Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
🏦
BetaRBI IT Master Directions 2023rbi_cyber_readiness_2024.1

RBI Cyber Resilience Readiness

CSITE examination preparation for banks, NBFCs, and payment system operators. Auto-derived supervision tier. Critical finding detection. Board Pack and IS Audit pre-brief.

22
Critical controls
9
Examination domains
4
Supervision tiers
12
Entity types
Free
Full assessment
₹0
To start
Before you start — what to have ready for RBI Cyber Resilience

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What RBI Cyber Resilience is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Board-approved IT / cyber security policy
  • IT Strategy Committee and IT Steering Committee minutes
  • IAM policy with joiner/mover/leaver and access review records
  • Incident response and reporting procedure (CERT-In / RBI timelines)
  • Business continuity and disaster recovery plan
  • Vendor / outsourcing risk management agreements

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Board minutes and IAM records contain named individuals and internal system detail. Mask personal contact details and any credentials; the policies, minutes and procedures are what is assessed.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
22
Critical controls
18 always-on + 4 conditional (SWIFT, payments, outsourced IT)
4
Supervision tiers
T1 → T4
12
Entity types
Banks to PPIs
₹0
Free assessment
No account needed

RBI supervision tiers

RBI assigns each regulated entity a supervision tier based on entity type and systemic importance. Higher tiers face more frequent CSITE examinations and higher expected maturity levels.

Tier T1
  • Large Scheduled Commercial Banks
Tier T2
  • Small Finance Banks
  • Payment Banks
  • NBFC-UL
  • UCB Tier 1
  • Large PSOs
Tier T3
  • Regional Rural Banks
  • NBFC-ML
  • UCB Tier 2
  • Payment Aggregators
  • PPI Issuers
  • Small PSOs
Tier T4
  • NBFC Base Layer (minimal obligations)

Not sure which tier you are? Enter your entity type in Step 1 — tier is derived automatically.

9 examination domains

🏛️GOV12× weight
IT Governance

Board-level IT strategy committee, CISO designation, cyber policy, IS policy.

⚖️RM11× weight
IT Risk Management

Risk assessment framework, live risk register, technology change risk.

🔒IS13× weight
Infrastructure Security

Network segmentation, IAM, privileged access, patch management, encryption.

📡CD13× weight
Cyber Defence

24×7 SOC/CSISC, VAPT, SIEM, threat intelligence, DLP.

🚨IR12× weight
Incident Response

Incident response plan, RBI 6-hour reporting, CERT-In reporting, post-incident review.

♻️BC12× weight
Business Continuity

BCP/DR plans, DR infrastructure, DR drills, RTO/RPO targets.

🤝VR10× weight
Vendor & Outsourcing Risk

Outsourcing policy, vendor due diligence, critical IT vendor management.

💳DP11× weight
Digital Payments Security

Payment security framework, fraud monitoring, tokenisation, API security.

📋RC14× weight
Regulatory Compliance

IS Audit (CERT-In empanelled), RBI advisory tracking, examination pre-brief.

How it works

1
Entity profile

Select your RBI entity type (bank, NBFC, payment aggregator, etc.) and operational flags — payment activity, SWIFT, cloud, AI/ML, outsourced IT. Tier is auto-derived.

Start profile →
2
CSITE assessment

Rate 22 critical controls (18 always-on + 4 conditional on SWIFT, payment activity, and outsourced IT) across 9 domains on a 0–4 maturity scale. Questions mirror what CSITE examiners verify. Evidence cap applied automatically.

Go to assessment →
3
Examination readiness

Get an examination readiness level (Comprehensively Documented → Critical), critical findings list, domain heatmap, and priority gap register sorted by examination weight.

View results →
4
Evidence library

Upload documents once — each is checked against every applicable control. Your answers are a claim; uploaded evidence is what produces a proof-backed position.

Open library →
What is a CSITE examination?

CSITE (Cyber Security and Information Technology Examination) is RBI's dedicated IT supervision team. CSITE examinations are off-site or on-site reviews of an entity's IT governance, cybersecurity controls, and technology risk management. The assessment controls in this tool mirror CSITE's published examination focus areas. Entities with prior CSITE findings or directions under Section 35A face closer scrutiny.