Skip to main content
Compliance · RBI Directions, 2026

The paragraph 151 cadence is a schedule, not a procurement event

The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 came into effect on the day they were issued, 31 July 2026. Paragraph 151 sets vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical information systems and / or those in the DMZ having customer interface, and paragraph 150 adds the lifecycle trigger points. This page sets out what an engagement produces against those paragraphs, which duties stay with the bank, and which delivery model puts a named auditor inside the work.

What the engagement leaves behind

Three moments, and what exists at each of them

Evidence opens this page because a bank under these Directions is buying an artefact rather than an activity. The paragraph numbers are in the instrument; what an engagement hands over is not.

01 Scope

Before anything runs

The scope
Which targets, which of the eleven coverage classes, which roles, and what the run is authorised to do. Agreed and signed before the engagement starts, and retained with it.
The method
The methodology the engagement will follow, written down, including how severity is derived. Paragraph 154 puts the documented approach on the bank; this is an input to it.
The gates
Three approval gates are set before the run and apply on every class and in all three delivery models: destructive or state-changing actions; persistence and movement past the entry host; live credentials or real customer data.
02 Testing

While the testing runs

The exchange
Every finding carries the request and the response as sent and returned, with the portion that proves the defect marked. A reviewer does not have to take the finding on trust.
The reproduction
Steps written so that one of your own engineers can reproduce the finding without us in the room, which is what makes a remediation testable by the team doing it.
The refusals
What each gate permitted and what it refused is recorded with the run. That record is where the testing stopped, and why, in the words of the person who authorised it.
03 Closure

After the report lands

The severity
CVSS v4.0 with the vector printed, so a score can be recomputed rather than accepted, and the CWE naming the weakness class.
The retest
A finding closes on a retest that cannot reproduce it. The retest is run against the conditions that produced the original finding.
The signature
In the expert-verified and human-led models the report is signed by Security Brigade as the firm that delivered the engagement. Security Brigade has been CERT-In empanelled since 2008.

The closure vocabulary

Four states, and only one of them is conferred by a retest

Paragraph 161 puts the status of closure of VA / PT observations in front of the IT Strategy Committee and the Information Security Committee at least quarterly. A status is worth no more than the vocabulary underneath it, so the vocabulary is published.

Four states, and only one of them is conferred by a retest
StateWhat it meansWhat follows
Open Proven, reported, and unchanged since it was written. The exchange that produced it and the steps to reproduce it are in the report. Counts against closure.
Fixed Your team has recorded a remediation. The finding moves on your assertion, and the state says so rather than dressing it as a closure. Still counts against closure.
Retested The remediation has been tested against the conditions that produced the original finding, in the same scope. Resolves to closed, or returns to open.
Closed Terminal The retest could not reproduce the finding. This is the only route into this state, which is what makes the number defensible at quarter end. Closed, with the retest on record.
Key
  • Proven and outstanding
  • Asserted fixed, not yet verified
  • Verification in progress
  • Closed on a retest that could not reproduce it
  • TerminalNo state follows this one

The paragraphs with a clock on them

What the Directions ask of a bank’s testing programme

Modality is stated on every row because the difference between shall and may is the whole content of two of these paragraphs. Each was read on the Reserve Bank’s Directions page for RBI/DoS/2026-27/410.

ParagraphWhat it says
149 and 150 Paragraph 149 requires VA and PT periodically for all the critical and internet facing systems. Paragraph 150 adds the trigger points: VA / PT of critical, internet facing web / mobile applications, servers, and network components throughout their lifecycle, including pre-implementation, post implementation, and after changes.
Modality: shall. Paragraph 150 adds trigger points rather than a frequency — the frequency is the paragraph below. Read at source, 14 September 2026.
151 For critical information systems and / or those in the DMZ having customer interface, VA at least once in every six months and PT at least once in 12 months. For non-critical information systems, a risk-based approach decides both the requirement and the periodicity of conduct.
Modality: shall. The scope is disjunctive — and / or — so either criticality or a DMZ customer interface brings a system inside the cadence. Read at source, 14 September 2026.
154 A documented approach for the conduct of VA / PT covering the scope, coverage, vulnerability scoring mechanism such as the Common Vulnerability Scoring System, and all other aspects. This shall also apply to the bank’s information systems hosted in a cloud environment.
Modality: shall, on both limbs — the same documented approach reaches information systems hosted in a cloud environment. The duty is the bank’s. Read at source, 14 September 2026.
160 and 161 Findings and follow-up actions are to be monitored closely by the Information Security and IS Audit teams and by Senior Management, and the status of the closure of the VA / PT observations shall be put to the IT Strategy Committee and the Information Security Committee at least on a quarterly basis.
Modality: shall, and at least quarterly is a floor. The cadence attaches to the reporting of closure status rather than to the testing. Read at source, 14 September 2026.
162 The bank may conduct red teaming exercises to identify the vulnerabilities and the business risk, assess the efficacy of the defences and check the mitigating controls already in place by simulating the objectives and actions of an attacker.
Modality: may. The paragraph confers a discretion on the bank, and the verb is the whole content of the row. Read at source, 14 September 2026.
182 Cyber incidents reported within six hours of detection on the DAKSH platform, the Reserve Bank’s Advanced Supervisory Monitoring System. The bank shall also pro-actively notify CERT-In regarding cyber incidents.
Modality: shall, on both limbs. The six-hour clock attaches to the DAKSH limb, and the CERT-In limb is written as a pro-active notification duty. Read at source, 14 September 2026.
227 and 228 A separate IS Audit function or resources with the required professional skills and competence within the Internal Audit function. Where the bank uses external resources in areas where skills are lacking, responsibility and accountability remain with the competent authority within Internal Audit. IS Audit planning is carried out by adopting a risk-based audit approach.
Modality: shall. The risk-based audit approach is the planning basis the paragraph names. Read at source, 14 September 2026.

149 and 150

What it says
Paragraph 149 requires VA and PT periodically for all the critical and internet facing systems. Paragraph 150 adds the trigger points: VA / PT of critical, internet facing web / mobile applications, servers, and network components throughout their lifecycle, including pre-implementation, post implementation, and after changes.

Modality: shall. Paragraph 150 adds trigger points rather than a frequency — the frequency is the paragraph below. Read at source, 14 September 2026.

151

What it says
For critical information systems and / or those in the DMZ having customer interface, VA at least once in every six months and PT at least once in 12 months. For non-critical information systems, a risk-based approach decides both the requirement and the periodicity of conduct.

Modality: shall. The scope is disjunctive — and / or — so either criticality or a DMZ customer interface brings a system inside the cadence. Read at source, 14 September 2026.

154

What it says
A documented approach for the conduct of VA / PT covering the scope, coverage, vulnerability scoring mechanism such as the Common Vulnerability Scoring System, and all other aspects. This shall also apply to the bank’s information systems hosted in a cloud environment.

Modality: shall, on both limbs — the same documented approach reaches information systems hosted in a cloud environment. The duty is the bank’s. Read at source, 14 September 2026.

160 and 161

What it says
Findings and follow-up actions are to be monitored closely by the Information Security and IS Audit teams and by Senior Management, and the status of the closure of the VA / PT observations shall be put to the IT Strategy Committee and the Information Security Committee at least on a quarterly basis.

Modality: shall, and at least quarterly is a floor. The cadence attaches to the reporting of closure status rather than to the testing. Read at source, 14 September 2026.

162

What it says
The bank may conduct red teaming exercises to identify the vulnerabilities and the business risk, assess the efficacy of the defences and check the mitigating controls already in place by simulating the objectives and actions of an attacker.

Modality: may. The paragraph confers a discretion on the bank, and the verb is the whole content of the row. Read at source, 14 September 2026.

182

What it says
Cyber incidents reported within six hours of detection on the DAKSH platform, the Reserve Bank’s Advanced Supervisory Monitoring System. The bank shall also pro-actively notify CERT-In regarding cyber incidents.

Modality: shall, on both limbs. The six-hour clock attaches to the DAKSH limb, and the CERT-In limb is written as a pro-active notification duty. Read at source, 14 September 2026.

227 and 228

What it says
A separate IS Audit function or resources with the required professional skills and competence within the Internal Audit function. Where the bank uses external resources in areas where skills are lacking, responsibility and accountability remain with the competent authority within Internal Audit. IS Audit planning is carried out by adopting a risk-based audit approach.

Modality: shall. The risk-based audit approach is the planning basis the paragraph names. Read at source, 14 September 2026.

The testing relationship itself

Paragraphs 155 to 159, in the order they bite

This is the cluster that governs the testing relationship itself rather than its frequency, and every duty in it belongs to the bank. Three of the five attach at renewal, which is why they are worth reading before a contract rolls rather than after.

How this page was sourced

One instrument, read at source, with the edge of the reading marked

RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 As of 2026-09-14
  • RBI/DoS/2026-27/410, reference DoS.CO.CSITEG.4/31.01.015/2026-27, issued 31 July 2026 by the Department of Supervision in exercise of powers under the Banking Regulation Act, 1949 and the Reserve Bank of India Act, 1934. 233 paragraphs across eight chapters.
  • Paragraph 2: the Directions come into effect immediately upon issuance. The date they started to apply is the date they were signed.
  • Paragraph 3 sets who they reach — banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, corresponding new banks, and the State Bank of India, as defined in the Banking Regulation Act, 1949.
  • Every paragraph quoted or paraphrased on this page was read on the Reserve Bank’s Directions page for RBI/DoS/2026-27/410 on 14 September 2026.
  • Paragraph 230 repeals the extant Cybersecurity Framework and IT Governance instructions applicable to Commercial Banks, as communicated by circular DoS.CO.PPG.66/11.01.005/2026-27 of 31 July 2026 — RBI/DoS/2026-27/221, which repeals 628 circulars with immediate effect alongside 64 Consolidated Directions administered by the Department of Supervision. Read at source, 14 September 2026.
  • Paragraph 231 saves action already taken or initiated under the repealed instruments, which continues to be governed by them.
  • Six entity-specific Directions carry the same date and the same department, including those for Commercial Banks, Small Finance Banks, Payments Banks, Urban Co-operative Banks, NBFCs and Credit Information Companies.

Deliberately excluded

  • The annex to the repeal circular has not been read. The repeal is cited from paragraph 230 and from the repeal circular’s own text in general terms, and no individual pre-2026 circular is placed at any annex position anywhere on this page.
  • Currency is stated as traced rather than certified. The Directions page renders the instrument as issued on 31 July 2026 with no amendment notation, and no amending Direction was traced between 31 July and 14 September 2026 — which is a search result, not a certification. Re-check before relying on it.
  • The five sibling instruments were not separately currency-checked in this reading, and their paragraph numbering differs from the numbering used here. A Commercial Banks paragraph number is not a citation for an NBFC or an Urban Co-operative Bank, and two of the six apply their chapters by tier.
  • Population figures for any entity class are outside this reading. Paragraph 3 defines who is in scope; a count of the entities that reaches would have to come from elsewhere, and none is published here.

How findings map

Which duty each part of an engagement supplies into

Paragraphs 149 to 161 address the bank. An engagement supplies into those duties rather than discharging them, and that is the distinction a supervisor makes first.

The bank’s dutyWhat an engagement supplies
Paragraph 151 — VA at least once in every six months and PT at least once in 12 months, across critical information systems and / or DMZ systems with a customer interface Testing held on a calendar rather than assembled as a procurement event each time. Coverage is the same eleven classes in all three delivery models, so one scope can carry the whole of the paragraph 151 estate instead of splitting it across vendors.
Paragraph 150 — testing at pre-implementation, post implementation and after changes, across the lifecycle of the application, server or network component Per-scan units rather than a single annual engagement, so a release or a change can be tested when it happens rather than at the next contract window. The entry tier is $500 for one scan of one application or target.
A paragraph 150 trigger fires where it fires in a release cycle, which on an annual contract is between engagements.
Paragraph 154 — a documented approach covering scope, coverage and a vulnerability scoring mechanism, applied also to information systems hosted in a cloud environment A written methodology and a signed scope per engagement, severity on CVSS v4.0 with the vector printed, and the CWE per finding. Cloud configuration is one of the eleven classes rather than an add-on to the network scope.
The documented approach is the bank’s artefact. What is supplied here is an input to it.
Paragraph 156 — qualification, professional expertise, credentials and competency, of the firm and of the audit personnel, assessed at every selection, appointment, engagement or renewal Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified. In the expert-verified and human-led models a senior Security Brigade auditor is inside the engagement, so the assessment has a named team to run against.
Paragraphs 160 and 161 — findings and follow-up monitored closely, and closure status put to the IT Strategy Committee and the Information Security Committee at least quarterly Each finding holds its own state through open, fixed, retested and closed, and reaches closed only on a retest that cannot reproduce it. The closure position is therefore readable on any day of the quarter rather than reconstructed at the end of it.
What the committee is handed, and in what shape, is the bank’s decision.

Paragraph 151 — VA at least once in every six months and PT at least once in 12 months, across critical information systems and / or DMZ systems with a customer interface

What an engagement supplies
Testing held on a calendar rather than assembled as a procurement event each time. Coverage is the same eleven classes in all three delivery models, so one scope can carry the whole of the paragraph 151 estate instead of splitting it across vendors.

Paragraph 150 — testing at pre-implementation, post implementation and after changes, across the lifecycle of the application, server or network component

What an engagement supplies
Per-scan units rather than a single annual engagement, so a release or a change can be tested when it happens rather than at the next contract window. The entry tier is $500 for one scan of one application or target.

A paragraph 150 trigger fires where it fires in a release cycle, which on an annual contract is between engagements.

Paragraph 154 — a documented approach covering scope, coverage and a vulnerability scoring mechanism, applied also to information systems hosted in a cloud environment

What an engagement supplies
A written methodology and a signed scope per engagement, severity on CVSS v4.0 with the vector printed, and the CWE per finding. Cloud configuration is one of the eleven classes rather than an add-on to the network scope.

The documented approach is the bank’s artefact. What is supplied here is an input to it.

Paragraph 156 — qualification, professional expertise, credentials and competency, of the firm and of the audit personnel, assessed at every selection, appointment, engagement or renewal

What an engagement supplies
Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified. In the expert-verified and human-led models a senior Security Brigade auditor is inside the engagement, so the assessment has a named team to run against.

Paragraphs 160 and 161 — findings and follow-up monitored closely, and closure status put to the IT Strategy Committee and the Information Security Committee at least quarterly

What an engagement supplies
Each finding holds its own state through open, fixed, retested and closed, and reaches closed only on a retest that cannot reproduce it. The closure position is therefore readable on any day of the quarter rather than reconstructed at the end of it.

What the committee is handed, and in what shape, is the bank’s decision.

The scoping question

What critical and / or DMZ having customer interface does to a scope

Paragraph 151 writes its scope disjunctively, and that single conjunction decides how large the cadence is. A system is inside the six-month and twelve-month cadence if it is a critical information system, and it is inside if it sits in the DMZ with a customer interface — either limb on its own is sufficient, and the second limb reaches the internet-facing customer estate. For information systems that are not critical, the same paragraph puts both the requirement and the periodicity on a risk-based approach the bank adopts and records. Two consequences follow for anyone writing a scope against this paragraph. The first is that the scope is built from two tests rather than one, so a system that does not clear an internal criticality threshold can still be brought in by the DMZ limb. The second is that paragraph 150 attaches to the lifecycle rather than to the calendar, so a scope written once a year and executed once a year carries the cadence but leaves the trigger points — pre-implementation, post implementation, after changes — to fall between engagements.

Why the model is the decision

The paragraphs that make this a question about people

Paragraph 155 asks for appropriately trained and independent information security experts or auditors. Paragraph 156 then gives the bank the job of checking that, and sets out what it checks: requisite qualification, professional expertise of the firm as well as of the audit personnel engaged by it, appropriate credentials and suitable competency — at selection, at appointment, at engagement and again at every renewal. That is an assessment run on a named team, which is why the delivery model is the first decision on this page rather than a footnote to it. Paragraph 159 adds what follows where the auditor a bank engages is CERT-In empanelled: the bank is then guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines, so an empanelled firm brings a defined audit-policy regime into the relationship alongside the testing. Security Brigade has held CERT-In empanelment since 2008, and in the expert-verified and human-led models the engagement is delivered by that firm.

The boundary

What this page claims, and where it stops

The instrument runs to 233 paragraphs across eight chapters. These are the five places this page deliberately declines to round a fact up.

The position
How much of the instrument this covers What is described here is testing and the evidence it produces. The Cyber Security Operations Centre of Chapter VI, incident response operations, digital forensics and DDoS standby arrangements, business continuity and disaster recovery, data loss prevention and endpoint controls are the bank’s own programme, and none of them is an offering on this site.
Mapping, never issuing Findings are mapped to the paragraphs a bank is measured against. Certification and attestation are issued by certification bodies and by auditors appointed for that purpose, which is separate work from testing and is not performed here.
Whose duties these are Paragraphs 149 to 161 address the bank. The documented approach is the bank’s to hold, the auditor assessment is the bank’s to run, the review of coverage and scope is the bank’s to do, and the quarterly closure status is the bank’s to put to its committees. An engagement supplies into those duties.
What paragraph 158 actually does It is a performance-evaluation standard the bank applies. A tested system later found to have been compromised through vulnerabilities not observed or highlighted on a timely basis qualifies as a deficiency in discharge of function, and the consequence the paragraph names is that such deficiencies are factored in when the contract is next selected or renewed. The text carries the qualifiers ceteris paribus and apparently.
This instrument, not its siblings Every paragraph number on this page is a Commercial Banks number, from RBI/DoS/2026-27/410. Small Finance Banks, Payments Banks, Urban Co-operative Banks, NBFCs and Credit Information Companies each received their own Direction on the same date, and two of those apply their chapters by tier — by digital capability in one and by Scale Based Regulation layer in the other. Which instrument reaches your entity, and what it asks of you, is a determination for you and your advisers.
The sibling instruments were not separately currency-checked in the reading behind this page.

How much of the instrument this covers

The position
What is described here is testing and the evidence it produces. The Cyber Security Operations Centre of Chapter VI, incident response operations, digital forensics and DDoS standby arrangements, business continuity and disaster recovery, data loss prevention and endpoint controls are the bank’s own programme, and none of them is an offering on this site.

Mapping, never issuing

The position
Findings are mapped to the paragraphs a bank is measured against. Certification and attestation are issued by certification bodies and by auditors appointed for that purpose, which is separate work from testing and is not performed here.

Whose duties these are

The position
Paragraphs 149 to 161 address the bank. The documented approach is the bank’s to hold, the auditor assessment is the bank’s to run, the review of coverage and scope is the bank’s to do, and the quarterly closure status is the bank’s to put to its committees. An engagement supplies into those duties.

What paragraph 158 actually does

The position
It is a performance-evaluation standard the bank applies. A tested system later found to have been compromised through vulnerabilities not observed or highlighted on a timely basis qualifies as a deficiency in discharge of function, and the consequence the paragraph names is that such deficiencies are factored in when the contract is next selected or renewed. The text carries the qualifiers ceteris paribus and apparently.

This instrument, not its siblings

The position
Every paragraph number on this page is a Commercial Banks number, from RBI/DoS/2026-27/410. Small Finance Banks, Payments Banks, Urban Co-operative Banks, NBFCs and Credit Information Companies each received their own Direction on the same date, and two of those apply their chapters by tier — by digital capability in one and by Scale Based Regulation layer in the other. Which instrument reaches your entity, and what it asks of you, is a determination for you and your advisers.

The sibling instruments were not separately currency-checked in the reading behind this page.

Adjacent instruments

Where the question is who may sign rather than how often

Paragraph 156 is about competency and paragraph 159 is about what an empanelled engagement brings with it. Whether a particular filing calls for empanelled delivery turns on the instrument the filing is made under, and those instruments are not interchangeable. The CERT-In page in the framework list below names each one and what it carries, scoped to itself. Under SEBI’s Cyber Security and Cyber Resilience Framework the same estate is measured differently again: VAPT, cyber audit, red teaming and threat hunting sit on four separate cadences with four separate deliverables, and treating them as one engagement produces a filing that does not match the framework’s own table.

Put the paragraph 151 cadence on a schedule

A scoping call settles which systems meet either of paragraph 151’s two tests, where paragraph 150’s trigger points fall in your release cycle, and which delivery model the engagement needs — which, under paragraph 156, is a question about the named team as much as about the scope.