Cyber incident reporting deadlines in India: who you tell, and by when
Work out every regulatory notification an Indian entity owes after a cyber incident, as wall-clock IST deadlines — CERT-In, the seven RBI Directions, SEBI CSCRF and LODR, IRDAI and NCIIPC, each with the clause it comes from.
Work out your deadlines
Pick your entity class and tick what applies. The tool resolves every notification you owe and what starts each clock. Adding the moment you noticed turns the windows into wall-clock IST times.
| Instrument | What you file | Window | Goes to |
|---|---|---|---|
| CERT-In Directions, 2022No. 20(3)/2022-CERT-In | Report the incident to CERT-Inwithin 6 hours of noticing such incidents or being brought to notice about such incidents | 6 hours from noticing, or being brought to noticefrom: noticing, or being brought to notice | CERT-Inincident@cert-in.org.in · 1800-11-4949 |
| RBI Cyber Directions, 2026 — Commercial bankRBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182 | Report the cyber incident on the DAKSH platformshall report cyber incidents within six hours of detection on DAKSH platformOne of seven parallel Directions issued on 31 July 2026, one per entity class. Quote this instrument and its own paragraph number — the numbering differs between them. | 6 hours from detectionfrom: detection | Reserve Bank of Indiadaksh.rbi.org.in |
| SEBI LODR, Reg. 30(6)SEBI LODR Regulations, 2015, as amended 14 July 2026 | Market disclosure of the event, if the KMP determines it is materialtwelve hours from the occurrence of the event or informationTwelve hours, not twenty-four. A ransomware event, data breach or IT outage emanates from within the listed entity, which is limb (ii). Limb (iii)’s twenty-four hours is for events arising outside it. Materiality is the authorised KMP’s determination, not a technical one. | 12 hours from occurrence of a material eventfrom: occurrence of a material event | Stock exchanges |
| SEBI LODR, Reg. 27(2)(ba)SEBI LODR Regulations, 2015, as amended 14 July 2026 | Disclose details of the incident in the quarterly corporate governance reportDetails of cyber security incidents or breaches or loss of data or documents shall be disclosed along with the reportNo materiality test. An incident correctly judged immaterial for Reg. 30 is still reportable here — so this belongs on the post-incident checklist, not the first-24-hours one. | Next quarterly corporate governance report | Stock exchanges |
| DPDP Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) · Rule 7 · G.S.R. 843(E), section 8 | Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force. Rule 7 falls in the eighteen-month tranche under Rule 1(4), and section 8 commences on the same date — 13 May 2027. There is no DPDP breach clock running on an incident today. Plan and rehearse against it; do not file against it. | Not in force | Data Principals and the Data Protection Board of India |
Indicative, and not legal advice. Whether an instrument applies to a particular entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Verify every citation against the published text before a notification is filed.
Take this away as an escalation pack
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Every clock, and what starts it
These are not alternatives. A listed private-sector bank holding customer personal data can owe CERT-In, the Reserve Bank and the stock exchanges on the same incident, on different clocks, in different formats, to different recipients.
Two of them do not run from noticing at all. The RBI Directions run from detection, and so do the IFSCA Guidelines that govern GIFT City entities — and IFSCA is the only one that does not stop at the first filing, adding an interim report at three days, mitigation measures at seven and a root cause analysis at thirty.
| Entity class | Reference | Reporting paragraph |
|---|---|---|
| Commercial bank | RBI/DoS/2026-27/410 | Ch. V, §Z.1, para 182 |
| Small Finance Bank | RBI/DoS/2026-27/419 | para 181 |
| Payments Bank | RBI/DoS/2026-27/428 | para 181 |
| Urban Co-operative Bank | RBI/DoS/2026-27/437 | para 88 |
| All India Financial Institution | RBI/DoS/2026-27/456 | para 177 |
| Non-Banking Financial Company | RBI/DoS/2026-27/461 | Ch. IV para 28 / Ch. V para 141 |
| Credit Information Company | RBI/DoS/2026-27/470 | para 177 |
The Commercial Banks Directions exclude Small Finance Banks, Payments Banks and Local Area Banks because each of the first two has its own instrument. That exclusion means file elsewhere, not no obligation.
5 cases are worked through in full, if one of them is yours: NBFC after ransomware attack, listed commercial bank after data breach, stock broker after client data leak, insurer after DDoS attack, GIFT City entity after cyber incident.
One incident, many clocks
The difficulty is rarely a single instrument. It is that several run at once, from different trigger events. Work it in this order.
- Fix the trigger time and write it down. The moment of noticing, in IST, with the source — alert, vendor call, researcher email, regulator enquiry. Every clock is measured from something, and this is the first thing every regulator asks.
- Run the baseline. CERT-In binds nearly every Indian entity.
- Add the sectoral filing. For an RBI regulated entity that means identifying which of the seven Directions binds it, and for an NBFC also which chapter.
- Add the market-disclosure track if the entity is listed. Materiality is the authorised KMP's determination, not a technical one.
- Add NCIIPC if a declared protected system is affected. Protected -system status is a notified fact, never an inference from sector or size.
- Check the third-party direction. If the incident originated at a service provider, the contract's notification terms and the applicable outsourcing instrument are both live. If you are the service provider, your customers' clocks are now running on the notice you give them.
The obligations that bite during an incident
Three standing requirements decide how well the first six hours go, and all three are cheaper to satisfy before an incident than during one.
- Logs, 180 rolling days, within Indian jurisdiction. All ICT system logs enabled, maintained securely for a rolling 180 days and held within Indian jurisdiction. They must be provided to CERT-In with an incident report or when directed.
- Clock synchronisation to NIC or NPL. All ICT system clocks synchronised to the NTP servers of NIC or NPL, or to servers traceable to them. An incident timeline assembled from unsynchronised clocks is very hard to defend.
- A registered CERT-In point of contact. A designated PoC registered with CERT-In in the Annexure II format and kept current. CERT-In directs all communications to the PoC.
For the wider picture of which instruments bind you in the first place, use the regulation finder, or read the pillar guide to cyber security regulations in India.
This tool is indicative and is not legal advice. It does not determine that any instrument applies to your entity — that is a question for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- How long do you have to report a cyber incident in India?
- Six hours to CERT-In, from noticing the incident or being brought to notice of it. Most sectoral clocks are also six hours: RBI regulated entities report on DAKSH within six hours of detection, SEBI regulated entities notify SEBI and CERT-In within six hours, and insurers report to CERT-In within six hours copied to IRDAI. A listed entity separately owes its stock exchanges a disclosure within twelve hours where the incident is material.
- Does the six-hour clock start when an incident is confirmed?
- No. The CERT-In Directions run from noticing the incident or being brought to notice of it, which means a vendor, a researcher or a regulator telling you starts the clock exactly as your own alerting does. The RBI Directions run from detection. In neither case does an incomplete investigation pause the clock — draft on what is known, mark the unknowns as under investigation, and file the update.
- Is the SEBI LODR deadline for a cyber incident 12 hours or 24 hours?
- Twelve hours. Regulation 30(6) sets twelve hours for an event emanating from within the listed entity and twenty-four for an event arising outside it. A ransomware event, data breach or IT outage originates within the entity, so it falls in the twelve-hour limb. The twenty-four hour figure is the one most commonly repeated, and quoting it puts the disclosure twelve hours late.
- Does the DPDP Act require breach notification within 72 hours today?
- No. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act both commence eighteen months after the Rules were notified on 13 November 2025, which is 13 May 2027. There is no DPDP breach-intimation clock running on an incident today. The regime is worth planning and rehearsing against, but a notification filed against it now is filed against an obligation that has not commenced.
- How long does a GIFT City entity have to report a cyber incident?
- Six hours from detection, to the Authority at cyber-incidents@ifsca.gov.in with a copy to the CISO, IFSCA, under the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025. The obligation then continues: an interim report at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. An IFSC licence displaces the mainland regulator, so a GIFT City banking unit does not file under the RBI Directions — but CERT-In still binds it.
- Which RBI Direction applies to an NBFC after a cyber incident?
- RBI/DoS/2026-27/461, the Non-Banking Financial Companies instrument — not the Commercial Banks Directions at 410. Its chapters are graded: a Base Layer NBFC below ₹500 crore sits under Chapter III, which carries no six-hour DAKSH clause at all, while Chapter IV covers Base Layer at ₹500 crore and above and Chapter V covers the Middle, Upper and Top Layers. CERT-In’s six hours binds every one of them.