We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Open resource · no email gate · CC BY 4.0 · v1.0.0

One incident, every clock: the India reporting map

A single breach in an Indian regulated entity can start several reporting clocks at once. This map puts them side by side — every quantified deadline traces to the Compliance Registry.

Raw Markdown →All open resources

Everyone in scope of the CERT-In Directions

6 hours from noticing

Reports to: CERT-In

Specified cyber incidents must be reported within six hours of being noticed. Applies to service providers, intermediaries, data centres, body corporates and government organisations — no small-business exemption.

Source entry: certin-6h

Data fiduciaries (from DPDP Phase III, May 2027)

Without delay, then 72-hour detailed report

Reports to: Data Protection Board + affected data principals

Rule 7: intimate the Board without delay on becoming aware; detailed report within 72 hours (extendable by the Board); notify affected data principals in plain language. Every personal data breach triggers the duty.

Source entry: dpdp-breach-notification

Scheduled commercial banks

2–6 hours from detection

Reports to: RBI

The Cyber Security Framework in Banks (2 June 2016) requires incident reporting to RBI within 2–6 hours of detection, with updates as facts develop.

Source entry: rbi-cyber-framework-2016

SEBI regulated entities

Per CSCRF reporting requirements

Reports to: Exchange / depository / SEBI per CSCRF category

The CSCRF (issued 20 Aug 2024) defines incident reporting through the entity's reporting authority; the cadence depends on your RE category — confirm against the framework text during scoping.

Framework entry: sebi-cscrf-issued

Insurers and intermediaries

Per the 2023 guidelines

Reports to: IRDAI

The Information and Cyber Security Guidelines 2023 (24 Apr 2023) carry incident-reporting duties for regulated insurance entities; confirm the applicable timeline in the guidelines during scoping.

Framework entry: irdai-infosec-2023

The four traps

1. The clocks start at different moments: CERT-In runs from NOTICING, DPDP from BECOMING AWARE, RBI from DETECTION. Your incident log must timestamp each.

2. One runbook, not three: the most common failure is each duty living with a different team, and one filing being missed while another is being drafted.

3. Out-of-hours authority: six hours is lost in escalation, not detection — name who may classify an incident as reportable at 2am.

4. Evidence the filing: keep the submitted report, the timestamp and the acknowledgement — regulators ask for the trail, not the intention.

Can your runbook actually hit these clocks?

We test exactly this in a national cyber compliance review — including whether a reportable call can be made out of hours, and whether one incident feeds every filing from a single runbook.

Incident-readiness review →

v1.0.0 · updated 2026-08-01 · CC BY 4.0 — reuse with attribution to CyberSigma.