India: RBI, SEBI, CERT-In And The 2029 Quantum Roadmap
India's binding rules already demand strong cryptography and name post-quantum risk, while the dated migration milestones sit in a national roadmap. What applies, and what is still under study, as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
India’s approach to post-quantum cryptography has three layers that are easy to blur together. Binding financial rules already require strong, current cryptography and, in one case, name post-quantum risk outright. A national roadmap from the Department of Science and Technology sets specific migration dates up to 2033. And the Reserve Bank of India (RBI) has a committee studying what banks should do, whose report has not yet appeared.
Mixing these layers up leads to claims such as “India requires post-quantum migration by 2029”, which is not what the documents say. This article separates them as of October 2026. It is general information, not legal advice. For how India compares with other regions, see the regional overview.
Binding Rules That Apply Now
RBI directions on IT and cyber security (Binding). The requirement first appeared in the RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices, issued on 7 November 2023 and effective from 1 April 2024. Its paragraph 16 asks for strong encryption settings, covering key lengths, algorithms, cipher suites and protocols, drawn from published international standards that have not been withdrawn or proven weak.1 On 31 July 2026 the RBI replaced the earlier IT governance and cyber security directions for commercial banks with a new set of 2026 directions. For commercial banks the same expectation now sits in paragraph 140, in substantially the same terms.2 Other types of regulated entity, such as non-banking financial companies, have their own 2026 directions, which were not reviewed for this article.
The condition about deprecated standards is the part that matters most. Once standards bodies deprecate quantum-vulnerable algorithms, these paragraphs turn that deprecation into a compliance question for Indian banks.
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) (Binding). The Securities and Exchange Board of India issued the CSCRF on 20 August 2024 for its regulated entities. It is one of the few binding instruments found in this research that names post-quantum risk: risk assessments must include it, and the framework’s future-proofing section mentions harvest now, decrypt later.3 Its data security standard requires encryption of data in motion, at rest and, for cloud, in use, and gives RSA and AES as example algorithms. RSA is one of the algorithms a quantum computer would break, which shows how far there is to go between naming the risk and changing the toolkit. The framework does go further in Box Item 7, on cybersecurity and quantum computing. Its indicative measures include keeping an inventory of cryptographic assets, with critical assets prioritised for post-quantum migration, alongside post-quantum strategies, proof-of-concept trials and crypto agility.4
CERT-In Directions of 28 April 2022 (Binding). Issued under section 70B(6) of the IT Act, these require covered organisations to report specified types of cyber incident within six hours of noticing them or being told about them, and to keep logs in India for 180 days.5 They are not about cryptography, but a cryptographic failure that leads to an incident of a reportable type would fall under them.
The National Roadmap
In May 2026 the Department of Science and Technology published a roadmap for a quantum-safe ecosystem in India under the National Quantum Mission (Guidance, as a national strategy).6 It sets two tracks. Organisations running critical information infrastructure (CII) are treated as urgent adopters with shorter timelines than other enterprises. The roadmap names banking, financial services and insurance among the critical sectors on this accelerated track, along with government, strategic and defence systems, power, telecoms and transport.6
Each track has three milestones: build foundations (governance, a cryptographic inventory and a quantum risk assessment), migrate high-priority systems, and reach full adoption with post-quantum cryptography as the default. For CII the milestones fall by 2027, by 2028 and by 31 December 2029. For other enterprises they fall by 2028, by 2030 and by 31 December 2033.6
The roadmap also turns to procurement. It recommends asking vendors for a cryptographic bill of materials (CBOM), a machine-readable list of the cryptography inside a product, from financial year 2026-27, and making CBOM submission mandatory through procurement policy from financial year 2027-28.6 That “mandatory” is the roadmap’s recommendation to buyers. It is not a legal duty on vendors.
Under Study: RBI Q-SAFE
On 25 May 2026 the RBI set up an expert committee on a Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE), with Professor Anil Prabhakar of IIT Madras as convener (Announcement).7 Its terms of reference include assessing the financial sector’s cryptographic inventory through a CBOM, comparing regulatory approaches in other countries, judging industry readiness, and recommending a roadmap and framework for a quantum-secure Indian financial system. The report is due six months after the committee’s first meeting. As of October 2026, it has not been published.
CERT-In has also issued technical guidelines on bills of materials. The primary document could not be retrieved for this article, so whether and how it covers CBOMs is not described here.
| Layer | Instruments | Status | What it asks for |
|---|---|---|---|
| Binding now | RBI IT directions (2023 Master Direction para 16; 2026 commercial bank directions para 140); SEBI CSCRF; CERT-In Directions 2022 | Binding | Strong, non-deprecated cryptography (RBI); post-quantum risk in risk assessment, with a cryptographic asset inventory among indicative measures (SEBI); six-hour reporting of specified incidents (CERT-In) |
| National roadmap | DST roadmap under the National Quantum Mission, May 2026 | Guidance (strategy) | Inventory and risk assessment, then migration: CII by end 2029, other enterprises by end 2033; CBOMs from vendors |
| Under study | RBI Q-SAFE committee, May 2026 | Announcement | Report on a sector roadmap, including a CBOM-based view of the sector, due six months after first meeting |
Deadlines To Watch
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Build foundations: governance, cryptographic inventory and quantum risk assessment.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Migrate high-priority systems to post-quantum cryptography.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Build foundations: governance, cryptographic inventory and quantum risk assessment.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Full post-quantum adoption, with post-quantum cryptography as the default.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Migrate high-priority systems to post-quantum cryptography.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Full post-quantum adoption, with post-quantum cryptography as the default.
A Note On AI
India has no dedicated AI statute as of October 2026. The Ministry of Electronics and Information Technology published India AI Governance Guidelines in November 2025 (Guidance),8 and an RBI committee report on AI in finance (FREE-AI) appeared in August 2025 as a report rather than a direction.9 The one binding AI-related change is an amendment to the IT intermediary rules, notified on 10 February 2026 and in force from 20 February 2026, which brings realistic synthetically generated audio and visual content, such as deepfakes, under labelling and due-diligence duties for the intermediaries that host or enable it.10 See AI regulation at a glance and AI Governance And Regulation.
Where To Start
For an Indian bank, the binding hook is the RBI requirement to avoid deprecated cryptography; for a SEBI-regulated entity, it is the duty to assess post-quantum risk, backed by the CSCRF’s indicative measure of a cryptographic asset inventory. Both need the same evidence: a list of where cryptography is used and which algorithms each system relies on. The DST roadmap and the Q-SAFE terms of reference both point to the same artefact. Cryptography Compliance covers how to build it.
Footnotes
-
Reserve Bank of India, “Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices”, 7 November 2023, paragraph 16. rbi.org.in ↩
-
Reserve Bank of India, “Reserve Bank of India (Commercial Banks: Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026”, RBI/DoS/2026-27/410, 31 July 2026, paragraph 140. rbi.org.in ↩
-
Securities and Exchange Board of India, “Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities”, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024. sebi.gov.in ↩
-
Securities and Exchange Board of India, CSCRF annexure, Box Item 7 “Cybersecurity and Quantum Computing”, 20 August 2024. sebi.gov.in ↩
-
CERT-In, “Directions under sub-section (6) of section 70B of the Information Technology Act, 2000”, No. 20(3)/2022-CERT-In, 28 April 2022. cert-in.org.in ↩
-
Department of Science and Technology, Government of India, “Quantum-Safe Ecosystem in India” roadmap, May 2026. dst.gov.in ↩ ↩2 ↩3 ↩4
-
Reserve Bank of India, press release on the Expert Committee on Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE), 25 May 2026. rbi.org.in ↩
-
Press Information Bureau, release on MeitY’s India AI Governance Guidelines, 5 November 2025. pib.gov.in ↩
-
Reserve Bank of India, press release on the FREE-AI committee report, 13 August 2025. rbi.org.in ↩
-
Ministry of Electronics and Information Technology, Notification G.S.R. 120(E), “Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026”, 10 February 2026. meity.gov.in ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.