What a GIFT City entity must report after a cyber incident
Work out every regulatory notification an Indian entity owes after a cyber incident, as wall-clock IST deadlines — CERT-In, the seven RBI Directions, SEBI CSCRF and LODR, IRDAI and NCIIPC, each with the clause it comes from.
What this case turns on
A GIFT City entity is licensed by IFSCA, and that displaces the mainland regulator: a banking unit in the IFSC does not file under the RBI’s 2026 Directions, and an IFSC fund does not take a CSCRF category. The clock also behaves differently from every other Indian instrument. It runs from detection rather than from noticing, and it does not stop at the first filing — an interim report falls due at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. Four express exemptions at para 21 are easy to fall inside, but each is conditional on adopting the parent entity’s framework and naming its CISO as Designated Officer.
| Instrument | What you file | Window | Starts from |
|---|---|---|---|
| CERT-In Directions, 2022 | Report the incident to CERT-In | 6 hours from noticing, or being brought to notice | Noticing, or being brought to notice |
| IFSCA Cyber Security Guidelines, 2025 | Report the particulars of the incident to the Authority | 6 hours from detection | Detection |
| IFSCA Cyber Security Guidelines, 2025 | Submit the interim report | 3 days from detection | Detection |
| IFSCA Cyber Security Guidelines, 2025 | Take mitigation measures for the incident | 7 days from detection | Detection |
| IFSCA Cyber Security Guidelines, 2025 | Submit the detailed root cause analysis report | 30 days from detection | Detection |
| DPDP Act, 2023 and DPDP Rules, 2025 | Intimation to affected Data Principals, and a two-stage report to the Data Protection Board | Not in force | — |
Adjust it to your own facts
The tool below opens on this scenario. Change anything that does not match your entity, and add the moment you noticed to turn the windows into wall-clock IST deadlines.
| Instrument | What you file | Window | Goes to |
|---|---|---|---|
| CERT-In Directions, 2022No. 20(3)/2022-CERT-In | Report the incident to CERT-Inwithin 6 hours of noticing such incidents or being brought to notice about such incidents | 6 hours from noticing, or being brought to noticefrom: noticing, or being brought to notice | CERT-Inincident@cert-in.org.in · 1800-11-4949 |
| IFSCA Cyber Security Guidelines, 2025IFSCA-CSD0MSC/13/2025-DCS · para 19 | Report the particulars of the incident to the Authoritynot later than six (6) hours from the detection of the incidentFrom detection, not from noticing. A GIFT City entity files here rather than with the RBI, SEBI or IRDAI — an IFSC licence displaces the mainland regulator even for business those regulators supervise onshore. | 6 hours from detectionfrom: detection | IFSCA, copied to the CISO, IFSCAcyber-incidents@ifsca.gov.in |
| IFSCA Cyber Security Guidelines, 2025IFSCA-CSD0MSC/13/2025-DCS · para 20 | Submit the interim report | 3 days from detectionfrom: detection | IFSCAcyber-incidents@ifsca.gov.in |
| IFSCA Cyber Security Guidelines, 2025IFSCA-CSD0MSC/13/2025-DCS · para 20 | Take mitigation measures for the incidentA deadline on the remediation itself, not on a filing. No other Indian cyber instrument puts a clock on the fix. | 7 days from detectionfrom: detection | Internal, evidenced to IFSCA |
| IFSCA Cyber Security Guidelines, 2025IFSCA-CSD0MSC/13/2025-DCS · para 20 | Submit the detailed root cause analysis report | 30 days from detectionfrom: detection | IFSCAcyber-incidents@ifsca.gov.in |
| DPDP Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) · Rule 7 · G.S.R. 843(E), section 8 | Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force. Rule 7 falls in the eighteen-month tranche under Rule 1(4), and section 8 commences on the same date — 13 May 2027. There is no DPDP breach clock running on an incident today. Plan and rehearse against it; do not file against it. | Not in force | Data Principals and the Data Protection Board of India |
Indicative, and not legal advice. Whether an instrument applies to a particular entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Verify every citation against the published text before a notification is filed.
Take this away as an escalation pack
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
For the full picture — every clock, how they overlap, and the standing obligations that decide how the first six hours go — see the complete incident reporting clock.
This page is indicative and is not legal advice. Whether an instrument applies to your entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- How long do you have to report a cyber incident in India?
- Six hours to CERT-In, from noticing the incident or being brought to notice of it. Most sectoral clocks are also six hours: RBI regulated entities report on DAKSH within six hours of detection, SEBI regulated entities notify SEBI and CERT-In within six hours, and insurers report to CERT-In within six hours copied to IRDAI. A listed entity separately owes its stock exchanges a disclosure within twelve hours where the incident is material.
- Does the six-hour clock start when an incident is confirmed?
- No. The CERT-In Directions run from noticing the incident or being brought to notice of it, which means a vendor, a researcher or a regulator telling you starts the clock exactly as your own alerting does. The RBI Directions run from detection. In neither case does an incomplete investigation pause the clock — draft on what is known, mark the unknowns as under investigation, and file the update.
- Is the SEBI LODR deadline for a cyber incident 12 hours or 24 hours?
- Twelve hours. Regulation 30(6) sets twelve hours for an event emanating from within the listed entity and twenty-four for an event arising outside it. A ransomware event, data breach or IT outage originates within the entity, so it falls in the twelve-hour limb. The twenty-four hour figure is the one most commonly repeated, and quoting it puts the disclosure twelve hours late.
- Does the DPDP Act require breach notification within 72 hours today?
- No. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act both commence eighteen months after the Rules were notified on 13 November 2025, which is 13 May 2027. There is no DPDP breach-intimation clock running on an incident today. The regime is worth planning and rehearsing against, but a notification filed against it now is filed against an obligation that has not commenced.
- How long does a GIFT City entity have to report a cyber incident?
- Six hours from detection, to the Authority at cyber-incidents@ifsca.gov.in with a copy to the CISO, IFSCA, under the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025. The obligation then continues: an interim report at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. An IFSC licence displaces the mainland regulator, so a GIFT City banking unit does not file under the RBI Directions — but CERT-In still binds it.
- Which RBI Direction applies to an NBFC after a cyber incident?
- RBI/DoS/2026-27/461, the Non-Banking Financial Companies instrument — not the Commercial Banks Directions at 410. Its chapters are graded: a Base Layer NBFC below ₹500 crore sits under Chapter III, which carries no six-hour DAKSH clause at all, while Chapter IV covers Base Layer at ₹500 crore and above and Chapter V covers the Middle, Upper and Top Layers. CERT-In’s six hours binds every one of them.