Incident reporting: nine clocks, and none of them start together
Six hours, 24 hours, four business days — the durations are the memorable half. What each clock runs from is the half that decides whether you filed late.
The number is the half everyone quotes
Every comparison of incident reporting deadlines is a table of durations. Six hours. Seventy-two hours. Four business days. Read that way, the conclusion writes itself: India is the strict one, everyone else is relaxed.
The durations are accurate and the conclusion is wrong, because a deadline is a duration and a starting gun, and the starting guns are not the same event. Two of these clocks start before you have decided anything. Two start only once you have made a formal determination — which means a slow determination moves the deadline, and a determination you were slow to make is itself the violation.
What each one actually says
| Instrument | First deadline | Runs from |
|---|---|---|
| CERT-In Directions (India) | 6 hours | noticing, or being brought to notice |
| SEBI CSCRF (India) | 6 hours | noticing or detecting, or being brought to notice |
| SEBI LODR (India) | 12 hours | occurrence of the event |
| RBI Cyber Directions, 2026 (India) | 6 hours | detection |
| IRDAI Guidelines, 2026 (India) | 6 hours | noticing, or being brought to notice |
| NIS2, Article 23 (EU) | 24 hours | becoming aware |
| DORA (EU) | 4 hours | classification as major |
| Cyber Resilience Act, Article 14 (EU) | 24 hours | becoming aware |
| SEC Form 8-K, Item 1.05 (US) | 4 business days | determining materiality |
Two entries need their fine print, because both are routinely printed wrong.
DORA is not a four-hour rule, and not a 24-hour rule either. Delegated Regulation (EU) 2025/301 sets the initial notification “as early as possible, but in any case, within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware.” Both limbs bind. Classify at hour 22 and you have two hours, not four. Classify only at hour 30 — which the Regulation contemplates — and the initial notification is due within four hours of that classification.
The later stages then chain off each other rather than off the incident: the intermediate report is due within 72 hours of the initial notification, “even where the status or the handling of the incident have not changed”, and the final report within one month of the intermediate report, not of the incident.
The SEC’s clock does not start when you are breached. Item 1.05 of Form 8-K is due within four business days of determining that an incident was material. The adopting release is explicit that the determination must be made without unreasonable delay and may not be “unreasonably delayed in an effort to avoid timely disclosure.” So the four days are generous and the discretion in front of them is not: the enforceable question is when you should have known it was material, not when you concluded it.
There is a national-security exit, and it is narrow. Where the US Attorney General determines that immediate disclosure poses a substantial risk to national security or public safety, disclosure may be delayed up to 30 days, extended by a further 30, and in extraordinary circumstances by a final 60 — a maximum of 120 days, each step requiring the Attorney General’s determination.
Six hours sets the pace for everything else
For an Indian regulated entity, the practical effect of the table is that the Indian clocks govern. CERT-In’s six hours is the tightest, and it runs from the softest trigger in the set — “or being brought to notice” means a researcher’s email or a customer’s phone call starts it exactly as your own SIEM does.
That has a consequence worth being deliberate about. If you have six hours from someone else telling you, then the assessment work the EU and US clocks depend on — is this major, is this material — has to begin inside a window where you are already filing in India. The Indian filing is not the end of the first shift; it is the thing that happens while the rest of the assessment is still running.
The corollary is more useful than it sounds: an organisation built to file in India in six hours is structurally well placed for every other clock in the table. The reverse is not true.
If you are listed in the US, your American clock is Indian
This is the part most often missed by Indian issuers with an ADR listing.
Foreign private issuers do not file Item 1.05 of Form 8-K. They furnish on Form 6-K, and Form 6-K requires an issuer to furnish copies of information it makes or is required to make public under the law of its jurisdiction of incorporation, files under the rules of any stock exchange, or otherwise distributes to security holders.
The US obligation is therefore derivative. It is not an independent four-business-day assessment running in parallel — it is triggered by what you disclose in India. Your SEBI LODR disclosure at twelve hours, or your CERT-In filing, is what pulls the 6-K. An Indian issuer waiting to run a separate US materiality analysis has misread the mechanism; an Indian issuer that discloses at home has already started the American clock.
Form 20-F carries the annual governance disclosure separately — the board’s oversight of cybersecurity risk, and management’s role in assessing and managing it.
The only clock that pauses at a weekend
DORA has a provision nothing else in the table has. Where a deadline falls on a weekend day or a bank holiday in the entity’s Member State, the report may be submitted by noon of the next working day.
Then it takes it back for the entities most likely to need it. That relief does not apply to the initial notification or the intermediate report by credit institutions, central counterparties, operators of trading venues, or any financial entity identified as essential or important under NIS2. Competent authorities may disapply it for other significant or systemic entities too.
So the weekend extension is real, and a bank cannot use it. Every Indian clock runs continuously; none of them notices a Sunday.
What this changes in a runbook
- Write the trigger next to every deadline. A runbook listing “CERT-In: 6h, NIS2: 24h, SEC: 4 business days” is a list of durations from unstated moments, and it will be read as a queue when it is not one.
- Log the moment of notice, not just detection. For three Indian instruments and the CRA, an inbound report starts the clock. If your ticketing records when the SOC saw it rather than when the email arrived, your evidence of timeliness is measuring the wrong instant.
- Treat classification and materiality as clock events. DORA and the SEC both hang a deadline on a decision you control, which means the decision needs a timestamp, an owner and a reason — and it needs to happen promptly, because delaying it is the thing that draws scrutiny.
- Do not build DPDP in yet. Note the 13 May 2027 date and leave the clock out until it commences.
The Indian instruments are worked through entity by entity in the CERT-In six-hour page, and the EU product-side duty in the Cyber Resilience Act page.
EU deadlines read from Directive (EU) 2022/2555, Article 23, and Commission Delegated Regulation (EU) 2025/301, Article 5, on EUR-Lex. US deadlines from the SEC’s adopting release 33-11216. Indian clocks are held in this site’s own register, each with its own verification date.
Every instrument cited here was verified against the issuing regulator's own notification on .Questions this page answers
- How fast must a cyber incident be reported in India?
- Six hours, under the CERT-In Directions issued under section 70B(6) of the Information Technology Act, 2000, running from noticing the incident or being brought to notice of it. SEBI’s CSCRF, the RBI’s 2026 Cyber Directions and IRDAI’s 2026 Guidelines each set six hours for the entities they bind; SEBI’s LODR sets twelve hours for a material event originating within the entity.
- What are the NIS2 and DORA incident reporting deadlines?
- NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report no later than one month after that notification. DORA requires an initial notification within four hours of classifying an incident as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within one month of the intermediate report.
- When does the SEC’s four-business-day cybersecurity clock start?
- On determining that an incident is material, not on discovering it. The SEC’s adopting release requires the materiality determination to be made without unreasonable delay, and states that it may not be unreasonably delayed in an effort to avoid timely disclosure.
- Does an Indian company listed in the US file a Form 8-K for a cyber incident?
- No. A foreign private issuer furnishes the information on Form 6-K instead, and that obligation is triggered by what the issuer makes public under the law of its jurisdiction of incorporation, files under stock exchange rules, or distributes to security holders. The US filing is derivative of the Indian disclosure rather than an independent assessment.