Digital Law Weekly Tracker: W31 2026 — RBI Repeals 628 Circulars and Issues 64 Consolidated Supervisory Directions, Including Entity-Wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions 2026 with Six-Hour DAKSH Incident Reporting

Weekly Tracker cross-pillar 27 Jul 2026 Status: published
2026-W31
2026-07-27 to 2026-08-02
TL;DR

India's digital-law week of 27 July to 2 August 2026 was dominated by a single event on 31 July: the Reserve Bank of India's Department of Supervision released 64 consolidated Directions and repealed 628 circulars in one exercise (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27). Inside that package sit entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — for Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and All India Financial Institutions — each in force with immediate effect and each requiring cyber-incident reporting to the DAKSH platform within six hours of detection, a 24x7 Security Operations Centre, multi-factor authentication for privileged users and half-yearly disaster-recovery drills. Companion Digital Payment Security Controls and Fraud Risk Management Directions, 2026 issued the same day. The OGAI Rule 10 determination deadline of 30 July for 1-May filers passed with no determination order published on a Tier 1 source as at 2 August 2026.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
20 min read
Continue with Veritect

Track India's digital stack, week by week — DPDP, CERT-In, IT Rules, RBI.

Try Veritect free Book a demo

India's digital-law week of 27 July to 2 August 2026 turned on a single day. On 31 July the Reserve Bank of India's Department of Supervision released 64 consolidated Directions and repealed 628 circulars in one exercise (RBI/DoS/2026-27/221). Inside that package sit entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and All India Financial Institutions — each in force with immediate effect, each requiring cyber-incident reporting to DAKSH within six hours of detection, a 24x7 Security Operations Centre, multi-factor authentication for privileged users and half-yearly disaster-recovery drills. The OGAI Rule 10 determination deadline of 30 July passed with no order published.


At a Glance — W31 Scoreboard

# Pillar Development Issuer Date Score
1 cybersecurity Consolidation of Supervisory Instructions — 64 consolidated Directions released, 628 circulars repealed (RBI/DoS/2026-27/221) RBI, Dept of Supervision 31 Jul 2026 14
2 cybersecurity Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — entity-wise; six-hour DAKSH reporting, 24x7 SOC, independent CISO, half-yearly DR drills RBI 31 Jul 2026 14
3 fintech-payments Digital Payment Security Controls Directions, 2026 + Fraud Risk Management Directions, 2026 for NBFCs RBI 31 Jul 2026 11
4 platforms-intermediaries OGAI Rule 10 determination deadline passes with no published determination order or register entry MeitY / OGAI 30 Jul 2026 8
5 platforms-intermediaries Digital Accessibility Circulars compliance timelines extended; GARUDA green-channel AIF mechanism notified SEBI 30–31 Jul 2026 7
6 cybersecurity CIVN-2026-0381 — remote buffer overflow in DD-WRT router firmware (HIGH) CERT-In 29 Jul 2026 5
7 data-protection DPBI — no Tier 1 notification of Section 18(1) constitution traced; Rule 17 process continues MeitY 2 Aug 2026 5
8 telecom-emerging Press releases No. 104–105 — June 2026 subscription data, Godda drive test; no regulatory instrument in the week TRAI 28 Jul 2026 4

TL;DR for Founders

Three things to act on this week:

  1. If you are a bank, NBFC, payments bank or AIFI — or you sell technology into one: your cybersecurity rulebook changed on 31 July, with no transition period. Six-hour DAKSH incident reporting, a 24x7 SOC, MFA for privileged users and half-yearly DR drills are now Direction-level obligations, not guidance. Vendor contracts are explicitly in scope.

  2. If your incident-response runbook has one six-hour clock in it, it is now wrong. CERT-In under Section 70B of the Information Technology Act, 2000 and RBI via DAKSH are two separate filings from one detection event. Name a different owner for each.

  3. If you run or bank a real-money gaming platform: the 30 July determination deadline passed without a published order. That is not relief. Liability under the Promotion and Regulation of Online Gaming Act, 2025 attaches to the game's characteristics, not to an order — so the absence of a determination changes nothing about exposure.


Top 3 Developments

1. How Did RBI Rewrite the Supervisory Rulebook in a Single Day — and What Happened to the 628 Repealed Circulars? (Cybersecurity)

What changed: On 31 July 2026 the Reserve Bank of India's Department of Supervision issued Consolidation of Supervisory Instructions - Repeal of Circulars, reference RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27. The circular announces the release of 64 consolidated Directions and the repeal of 628 circulars.

What it contains: The consolidated Directions absorb instructions issued by the Department of Supervision and by departments whose supervisory functions later merged into it. Obsolete instructions were excluded from the consolidation on the express footing that they are no longer relevant. The savings clause is the operative protection for pending matters: actions already taken under a repealed instruction continue to be governed by that instruction's provisions.

The 64 Directions are cut entity-wise rather than subject-wise, which is the structural change practitioners will feel most. Each regulated-entity class now has its own named instrument across supervisory subjects — for example, Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026 (RBI/DoS/2026-27/408, DoS.CO.PPG.2/11.01.005/2026-27), Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026 (RBI/DoS/2026-27/413, DoS.CO.PPG.7/11.01.005/2026-27), Reserve Bank of India (Non-Banking Financial Companies - Miscellaneous) Supervisory Directions, 2026 (RBI/DoS/2026-27/467), Reserve Bank of India (Credit Information Companies - Miscellaneous) Supervisory Directions, 2026 (RBI/DoS/2026-27/471), Reserve Bank of India (All India Financial Institutions - Supervisory Returns) Directions, 2026 (RBI/DoS/2026-27/458) and Reserve Bank of India (Local Area Banks - Statutory Audit) Directions, 2026 (RBI/DoS/2026-27/448). All carry the same issue date of 31 July 2026 and all take effect immediately upon issuance.

Why it matters: Every internal policy, board note, audit programme, vendor schedule and regulatory-mapping spreadsheet in an Indian regulated entity that cites a Department of Supervision circular by its old reference is now at risk of citing a repealed instrument. This is not a drafting nicety — supervisory correspondence, RFP compliance annexures and outsourcing agreements routinely quote circular numbers, and a wrong citation in a supervisory response is an avoidable finding. The re-mapping exercise is mechanical but large, and it has no announced grace period.

Practitioner takeaway: Three workstreams. Inventory every instrument citation across policies, contracts and audit programmes. Map each to the corresponding 2026 Direction for your entity class, noting that instruments are now class-specific — a Commercial Bank Direction does not govern a Payments Bank. Preserve the savings position: for any live inspection, enforcement or remediation matter, record which repealed instruction governed the action taken, because the savings clause fixes the applicable law by reference to the date of the action, not the date of the response.

Link: RBI — Consolidation of Supervisory Instructions (Id 13663)

Score: 14/15.


2. What Do the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 Actually Require? (Cybersecurity / Fintech-Payments)

What changed: The consolidation package includes a family of parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued 31 July 2026, one per regulated-entity class: Commercial Banks — RBI/DoS/2026-27/410; Non-Banking Financial Companies — RBI/DoS/2026-27/461, DoS.CO.CSITEG.55/31.01.015/2026-27; Payments Banks — RBI/DoS/2026-27/428; and a further instrument for All India Financial Institutions (EXIM Bank, NABARD, SIDBI, NHB and NaBFID). Each comes into force with immediate effect.

Scope: The Commercial Banks version applies to banking companies under the Banking Regulation Act, 1949, including corresponding new banks and the State Bank of India, and expressly excludes Small Finance Banks, Payments Banks and Local Area Banks — each of which has its own instrument. Foreign branches operate on a comply-or-explain approach for selected provisions. The NBFC version is tiered: Base Layer NBFCs below Rs 500 crore and Core Investment Companies; Base Layer NBFCs at Rs 500 crore and above; and Top, Upper and Middle Layer NBFCs excluding CICs, each carrying differentiated requirements across six chapters.

Why it matters: The obligations are specific and testable, which is what converts a framework into a supervisory finding. On governance — board-approved IT, cybersecurity, information-security and business-continuity policies reviewed at least annually; a board-level IT Strategy Committee; a Chief Information Security Officer independent of the IT function; and Audit Committee oversight of information-systems audit. On controls — asset inventory, multi-factor authentication for privileged users, a 24x7 Security Operations Centre, periodic vulnerability assessment, penetration testing of critical internet-facing systems, disaster-recovery drills at least half-yearly for critical systems, and detailed audit logging. On incidents — reporting to the DAKSH supervisory platform within six hours of detection. On third parties — baseline controls flow through to vendors, with ATM switch service providers named on the face of the instrument.

The strategic point for the wider digital-law stack: this is the second major sectoral instrument in eight days, after the Reserve Bank's model-risk consultation closed on 24 July, to move an area of technology practice from advisory guidance into a binding, auditable control set. India now has three parallel cyber-supervision regimes with materially different perimeters — RBI's Directions for regulated entities, SEBI's Cybersecurity and Cyber Resilience Framework of 20 August 2024 for its regulated entities, and CERT-In's cross-sectoral Directions of 28 April 2022 under Section 70B of the Information Technology Act, 2000. A payments company that is an NBFC, a SEBI-registered intermediary's technology partner, and a body corporate for CERT-In purposes will sit inside all three.

Practitioner takeaway: Re-baseline the control matrix against the named Direction for your entity class, not against the 2 June 2016 Cyber Security Framework circular or the November 2023 IT Governance Master Direction. Check CISO reporting lines against the independence requirement before the next board cycle. Reopen ATM switch, managed-SOC, cloud and core-banking vendor contracts for flow-down of baseline controls and audit rights.

Link: RBI — Commercial Banks Cybersecurity Directions, 2026 | NBFC version

Score: 14/15.


3. Which Digital-Payment and Fraud Obligations Now Bind NBFCs and Housing Finance Companies? (Fintech-Payments)

What changed: Two further instruments issued on 31 July 2026 with immediate effect. The Reserve Bank of India (Non-Banking Financial Companies - Digital Payment Security Controls) Directions, 2026RBI/DoS/2026-27/462, DoS.CO.CSITEG.56/31.01.015/2026-27 — and the Reserve Bank of India (Non-Banking Financial Companies - Fraud Risk Management) Directions, 2026RBI/DoS/2026-27/463, DoS.CO.FMG.57/23.04.001/2026-27.

Scope: The digital-payment instrument applies to credit-card-issuing NBFCs and to their digital payment products and services, expressly including products offered through RBI-authorised Payment System Operators. The fraud instrument applies to NBFCs registered under the Reserve Bank of India Act, 1934 or the Factoring Regulation Act, 2011 in the Upper, Middle and Base Layers with asset size of Rs 500 crore and above, plus Housing Finance Companies registered under the National Housing Bank Act, 1987 — with the reporting chapters (Chapters VI and VIII) excluding HFCs, which report to the National Housing Bank instead.

Why it matters: The PSO limb closes a structuring gap. Card and lending fintechs commonly deliver the payment leg of a product through an authorised Payment System Operator and treat the security perimeter as the PSO's problem; the Direction places the control obligation on the issuing NBFC irrespective of that routing. The split reporting line for HFCs is the second trap — a group running both an NBFC and an HFC now has two fraud-reporting destinations for structurally similar events, and a single group-level fraud policy that names only the Reserve Bank will be non-compliant for the HFC leg.

Practitioner takeaway: Run a perimeter test first — layer, asset size and registration statute decide which of the three 31 July instruments bind each group entity. Then reconcile fraud-reporting routing (RBI versus NHB) inside the group fraud policy before the next reporting cycle.

Link: RBI — NBFC Digital Payment Security Controls Directions, 2026 | NBFC Fraud Risk Management Directions, 2026

Score: 11/15.


Beyond this Brief Preview — Veritect Legal AI

The full 64-instrument map of the 31 July 2026 RBI consolidation, the repealed-circular concordance, entity-class applicability matrices across the Cybersecurity, Digital Payment Security Controls and Fraud Risk Management Directions, 2026, and a side-by-side of the RBI DAKSH, CERT-In Section 70B and SEBI CSCRF incident-reporting clocks are available in Veritect Legal AI.


Regulatory Action Log — Items 4-8

Date Regulator Pillar Action Source
30 Jul 2026 MeitY / OGAI platforms-intermediaries Rule 10 determination deadline for 1-May filers passes. No determination order and no entry in the online register of online money games published on a Tier 1 source as at 2 Aug 2026. Rule 9 five-factor test still untested by published reasoning; appeals lie within 30 days to the Secretary, MeitY as Appellate Authority meity.gov.in
31 Jul 2026 SEBI platforms-intermediaries Circular extending timelines for compliance with the Digital Accessibility Circulars — the accessibility obligation on SEBI-regulated digital interfaces slips again; relevant to any intermediary shipping a customer-facing app or web front end sebi.gov.in
30 Jul 2026 SEBI platforms-intermediaries GARUDA (Green-channel: AIF Rollout Upon Document Acknowledgement) mechanism notified for processing AIF placement memoranda — acknowledgement-based digital filing route replacing sequential review for eligible filings sebi.gov.in
29 Jul 2026 CERT-In cybersecurity CIVN-2026-0381 (severity HIGH) — remote buffer-overflow vulnerability in DD-WRT router firmware; consumer and branch-edge routing exposure, and a reminder that CPE devices sit inside the Section 70B reporting perimeter cert-in.org.in
28 Jul 2026 TRAI telecom-emerging Press releases No. 104 (Telecom Subscription Data as on June 2026) and No. 105 (Independent Drive Test, Godda Lok Sabha constituency). No consultation paper, regulation or direction issued in the week; TCCCPR (Third Amendment) Regulations, 2026 remain under finalisation post-Open House trai.gov.in

Veritect daily-news cross-check: Veritect's daily-news output for 27 July to 2 August 2026 carried no technology-law items for this window. No duplication with this tracker.


What's Next

  • 6 August 2026 — expected RBI amendment activity in the Responsible Business Conduct series; watch for digital-lending and recovery-conduct changes with 2027 effective dates.
  • 17 August 2026RBI data-governance consultation closes (Press Release 2026-2027/677, 15 July 2026). Last date for regulated entities and technology vendors to shape the Data Function, Data Owner, Data Steward and Data Custodian architecture. Submissions to dor.datagovfed@rbi.org.in.
  • 24 July 2026 (already passed)CERT-In AI Blueprint Phase 3 closed at Day 60 of the CISG-2026-02 roadmap for 25-May starters: red-team exercises, adversarial AI simulations, continuous control validation and model-integrity validation. (Corrected 5 September 2026 — this edition originally gave a 23 August 2026 Phase 3 close and described Phase 3 as external AI supply-chain assessments and board reporting; neither is supported by Section 13 of CISG-2026-02. Third-party and supply-chain assurance is a Phase 2 item.)
  • ~August–September 2026first OGAI Rule 10 determination orders and register entries; each will articulate the Rule 9 five-factor interpretation for every subsequent filer.
  • Q3–Q4 2026RBI final Model Risk Management guidance following the 24 July consultation close; TRAI TCCCPR (Third Amendment) Regulations, 2026 final notification post-Open House, in force thirty days after Gazette publication.
  • ~November 2026DPDP consent-manager registration window opens under Rule 4 of the Digital Personal Data Protection Rules, 2025; RBI Q-SAFE quantum-safe roadmap due.
  • 1 January 2027RBI Customer Liability Amendment Directions go live: Rs 500 SMS alert threshold, 45/60-day fraud investigation windows, five-day credit-card shadow reversal.
  • ~13 May 2027 — end of the 18-month DPDP phased-compliance runway.

Founder Action Items

  • Re-baseline your cyber control matrix against the named 2026 Direction for your entity class. Citing the 2 June 2016 Cyber Security Framework circular or the November 2023 IT Governance Master Direction is no longer safe. Instruments are now class-specific: Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and AIFIs each have their own text.
  • Split your six-hour incident clock into two. CERT-In under Section 70B of the Information Technology Act, 2000 and RBI via DAKSH are separate filings from one detection event, with different recipients and different measurement points. Assign a named owner to each in the escalation matrix.
  • Check whether your CISO is independent of the IT function, and whether an IT Strategy Committee exists at board level. Both are express requirements and both are visible in a single board-minutes review — which makes them the cheapest supervisory findings to avoid and the most embarrassing to receive.
  • Reopen technology vendor contracts for control flow-down. ATM switch service providers are named; managed-SOC, cloud, core-banking and card-processing agreements should be read for baseline-control flow-down, audit rights, incident-notification timing that supports a six-hour outward filing, and source-code escrow.
  • If you are a group with an NBFC and an HFC, fix the fraud-reporting routing now. The Fraud Risk Management Directions, 2026 send HFC reporting to the National Housing Bank and NBFC reporting to the Reserve Bank. A single group policy naming only one recipient fails for the other leg.
  • Gaming and payments: do not read the missing determination order as clearance. Liability under the Promotion and Regulation of Online Gaming Act, 2025 attaches to the game's characteristics. Continue to require registration evidence from gaming merchants and ring-fence settlement for money-game-characteristic products.

Practitioner Watch-List

  • The repealed-circular concordance. The 31 July circular states the headline count — 628 repealed, 64 consolidated — but the mapping from old reference to new Direction is the artefact clients actually need. Build it before the next inspection cycle, and record for each live enforcement or remediation matter which repealed instruction governed the action taken, because the savings clause fixes applicable law by the date of the action.
  • Comply-or-explain for foreign branches. The Commercial Banks Directions apply a comply-or-explain approach to selected provisions for foreign branches. Identify which provisions, document the explanation contemporaneously rather than at inspection, and check whether host-jurisdiction requirements (for example, EU DORA or a host regulator's outsourcing regime) conflict with the DAKSH six-hour filing.
  • Vendor flow-down and the third-party perimeter. The naming of ATM switch service providers is indicative, not exhaustive. Expect supervisory attention to spread to managed SOC providers, cloud regions, core-banking vendors and card-processing partners, and expect model documentation duties from the pending Model Risk Management guidance to arrive in the same procurement cycle.
  • Interaction with the DoT localisation rule. Rule 25(3) of the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026 (notified 20 July 2026) requires telecommunication network systems and all associated data, logs and information to sit inside India with no copy routed or shared abroad. A regulated entity operating an offshore SOC or global log-shipping pipeline may now face an in-India requirement from the telecom side and an audit-logging requirement from the RBI side at the same time.
  • DPBI constitution. No Tier 1 notification of constitution under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 2 August 2026; the Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 continues, with Section 19(1) composition fixed at a Chairperson plus four Members by G.S.R. 845(E). Confirm against the Official Gazette before asserting Board status in any filing or client note.

FAQ

What exactly did RBI issue on 31 July 2026?

The Reserve Bank of India's Department of Supervision issued Consolidation of Supervisory Instructions - Repeal of Circulars (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27), releasing 64 consolidated Directions and repealing 628 circulars. The consolidated Directions absorb instructions from the Department of Supervision and from departments whose supervisory functions merged into it; obsolete instructions were excluded as no longer relevant. Actions already taken under a repealed instruction continue to be governed by that instruction. The package is cut entity-wise: Commercial Banks, Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban and Rural Co-operative Banks, All India Financial Institutions, NBFCs, Housing Finance Companies and Credit Information Companies each receive their own named instruments across compliance, internal audit, statutory audit, supervisory returns, fraud risk, digital payment security and cybersecurity subjects. All are dated 31 July 2026 and all take effect immediately on issuance.

Does the RBI six-hour DAKSH reporting duty replace CERT-In reporting?

No. They are independent obligations. CERT-In reporting arises under Section 70B(6) of the Information Technology Act, 2000 read with the CERT-In Directions of 28 April 2022, is owed to CERT-In, applies to service providers, intermediaries, data centres, body corporates and government organisations, and runs from noticing the incident or being brought to notice about it. The RBI duty under the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 is a supervisory obligation owed to the Reserve Bank through the DAKSH platform and runs from detection. One incident can trigger both, plus a SEBI filing under the Cybersecurity and Cyber Resilience Framework of 20 August 2024 for SEBI-regulated entities and a telecom filing under the Telecommunications (Telecom Cyber Security) Rules, 2024 for authorisation holders. Incident-response runbooks written around a single six-hour clock should be redrafted.

Which entities are covered by the Commercial Banks version of the cybersecurity Directions?

The Reserve Bank of India (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/410, 31 July 2026) apply to banking companies as defined under the Banking Regulation Act, 1949, including corresponding new banks and the State Bank of India, and exclude Small Finance Banks, Payments Banks and Local Area Banks — each of which has its own parallel instrument, with the Payments Banks version at RBI/DoS/2026-27/428. Foreign branches operate on a comply-or-explain approach for selected provisions. NBFCs are covered by RBI/DoS/2026-27/461 (DoS.CO.CSITEG.55/31.01.015/2026-27), which applies differentially by regulatory layer and asset size across six chapters, separating Base Layer NBFCs below Rs 500 crore and Core Investment Companies from Base Layer NBFCs at Rs 500 crore and above and from Top, Upper and Middle Layer NBFCs.

What is the compliance position for online money games after the 30 July 2026 determination deadline?

Unchanged, and that is the point. No determination order or online-register entry was published on a Tier 1 government source as at 2 August 2026. Under the Promotion and Regulation of Online Gaming Rules, 2026 (G.S.R. 303(E), 22 April 2026, in force 1 May 2026) the determination process should as far as practicable be completed within 90 days of a complete application or notice, and a determination order is specific to the particular game and the particular service provider. But prohibition under the Promotion and Regulation of Online Gaming Act, 2025 (Act 32 of 2025) attaches to the characteristics of the game — not to the existence of an order — so offering, advertising or processing financial transactions for a game answering the description of an online money game carries exposure now. On determination the Authority may direct banks and financial institutions to suspend, restrict or block associated financial transactions. Appeals lie within 30 days to the Appellate Authority, the Secretary, MeitY.

Where does DPDP enforcement readiness stand at the start of August 2026?

No Tier 1 notification constituting the Data Protection Board of India under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 2 August 2026. The Rule 17 Search-cum-Selection process under the Digital Personal Data Protection Rules, 2025 continues, and Section 19(1) composition is fixed at a Chairperson plus four Members by G.S.R. 845(E). Board constitution remains the gating event for penalty enforcement under the Schedule — up to Rs 250 crore for failure to take reasonable security safeguards, Rs 200 crore each for breach-notification and children's-data contraventions and Rs 50 crore for residual contraventions. The 18-month phased-compliance runway to approximately 13 May 2027 does not delay Board-initiated Rule 19 inquiries once the Board exists. Appeals lie to TDSAT. Confirm current status against the Official Gazette before relying on it.


Primary Sources

Tier 1 sources only: RBI (rbi.org.in), SEBI (sebi.gov.in), CERT-In (cert-in.org.in), TRAI (trai.gov.in), MeitY (meity.gov.in), DoT (dot.gov.in), eGazette (egazette.gov.in). All developments reported as of 2 August 2026 unless stated. Items flagged 'expected' or 'due' carry that qualifier explicitly. Where a Tier 1 source did not confirm a status — notably the constitution of the Data Protection Board of India and the publication of OGAI determination orders — that is recorded as an absence of confirmation rather than inferred either way. Reconfirm against primary-source URLs before acting.

Beyond this Brief Preview — Veritect Legal AI

Veritect Legal AI carries the research-grade layer behind this tracker: the full text and clause-level analysis of the 31 July 2026 RBI Directions family, the entity-class applicability matrix across all 64 consolidated instruments, the Rule 9 five-factor determination framework under the Promotion and Regulation of Online Gaming Rules, 2026, and the cross-regime incident-reporting concordance spanning Section 70B of the Information Technology Act, 2000, RBI DAKSH, SEBI CSCRF and the Telecommunications (Telecom Cyber Security) Rules, 2024.

Next edition: W32 tracker covering 3–9 August 2026 — RBI Responsible Business Conduct amendments and digital-lending device restrictions, TRAI's quality-of-service consultation paper and quarterly UCC enforcement data, DoT authorisation-portal developments, and new CERT-In advisories.


Corrections

5 September 2026 — CERT-In AI Blueprint Phase 3 close date and characterisation. This edition recorded that Phase 3 of CERT-In advisory CISG-2026-02 (25 May 2026) closes on 23 August 2026 for organisations that began the 60-day implementation on the issue date, and described Phase 3 as external AI supply-chain assessments and board-reporting integration. Neither statement is supported by the advisory. Section 13, Recommended Implementation Roadmap, prescribes a three-phase 60-day roadmap — Phase I Immediate Risk Reduction Days 0–7, Phase II Operational Strengthening Days 8–30, Phase III Advanced Resilience and Adaptive Security Days 31–60. For an entity commencing on 25 May 2026, Day 60 fell on 24 July 2026. Phase III comprises red team exercises and adversarial simulations, continuous control validation, security automation and orchestration, AI-assisted defensive operations, operational resilience and continuity planning, adversarial AI testing, validation of model integrity and AI orchestration security, and continuous reassessment of exposure and resilience posture. Third-party and supply-chain assurance is a Phase II item (Days 8–30), not a Phase III one. Recorded rather than silently amended because the error pointed in the direction of telling a reader a compliance window was still open when it had in fact closed a month earlier.

Primary source

Title: Consolidation of Supervisory Instructions - Repeal of Circulars (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27, 31 July 2026)
Issuer: Reserve Bank of India, Department of Supervision
Effective: 2026-07-31

Frequently asked

What did the Reserve Bank of India do on 31 July 2026 and why is it the biggest Indian cyber-regulatory event of 2026 so far?

On 31 July 2026 the Reserve Bank of India's Department of Supervision issued a circular titled 'Consolidation of Supervisory Instructions - Repeal of Circulars' (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27) announcing the release of 64 consolidated Directions and the repeal of 628 circulars in a single exercise. The consolidated Directions absorb instructions issued by the Department of Supervision and by departments whose supervisory functions have since merged into it; obsolete instructions were excluded on the footing that they are no longer relevant. Actions already taken under a repealed instruction continue to be governed by that instruction's provisions, so the exercise does not disturb pending supervisory or enforcement matters. For digital-law practitioners the significance is that the cyber and technology rulebook for Indian regulated entities has moved from a two-decade accretion of circulars into entity-wise Directions carrying immediate effect. The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 were issued in parallel versions for Commercial Banks (RBI/DoS/2026-27/410), Non-Banking Financial Companies (RBI/DoS/2026-27/461, DoS.CO.CSITEG.55/31.01.015/2026-27), Payments Banks (RBI/DoS/2026-27/428) and All India Financial Institutions, alongside Digital Payment Security Controls Directions, 2026 and Fraud Risk Management Directions, 2026. The compliance consequence is immediate: an entity's cyber policy stack now has to be re-mapped against a named Direction rather than a bundle of superseded circulars, and the previous practice of citing the 2 June 2016 Cyber Security Framework circular or the November 2023 IT Governance Master Direction as the controlling instrument is no longer safe.

What are the headline obligations under the RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026?

Taking the Commercial Banks version (RBI/DoS/2026-27/410, 31 July 2026) as the reference text, the framework is built on governance plus a technical control baseline. On governance: a board-approved suite of IT, cybersecurity, information-security and business-continuity policies reviewed at least annually; a board-level IT Strategy Committee; a Chief Information Security Officer whose role is independent of the IT function; and Audit Committee oversight of information-systems audit. On controls: a maintained asset inventory, multi-factor authentication for privileged users, a 24x7 Security Operations Centre, regular vulnerability assessment, penetration testing of critical internet-facing systems, disaster-recovery drills at least half-yearly for critical systems, and detailed audit logging across systems. On incident handling: cyber incidents must be reported to the RBI DAKSH platform within six hours of detection. Third-party reach is explicit — baseline controls flow through to vendors, with ATM switch service providers named. Foreign branches of Indian banks operate on a comply-or-explain approach for selected provisions. The Directions came into force with immediate effect on issuance, with no transition window announced, and commentary across the sector notes that they extend into areas previously covered only loosely, including data governance, cryptography, secure software development, vendor risk management, source-code escrow, IPv6 readiness and teleworking security.

Is the RBI six-hour DAKSH reporting duty the same as the CERT-In six-hour reporting duty?

No. They are two separate reporting obligations with different legal bases, different recipients and different trigger populations, and a regulated entity suffering one incident will frequently owe both. The CERT-In duty arises under Section 70B(6) of the Information Technology Act, 2000 read with the CERT-In Directions of 28 April 2022, applies to service providers, intermediaries, data centres, body corporates and government organisations generally, and requires notification of listed cyber-incident types to CERT-In within six hours of noticing the incident or being brought to notice about it. The RBI duty under the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 is a supervisory obligation on a regulated entity, is owed to the Reserve Bank through the DAKSH supervisory platform, and is measured from detection. Practical consequence for an incident-response runbook: a single detection event should fire two parallel clocks, not one, and the escalation matrix must name a person accountable for each filing. Sector-specific reporting obligations sit on top for entities that are also SEBI-regulated under the Cybersecurity and Cyber Resilience Framework of 20 August 2024, or that hold a telecom authorisation and owe reporting under the Telecommunications (Telecom Cyber Security) Rules, 2024.

Which NBFCs are caught by the Digital Payment Security Controls and Fraud Risk Management Directions, 2026?

The two instruments have deliberately different perimeters. The Reserve Bank of India (Non-Banking Financial Companies - Digital Payment Security Controls) Directions, 2026 (RBI/DoS/2026-27/462, DoS.CO.CSITEG.56/31.01.015/2026-27, 31 July 2026) apply to credit-card-issuing NBFCs and to their digital payment products and services, including products offered through RBI-authorised Payment System Operators. That last limb is the one lending and card-issuing fintechs should read closely: routing a product through an authorised PSO does not move it outside the perimeter. The Reserve Bank of India (Non-Banking Financial Companies - Fraud Risk Management) Directions, 2026 (RBI/DoS/2026-27/463, DoS.CO.FMG.57/23.04.001/2026-27, 31 July 2026) apply to NBFCs in the Upper Layer and Middle Layer and to Base Layer NBFCs with asset size of Rs 500 crore and above, together with Housing Finance Companies registered under the National Housing Bank Act, 1987 — but the reporting chapters exclude HFCs, which report instead to the National Housing Bank. The cybersecurity Directions for NBFCs (RBI/DoS/2026-27/461) apply differentially by regulatory layer and asset size, separating Base Layer NBFCs below Rs 500 crore and Core Investment Companies from Base Layer NBFCs at Rs 500 crore and above and from Top, Upper and Middle Layer NBFCs. Scoping is therefore the first workstream, not the last.

Did the Online Gaming Authority of India publish its first Rule 10 determination orders by the 30 July 2026 deadline?

No determination order and no entry in the online register of online money games had been published on a Tier 1 government source as at 2 August 2026. The 30 July 2026 date is the outer edge of the period for the first cohort of applicants who filed when the Promotion and Regulation of Online Gaming Rules, 2026 (G.S.R. 303(E), 22 April 2026) came into force on 1 May 2026; under the Rules the determination process should as far as practicable be completed within 90 days of a complete application or notice. Until a determination order is published, the Rule 9 five-factor test — participation fees, the user's expectation of winning money or other enrichment, the use made of fees and deposits, the structure of the revenue model, and how rewards, benefits or in-game assets are transferred, redeemed, monetised or used outside the game — remains untested by any published reasoning. That matters commercially because liability under the Promotion and Regulation of Online Gaming Act, 2025 (Act 32 of 2025) attaches to the characteristics of the game, not to the existence of a determination order: payment aggregators and banks processing transactions for a game that answers the description carry independent exposure whether or not the Authority has spoken. Appeals against a determination lie within 30 days to the Appellate Authority, which is the Secretary, MeitY.

Tags

digital-law weekly-tracker rbi-supervisory-consolidation rbi-cybersecurity-directions-2026 daksh-six-hour-incident-reporting digital-payment-security-controls fraud-risk-management-directions-2026 ciso-independence ogai-determination prog-act-2025 cert-in-vulnerability-note sebi-digital-accessibility dpdp-rules-2025 cybersecurity fintech-payments platforms-intermediaries data-protection telecom-emerging
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free