- NBFC layers
- The RBI’s scale-based classes of NBFC — base, middle, upper and top — which decide how much of the 2026 cyber Directions applies.
- CIC
- Core investment company — an NBFC that mainly holds investments in group companies; it follows the lightest tier of the cyber Directions.
- LSP
- Lending service provider — a firm that works for a lender on customer acquisition, underwriting support, collections or the lending app.
- DLA
- Digital lending app or platform — the app or website through which a loan is offered, whether run by the lender or a service provider.
- CIMS
- The RBI’s Centralised Information Management System, where lenders report the lending apps they and their service providers use.
- DAKSH
- The RBI’s supervisory portal, where regulated entities report cyber incidents within six hours.
- Payment aggregator
- A firm that collects payments for merchants and settles them, authorised by the RBI.
- PCI DSS
- The card industry’s data security standard, which the payment aggregator rules name as a baseline.
- CSCRF
- SEBI’s Cybersecurity and Cyber Resilience Framework of August 2024, for brokers, depositories, exchanges and other regulated entities.
- VAPT revalidation
- Under the CSCRF, the retest that confirms VAPT findings were fixed — due within five months of the test.
- KYC
- Know your customer — the identity and address documents collected to open an account or loan, and the most valuable data a lender holds.