Which Indian instrument says what about security awareness
The clause reference for employee cyber security awareness in India: the RBI Directions, 2026 across six entity types, SEBI CSCRF, CERT-In CISG-2025-02 and the DPDP Act, with paragraph and page numbers.
Four Indian instruments bear on employee cyber security awareness. The Reserve Bank's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 and SEBI's Cybersecurity and Cyber Resilience Framework, Version 1.0, place awareness obligations on supervised entities. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, govern how an empanelled auditing organisation conducts a test of that awareness. The Digital Personal Data Protection Act, 2023 governs the personal data such a test produces. This page prints the operative clause for each, with its number and page.
Two structural facts decide which row applies. The RBI paragraph number differs in each of the six entity-specific Directions. And where an instrument carries both, training and evaluation are separate provisions.
How the RBI Directions, 2026 are numbered
Six Directions, one for each supervised entity category, all issued 31 July 2026 and in force on issuance. They are separate documents, and the paragraph carrying the same obligation is numbered differently in each.
Paragraph 197 is the trap. In the Commercial Banks Direction it is an assessment paragraph; in the Credit Information Companies Direction it is the evaluation paragraph. Cite the Direction by entity type first, then the paragraph.
| Instrument | Entity or applicability | Clause | What it requires | Cadence |
|---|---|---|---|---|
| RBI Directions, 2026 | Commercial banks | Section BB, ¶202, pp. 47–48 | "The bank shall evaluate the awareness level of employees periodically" | Periodic |
| RBI Directions, 2026 | Commercial banks — new recruits, lower and middle management | ¶203, pp. 47–48 | "Cybersecurity awareness programmes shall be mandatory for all new recruits, and annual training … for lower and middle management" | On joining; annual |
| RBI Directions, 2026 | Commercial banks — Board and Senior Management | ¶204, pp. 47–48 | "annual training to all Board members and Senior Management" | Annual |
| RBI Directions, 2026 | Commercial banks — stakeholders including employees | ¶197 | "the awareness among the stakeholders including employees may also form a part of this assessment" | With the assessment |
| RBI Directions, 2026 | Payments banks | ¶201 | Evaluate the awareness level of employees periodically | Periodic |
| RBI Directions, 2026 | Small finance banks | ¶201 | Evaluate the awareness level of employees periodically | Periodic |
| RBI Directions, 2026 | Credit information companies | ¶197 | "The CIC shall" evaluate the awareness level of employees periodically | Periodic |
| RBI Directions, 2026 | Urban co-operative banks, Level III and Level IV (Chapter V, per ¶4) | Section H, ¶155–157 (¶156), p. 39 | "mandatory cybersecurity awareness programs for new recruits and web-based quiz and training for lower, middle, and upper management every year" | On joining; annual |
| RBI Directions, 2026 | NBFCs — all users | Section C.12, ¶35, p. 19 | A "robust, ongoing information security training and awareness program for all users" | Ongoing |
| RBI Directions, 2026 | NBFCs — all users | Section C.12, ¶36, p. 19 | A "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing"; an "up-to-date repository of the training and awareness status of all users" | Periodic; repository current |
The UCB row carries a qualifier that changes who it reaches. Section H sits in Chapter V, and the applicability table at ¶4 binds Chapter V to Level III and Level IV UCBs. A statement of the UCB obligation that omits the level is wrong for most UCBs. ¶156 is also the awareness paragraph that reaches upper management by name, and it prescribes the method: a web-based quiz.
SEBI CSCRF: the Standard, the guidelines and the compliance table
The CSCRF places awareness under PR.AT, "Awareness and Training", at §3.2, page 63. The objective is that personnel and partners "are provided cybersecurity awareness education, and are trained to perform their cybersecurity related duties".
The cadence appears twice and reads differently. The Standard on page 63 says "periodic". The periodic-compliance table gives row 9 as "Cybersecurity training program (PR.AT.S1) — All REs — Annually". Both are the same circular; say which one a stated cadence comes from.
The clause that names a testing method sits outside PR.AT, in the GV.RM Guidelines, item 1(e), page 87. Its "for e.g." is the regulator's and is load-bearing: the obligation is periodic assessment of the awareness level, and phishing test success rate is the illustration the circular offers.
| Instrument | Entity or applicability | Clause | What it requires | Cadence |
|---|---|---|---|---|
| SEBI CSCRF v1.0 | All REs | §3.2 PR.AT, Standard item 1, p. 63 | "Mandatory programs for building awareness … shall be established. Such programs shall be conducted on a periodic basis…" | "Periodic", per the Standard |
| SEBI CSCRF v1.0 | Privileged users, third parties, senior executives, the Board, physical and information security personnel | §3.2 PR.AT, Standard items 2–5, p. 63 | Extends the mandatory programmes to those groups, including a "dedicated program … for Board members" | Periodic |
| SEBI CSCRF v1.0 | All REs | Periodic-compliance table, row 9 | "Cybersecurity training program (PR.AT.S1) — All REs — Annually" | Annually |
| SEBI CSCRF v1.0 | All REs | PR.AT Guidelines item 2, pp. 103–104 | Employees "are aware of potential risks including social engineering attacks, phishing, etc." | With the programme |
| SEBI CSCRF v1.0 | All REs | PR.AT Guidelines item 3, pp. 103–104 | "security awareness campaigns that stress the avoidance of clicking on links and attachments in email" | With the programme |
| SEBI CSCRF v1.0 | All REs; extended where possible to outsourced staff and third-party service providers | PR.AT Guidelines item 4, pp. 103–104 | "periodic training programs … Wherever possible, this shall be extended to outsourced staff, third-party service providers" | Periodic |
| SEBI CSCRF v1.0 | "All REs except small-size, self-certification REs (Mandatory)" — row heading, p. 86 | GV.RM Guidelines item 1(e), p. 87; standards column GV.RM.S3 | "REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc." | Periodic |
CERT-In CISG-2025-02: how the test itself is conducted
CISG-2025-02 is a different kind of instrument. Its §4 applies it to CERT-In empanelled auditing organisations, so it binds the party performing an assessment. §13.2.7(ii) sets what must exist before the test runs; §15.2.2(iii) governs its conduct and its reporting.
| Instrument | Entity or applicability | Clause | What it requires | Cadence |
|---|---|---|---|---|
| CERT-In CISG-2025-02 | CERT-In empanelled auditing organisations (§4) | §13.2.7(ii), p. 50 | "Specific written permissions must be obtained from the auditee organization before conducting tests that involve … process testing, or social engineering." | Before each test |
| CERT-In CISG-2025-02 | General staff — "untrained or non-security personnel" | §15.2.2(iii), pp. 55–56 | Such testing "must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized"; the purpose is "to evaluate overall awareness and the effectiveness of security processes, not to single out individuals" | Every test — conduct and reporting |
| CERT-In CISG-2025-02 | The target population | §15.2.2(iii), pp. 55–56 | Tests "must only target group of employees explicitly included within the agreed audit scope", and "must not involve external entities such as customers, business partners, vendors, or other third parties, unless specific written consent is obtained from the target organization" | Every test |
The DPDP Act, 2023: the data the programme produces
An awareness programme generates personal data about identifiable employees: who was in the population, who clicked, who reported, and when. Section 4(1) permits processing for a lawful purpose on the data principal's consent or for a certain legitimate use, and section 7(i) sets out the legitimate use available to an employer:
"for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee."
Section 8 applies on either ground. s.8(5) requires reasonable security safeguards over the data; s.8(7)(a) requires erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served".
| Instrument | Entity or applicability | Clause | What it requires | Cadence |
|---|---|---|---|---|
| DPDP Act, 2023 | Any person processing personal data | s.4(1) | Processing for a lawful purpose, on the data principal's consent or for a certain legitimate use | Continuing |
| DPDP Act, 2023 | An employer processing employee personal data | s.7(i) | The legitimate use "for the purposes of employment or those related to safeguarding the employer from loss or liability…" | Continuing |
| DPDP Act, 2023 | Data fiduciary | s.8(5) | Reasonable security safeguards over the personal data held | While the data is held |
| DPDP Act, 2023 | Data fiduciary | s.8(7)(a) | Erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served" | On expiry of the purpose |
Training and evaluation are separate obligations
Where an instrument carries both, it draws them as separate provisions, and that decides what evidence answers which clause. A training register answers a training clause; an evaluation clause asks for a different artefact.
For commercial banks, ¶202 is the obligation to evaluate and ¶203 and ¶204 the obligations to train — consecutive paragraphs of one section. For NBFCs, ¶35 is the programme and ¶36 the measurement, and ¶36 is the most specific text in any of these instruments on what measurement means: a formal mechanism, effectiveness as the thing measured, periodic assessments or testing as the method, and a repository covering all users. In the CSCRF the same split runs across two parts of the circular — PR.AT on page 63 holds the programme, GV.RM Guidelines item 1(e) on page 87 the periodic assessment.
The primary documents
Every clause above was read from the source named here.
- RBI, Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — six entity-specific Directions, all issued 31 July 2026 and in force on issuance.
- SEBI, Cybersecurity and Cyber Resilience Framework (CSCRF) — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024, Version 1.0, 205 pages.
- CERT-In, Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02 — Version 1.0, 25 July 2025, 69 pages.
- Digital Personal Data Protection Act, 2023 — Act 22 of 2023, Gazette of India Extraordinary, Part II Section 1, No. 25, 11 August 2023.
About the author
Yashodhan Sawant, ISO/IEC 27001 Lead Auditor
Lead — ISMS & Certification Readiness
Leads ISO 27001 and SOC 2 readiness at Security Brigade — gap assessment, Statement of Applicability, clause 9.2 internal audit and management review, through to certification audit.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.