India · BFSI

RBI & SEBI:
Cybersecurity compliance for Indian BFSI

Banks, NBFCs, payment operators, stock exchanges, brokers, and asset managers in India sit under two overlapping regulators for cybersecurity — RBI for banking and payments, SEBI for capital markets — each with its own framework, reporting lines, and audit expectations.

Banks · NBFCs

RBI applies to

Payment system operators, co-op banks

MIIs · REs

SEBI applies to

Exchanges, brokers, AMCs, depositories

CSCRF

SEBI framework

Cybersecurity & Cyber Resilience Framework

SOC + VAPT

Shared ground

Common across both regulators

Why these sit apart from DPDP and GDPR

DPDP and GDPR govern personal data protection. RBI and SEBI govern the operational and cybersecurity resilience of regulated financial infrastructure itself — a bank or broker can be fully DPDP-compliant on data privacy and still fail an RBI or SEBI cybersecurity audit on an entirely separate set of obligations: board governance, SOC monitoring, incident response readiness, and third-party risk. Most BFSI organisations need to satisfy both categories simultaneously, on separate but overlapping evidence trails.

RBI — what banks & NBFCs are expected to have

1

Board-Approved Cyber Security Policy

A cyber security policy distinct from the general IT policy, approved by the board and reviewed periodically — not a subsection of an existing IT document.

2

Security Operations Centre (SOC)

Continuous monitoring and threat detection capability, whether run in-house or through a managed security service provider.

3

Cyber Crisis Management Plan (CCMP)

A tested, board-reviewed plan for detection, response, containment, and recovery from cyber incidents — not a document written once and filed away.

4

Incident Reporting

Time-bound reporting of qualifying cyber incidents to RBI and CERT-In, with the reporting workflow tested before an actual incident, not designed reactively during one.

5

IT & Outsourcing Governance

Risk assessment, board oversight, and exit strategy provisions for any IT service — including cloud and managed services — outsourced to a third party.

SEBI CSCRF — what market participants are expected to have

1

Tiered Applicability

Obligations scale by category — Market Infrastructure Institutions carry the highest bar, down through Qualified, Mid-size, and Small-size regulated entities.

2

VAPT & SOC Monitoring

Periodic vulnerability assessment and penetration testing plus continuous security operations monitoring, scaled to entity tier.

3

Cyber Crisis Management Plan

A board-approved plan for incident detection, response, and recovery, aligned with SEBI and CERT-In reporting requirements.

4

Data Localisation & Third-Party Risk

Data residency considerations and vendor risk assessment for any technology provider handling regulated data or systems.

Where this overlaps with what SG2 already delivers

VAPT requirements map directly to SG2's network and API penetration testing practice. SOC monitoring and incident response readiness map to Cyber Security Integration & Remediation. Board-ready evidence and multi-framework mapping (RBI, SEBI, ISO 27001, NIST CSF) run through MetaSight's compliance packs.

Frequently Asked Questions

Does RBI's cyber security framework apply to NBFCs, or only banks?
RBI's cyber security and IT governance expectations extend well beyond scheduled commercial banks — NBFCs, payment system operators, and cooperative banks are all brought into scope through their own applicable master directions, generally scaled to the entity's size and risk profile rather than a single uniform bar.
What is SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF)?
CSCRF is SEBI's consolidated cybersecurity framework covering Market Infrastructure Institutions (stock exchanges, clearing corporations, depositories) and regulated entities (brokers, mutual funds, AMCs, portfolio managers, and others), replacing a set of earlier sector-specific circulars with a single structure that scales obligations by entity size and systemic importance.
Do RBI and SEBI compliance work overlap with ISO 27001 or SOC 2?
Substantially. Board-approved security policy, risk assessment, incident response, vendor/outsourcing risk management, and periodic audits are common ground across RBI, SEBI, ISO 27001, and SOC 2 — an organisation that has already implemented one has a real head start on the others, even though each has regulator-specific requirements layered on top.
What does a VAPT requirement under SEBI/RBI actually involve?
Periodic vulnerability assessment and penetration testing of critical systems and infrastructure, typically by an empanelled or accredited third party, with findings tracked to remediation and evidenced for the regulator — not a one-time exercise, but a recurring cycle tied to the entity's audit calendar.

Not sure if RBI or SEBI applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call