If your NBFC’s logging setup was built against the old IT Framework circulars, it was built against rules that no longer exist.
On 31 July 2026 the Reserve Bank issued the NBFC Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026. They came into force immediately, repealed the earlier IT Framework and IT Governance directions, and scale obligations by regulatory layer rather than applying one rulebook to all.
This blog covers what the Directions require from a logging solution for NBFCs in India, how obligations differ by layer, and what your IS auditor will check.
The old directions are gone; so, what changed
The Directions repeal the existing IT Framework and IT Governance instructions for NBFCs. Prior liabilities survive, but the rulebook is new. If your logging policy cites a repealed circular, rewrite it. Obligations now scale by layer. Three chapters apply depending on where your NBFC sits.
- Chapter III covers Base Layer NBFCs below ₹500 crore and Core Investment Companies.
- Chapter IV covers Base Layer NBFCs at ₹500 crore and above.
- Chapter V covers Middle, Upper and Top Layer NBFCs, excluding CICs.
The gap between Chapter III and Chapter V is wide, though, and misreading which binds you is expensive either way.
What the Directions require for logging
Logging does not headline a chapter. The requirements sit inside audit trails, access controls and incident response.
1. Audit trails must prove things instead of just recording
For Chapter IV NBFCs, audit trails must exist for IT assets, satisfying business, regulatory and legal requirements. They must facilitate audit, work as forensic evidence and assist dispute resolution. Any unauthorised user activity must be recorded.
Chapter V goes further. Every application or system that can access or affect critical or sensitive information needs audit logging detailed enough to support audits, stand up as forensic evidence and support non-repudiation.
Non-repudiation means the log must prove who did something in a way the person cannot credibly deny. That raises the bar on identity fields, timestamp integrity and tamper protection above ordinary operational logging.
2. Someone has to monitor them
Chapter V requires a system for regularly monitoring audit trails and system logs, to detect, understand or recover from unauthorised activity or attack. This separates a log archive from a logging solution. The CISO’s office is tasked with managing and monitoring the Security Operations Centre.
3. Privileged users get closer supervision
Personnel with elevated system access must have all activities logged and periodically reviewed. Not sampled. All of them. If your privileged access management tool and log platform are not integrated, this gap surfaces first.
4. Outsourced systems are still your evidence problem
Contracts must ensure audit trails and logs for administrative activities are retained by the service provider and accessible to the NBFC on request.
Many NBFCs run core lending, collections or KYC on vendor platforms. Without contractual log access you cannot produce evidence for systems you depend on, and the regulator will not treat the vendor as the responsible party.
Why the six-hour clock is a logging problem
NBFCs must report cyber incidents on the DAKSH platform within six hours of detection, and notify CERT-In. Housing finance companies report to NHB instead.
The clock starts at detection. That word decides whether six hours is comfortable or impossible.
If detection depends on someone reviewing a dashboard next morning, you have created an indefensible gap between when the event happened and when you claim you found it. Investigators will reconstruct the real timeline from your logs anyway.
Six hours also covers more than filing a form. You need context on what happened and what was affected. Real-time ingestion, working correlation rules and alerting that reaches a human make it survivable.
What your logging solution needs by layer
1. Chapter III (Base Layer below ₹500 crore and CICs)
Basic IT systems, logical access controls, defined user roles, maker-checker controls and tested backups. No elaborate monitoring mandate. Build for access and transaction traceability, and expect to scale – the Directions require it.
2. Chapter IV (Base Layer at ₹500 crore and above)
Audit trails across IT assets, recorded unauthorised user activity and contractual log access from service providers. Centralised collection becomes practical, not optional.
3. Chapter V (Middle Layer and above)
The full build. Audit logging on every system touching critical or sensitive information, trails supporting non-repudiation, regular monitoring, complete privileged user logging, audit trails on data migration and straight-through processing, plus a SOC under CISO oversight. A SIEM is the only realistic way to deliver this.
What IS audit will check
IS Audit is now a defined obligation with board oversight, conducted at least annually. For critical systems, the Directions encourage continuous auditing. Your auditor will look for:
- Complete coverage means every system touching critical or sensitive data, mapped to an active log source
- Field-level detail sufficient for forensic use and non-repudiation
- Documented review evidence with named owners and cadence
- Privileged activity records for all elevated-access personnel
- Vendor log access clauses, and proof you have used them
- Incident timelines showing detection-to-DAKSH reporting inside six hours
The most common failure is not missing logs. It is missing proof that anyone looked at them.
Conclusion
The 2026 Directions replaced the rulebook, tied obligations to your layer and made audit trails the evidence base for governance, incident response and IS audit.
Confirm which chapter binds you and rescope your logging policy against it. Close the privileged user and vendor log access gaps, because auditors find those fastest. Then test whether your detection supports a six-hour report.
At CyberNX, we design NBFC logging architectures that hold up under RBI scrutiny, combining RBI compliance advisory with full stack observability and managed detection and response. Talk to our team about where your setup sits against the new Directions.
Logging solution for NBFCs FAQs
What is the log retention period for NBFCs under the 2026 Directions?
The Directions do not prescribe a duration. They require audit trails to satisfy business, regulatory and legal requirements, pushing the decision back to you. Most NBFCs align to the IT Act 2000 minimum of two years. Document the period and get it approved – an undefined policy is itself a finding.
Do the 2026 Directions require every NBFC to run a SOC?
No. SOC oversight sits with the CISO’s office under Chapter V, covering Middle, Upper and Top Layer NBFCs. Base Layer entities have lighter obligations. But the six-hour DAKSH deadline applies broadly and is hard to meet without continuous monitoring capability.
Do these Directions apply to housing finance companies?
Yes, but the reporting route differs. Housing finance companies report cyber incidents to the National Housing Bank rather than RBI. The underlying logging obligations still apply by layer.



