions were excluded as no longer relevant. Actions already taken under a repealed instruction continue to be governed by that instruction. The package is cut entity-wise: Commercial Banks, Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban and Rural Co-operative Banks, All India Financial Institutions, NBFCs, Housing Finance Companies and Credit Information Companies each receive their own named instruments across compliance, internal audit, statutory audit, supervisory returns, fraud risk, digital payment security and cybersecurity subjects. All are dated 31 July 2026 and all take effect immediately on issuance.
Does the RBI six-hour DAKSH reporting duty replace CERT-In reporting?
No. They are independent obligations. CERT-In reporting arises under Section 70B(6) of the Information Technology Act, 2000 read with the CERT-In Directions of 28 April 2022, is owed to CERT-In, applies to service providers, intermediaries, data centres, body corporates and government organisations, and runs from noticing the incident or being brought to notice about it. The RBI duty under the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 is a supervisory obligation owed to the Reserve Bank through the DAKSH platform and runs from detection. One incident can trigger both, plus a SEBI filing under the Cybersecurity and Cyber Resilience Framework of 20 August 2024 for SEBI-regulated entities and a telecom filing under the Telecommunications (Telecom Cyber Security) Rules, 2024 for authorisation holders. Incident-response runbooks written around a single six-hour clock should be redrafted.
Which entities are covered by the Commercial Banks version of the cybersecurity Directions?
The Reserve Bank of India (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/410, 31 July 2026) apply to banking companies as defined under the Banking Regulation Act, 1949, including corresponding new banks and the State Bank of India, and exclude Small Finance Banks, Payments Banks and Local Area Banks — each of which has its own parallel instrument, with the Payments Banks version at RBI/DoS/2026-27/428. Foreign branches operate on a comply-or-explain approach for selected provisions. NBFCs are covered by RBI/DoS/2026-27/461 (DoS.CO.CSITEG.55/31.01.015/2026-27), which applies differentially by regulatory layer and asset size across six chapters, separating Base Layer NBFCs below Rs 500 crore and Core Investment Companies from Base Layer NBFCs at Rs 500 crore and above and from Top, Upper and Middle Layer NBFCs.
What is the compliance position for online money games after the 30 July 2026 determination deadline?
Unchanged, and that is the point. No determination order or online-register entry was published on a Tier 1 government source as at 2 August 2026. Under the Promotion and Regulation of Online Gaming Rules, 2026 (G.S.R. 303(E), 22 April 2026, in force 1 May 2026) the determination process should as far as practicable be completed within 90 days of a complete application or notice, and a determination order is specific to the particular game and the particular service provider. But prohibition under the Promotion and Regulation of Online Gaming Act, 2025 (Act 32 of 2025) attaches to the characteristics of the game — not to the existence of an order — so offering, advertising or processing financial transactions for a game answering the description of an online money game carries exposure now. On determination the Authority may direct banks and financial institutions to suspend, restrict or block associated financial transactions. Appeals lie within 30 days to the Appellate Authority, the Secretary, MeitY.
Where does DPDP enforcement readiness stand at the start of August 2026?
No Tier 1 notification constituting the Data Protection Board of India under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 2 August 2026. The Rule 17 Search-cum-Selection process under the Digital Personal Data Protection Rules, 2025 continues, and Section 19(1) composition is fixed at a Chairperson plus four Members by G.S.R. 845(E). Board constitution remains the gating event for penalty enforcement under the Schedule — up to Rs 250 crore for failure to take reasonable security safeguards, Rs 200 crore each for breach-notification and children's-data contraventions and Rs 50 crore for residual contraventions. The 18-month phased-compliance runway to approximately 13 May 2027 does not delay Board-initiated Rule 19 inquiries once the Board exists. Appeals lie to TDSAT. Confirm current status against the Official Gazette before relying on it.
Primary Sources
Tier 1 sources only: RBI (rbi.org.in), SEBI (sebi.gov.in), CERT-In (cert-in.org.in), TRAI (trai.gov.in), MeitY (meity.gov.in), DoT (dot.gov.in), eGazette (egazette.gov.in). All developments reported as of 2 August 2026 unless stated. Items flagged 'expected' or 'due' carry that qualifier explicitly. Where a Tier 1 source did not confirm a status — notably the constitution of the Data Protection Board of India and the publication of OGAI determination orders — that is recorded as an absence of confirmation rather than inferred either way. Reconfirm against primary-source URLs before acting.
- RBI — Consolidation of Supervisory Instructions, Repeal of Circulars (RBI/DoS/2026-27/221, 31.07.2026)
- RBI — Commercial Banks Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (RBI/DoS/2026-27/410)
- RBI — NBFC Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (RBI/DoS/2026-27/461)
- RBI — Payments Banks Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (RBI/DoS/2026-27/428)
- RBI — NBFC Digital Payment Security Controls Directions, 2026 (RBI/DoS/2026-27/462)
- RBI — NBFC Fraud Risk Management Directions, 2026 (RBI/DoS/2026-27/463)
- RBI — Notifications portal
- SEBI — Extension of timelines for compliance with Digital Accessibility Circulars (31.07.2026)
- SEBI — Circulars listing
- CERT-In — Vulnerability Notes 2026
- CERT-In — Advisories List 2026
- TRAI — Press Releases
- MeitY — Promotion and Regulation of Online Gaming Act, 2025 and Corrigenda
- MeitY — Digital Personal Data Protection Rules, 2025
- Gazette of India (eGazette)
Beyond this Brief Preview — Veritect Legal AI
Veritect Legal AI carries the research-grade layer behind this tracker: the full text and clause-level analysis of the 31 July 2026 RBI Directions family, the entity-class applicability matrix across all 64 consolidated instruments, the Rule 9 five-factor determination framework under the Promotion and Regulation of Online Gaming Rules, 2026, and the cross-regime incident-reporting concordance spanning Section 70B of the Information Technology Act, 2000, RBI DAKSH, SEBI CSCRF and the Telecommunications (Telecom Cyber Security) Rules, 2024.
Next edition: W32 tracker covering 3–9 August 2026 — RBI Responsible Business Conduct amendments and digital-lending device restrictions, TRAI's quality-of-service consultation paper and quarterly UCC enforcement data, DoT authorisation-portal developments, and new CERT-In advisories.
Corrections
5 September 2026 — CERT-In AI Blueprint Phase 3 close date and characterisation. This edition recorded that Phase 3 of CERT-In advisory CISG-2026-02 (25 May 2026) closes on 23 August 2026 for organisations that began the 60-day implementation on the issue date, and described Phase 3 as external AI supply-chain assessments and board-reporting integration. Neither statement is supported by the advisory. Section 13, Recommended Implementation Roadmap, prescribes a three-phase 60-day roadmap — Phase I Immediate Risk Reduction Days 0–7, Phase II Operational Strengthening Days 8–30, Phase III Advanced Resilience and Adaptive Security Days 31–60. For an entity commencing on 25 May 2026, Day 60 fell on 24 July 2026. Phase III comprises red team exercises and adversarial simulations, continuous control validation, security automation and orchestration, AI-assisted defensive operations, operational resilience and continuity planning, adversarial AI testing, validation of model integrity and AI orchestration security, and continuous reassessment of exposure and resilience posture. Third-party and supply-chain assurance is a Phase II item (Days 8–30), not a Phase III one. Recorded rather than silently amended because the error pointed in the direction of telling a reader a compliance window was still open when it had in fact closed a month earlier.