Tool 1

Cyber incident reporting deadlines in India: who you tell, and by when

Work out every regulatory notification an Indian entity owes after a cyber incident, as wall-clock IST deadlines — CERT-In, the seven RBI Directions, SEBI CSCRF and LODR, IRDAI and NCIIPC, each with the clause it comes from.

In short
An Indian entity that notices a cyber incident owes CERT-In a report within six hours. RBI regulated entities file on DAKSH within six hours of detection; SEBI entities file to SEBI and CERT-In within six hours, then the portal within twenty-four. IRDAI is six hours, with no second step. A listed entity owes the exchanges twelve hours. DPDP does not commence until 13 May 2027.

Work out your deadlines

Pick your entity class and tick what applies. The tool resolves every notification you owe and what starts each clock. Adding the moment you noticed turns the windows into wall-clock IST times.

Your entity
When you noticed
4filings owed — windows from each trigger
InstrumentWhat you fileWindowGoes to
CERT-In Directions, 2022No. 20(3)/2022-CERT-InReport the incident to CERT-Inwithin 6 hours of noticing such incidents or being brought to notice about such incidents6 hours from noticing, or being brought to noticefrom: noticing, or being brought to noticeCERT-Inincident@cert-in.org.in · 1800-11-4949
RBI Cyber Directions, 2026 — Commercial bankRBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182Report the cyber incident on the DAKSH platformshall report cyber incidents within six hours of detection on DAKSH platformOne of seven parallel Directions issued on 31 July 2026, one per entity class. Quote this instrument and its own paragraph number — the numbering differs between them.6 hours from detectionfrom: detectionReserve Bank of Indiadaksh.rbi.org.in
SEBI LODR, Reg. 30(6)SEBI LODR Regulations, 2015, as amended 14 July 2026Market disclosure of the event, if the KMP determines it is materialtwelve hours from the occurrence of the event or informationTwelve hours, not twenty-four. A ransomware event, data breach or IT outage emanates from within the listed entity, which is limb (ii). Limb (iii)’s twenty-four hours is for events arising outside it. Materiality is the authorised KMP’s determination, not a technical one.12 hours from occurrence of a material eventfrom: occurrence of a material eventStock exchanges
SEBI LODR, Reg. 27(2)(ba)SEBI LODR Regulations, 2015, as amended 14 July 2026Disclose details of the incident in the quarterly corporate governance reportDetails of cyber security incidents or breaches or loss of data or documents shall be disclosed along with the reportNo materiality test. An incident correctly judged immaterial for Reg. 30 is still reportable here — so this belongs on the post-incident checklist, not the first-24-hours one.Next quarterly corporate governance reportStock exchanges
DPDP Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) · Rule 7 · G.S.R. 843(E), section 8Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force. Rule 7 falls in the eighteen-month tranche under Rule 1(4), and section 8 commences on the same date — 13 May 2027. There is no DPDP breach clock running on an incident today. Plan and rehearse against it; do not file against it.Not in forceData Principals and the Data Protection Board of India

Indicative, and not legal advice. Whether an instrument applies to a particular entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Verify every citation against the published text before a notification is filed.

Take this away as an escalation pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Every clock, and what starts it

These are not alternatives. A listed private-sector bank holding customer personal data can owe CERT-In, the Reserve Bank and the stock exchanges on the same incident, on different clocks, in different formats, to different recipients.

Two of them do not run from noticing at all. The RBI Directions run from detection, and so do the IFSCA Guidelines that govern GIFT City entities — and IFSCA is the only one that does not stop at the first filing, adding an interim report at three days, mitigation measures at seven and a root cause analysis at thirty.

Entity classReferenceReporting paragraph
Commercial bankRBI/DoS/2026-27/410Ch. V, §Z.1, para 182
Small Finance BankRBI/DoS/2026-27/419para 181
Payments BankRBI/DoS/2026-27/428para 181
Urban Co-operative BankRBI/DoS/2026-27/437para 88
All India Financial InstitutionRBI/DoS/2026-27/456para 177
Non-Banking Financial CompanyRBI/DoS/2026-27/461Ch. IV para 28 / Ch. V para 141
Credit Information CompanyRBI/DoS/2026-27/470para 177
The seven RBI Directions of 31 July 2026. Same six-hour clock in every one; the paragraph number differs.

The Commercial Banks Directions exclude Small Finance Banks, Payments Banks and Local Area Banks because each of the first two has its own instrument. That exclusion means file elsewhere, not no obligation.

5 cases are worked through in full, if one of them is yours: NBFC after ransomware attack, listed commercial bank after data breach, stock broker after client data leak, insurer after DDoS attack, GIFT City entity after cyber incident.

One incident, many clocks

The difficulty is rarely a single instrument. It is that several run at once, from different trigger events. Work it in this order.

  1. Fix the trigger time and write it down. The moment of noticing, in IST, with the source — alert, vendor call, researcher email, regulator enquiry. Every clock is measured from something, and this is the first thing every regulator asks.
  2. Run the baseline. CERT-In binds nearly every Indian entity.
  3. Add the sectoral filing. For an RBI regulated entity that means identifying which of the seven Directions binds it, and for an NBFC also which chapter.
  4. Add the market-disclosure track if the entity is listed. Materiality is the authorised KMP's determination, not a technical one.
  5. Add NCIIPC if a declared protected system is affected. Protected -system status is a notified fact, never an inference from sector or size.
  6. Check the third-party direction. If the incident originated at a service provider, the contract's notification terms and the applicable outsourcing instrument are both live. If you are the service provider, your customers' clocks are now running on the notice you give them.

The obligations that bite during an incident

Three standing requirements decide how well the first six hours go, and all three are cheaper to satisfy before an incident than during one.

  • Logs, 180 rolling days, within Indian jurisdiction. All ICT system logs enabled, maintained securely for a rolling 180 days and held within Indian jurisdiction. They must be provided to CERT-In with an incident report or when directed.
  • Clock synchronisation to NIC or NPL. All ICT system clocks synchronised to the NTP servers of NIC or NPL, or to servers traceable to them. An incident timeline assembled from unsynchronised clocks is very hard to defend.
  • A registered CERT-In point of contact. A designated PoC registered with CERT-In in the Annexure II format and kept current. CERT-In directs all communications to the PoC.

For the wider picture of which instruments bind you in the first place, use the regulation finder, or read the pillar guide to cyber security regulations in India.

This tool is indicative and is not legal advice. It does not determine that any instrument applies to your entity — that is a question for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

How long do you have to report a cyber incident in India?
Six hours to CERT-In, from noticing the incident or being brought to notice of it. Most sectoral clocks are also six hours: RBI regulated entities report on DAKSH within six hours of detection, SEBI regulated entities notify SEBI and CERT-In within six hours, and insurers report to CERT-In within six hours copied to IRDAI. A listed entity separately owes its stock exchanges a disclosure within twelve hours where the incident is material.
Does the six-hour clock start when an incident is confirmed?
No. The CERT-In Directions run from noticing the incident or being brought to notice of it, which means a vendor, a researcher or a regulator telling you starts the clock exactly as your own alerting does. The RBI Directions run from detection. In neither case does an incomplete investigation pause the clock — draft on what is known, mark the unknowns as under investigation, and file the update.
Is the SEBI LODR deadline for a cyber incident 12 hours or 24 hours?
Twelve hours. Regulation 30(6) sets twelve hours for an event emanating from within the listed entity and twenty-four for an event arising outside it. A ransomware event, data breach or IT outage originates within the entity, so it falls in the twelve-hour limb. The twenty-four hour figure is the one most commonly repeated, and quoting it puts the disclosure twelve hours late.
Does the DPDP Act require breach notification within 72 hours today?
No. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act both commence eighteen months after the Rules were notified on 13 November 2025, which is 13 May 2027. There is no DPDP breach-intimation clock running on an incident today. The regime is worth planning and rehearsing against, but a notification filed against it now is filed against an obligation that has not commenced.
How long does a GIFT City entity have to report a cyber incident?
Six hours from detection, to the Authority at cyber-incidents@ifsca.gov.in with a copy to the CISO, IFSCA, under the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025. The obligation then continues: an interim report at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. An IFSC licence displaces the mainland regulator, so a GIFT City banking unit does not file under the RBI Directions — but CERT-In still binds it.
Which RBI Direction applies to an NBFC after a cyber incident?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies instrument — not the Commercial Banks Directions at 410. Its chapters are graded: a Base Layer NBFC below ₹500 crore sits under Chapter III, which carries no six-hour DAKSH clause at all, while Chapter IV covers Base Layer at ₹500 crore and above and Chapter V covers the Middle, Upper and Top Layers. CERT-In’s six hours binds every one of them.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools