Tool 1

What a listed commercial bank must report after a data breach

Work out every regulatory notification an Indian entity owes after a cyber incident, as wall-clock IST deadlines — CERT-In, the seven RBI Directions, SEBI CSCRF and LODR, IRDAI and NCIIPC, each with the clause it comes from.

In short
An Indian entity that notices a cyber incident owes CERT-In a report within six hours. RBI regulated entities file on DAKSH within six hours of detection; SEBI entities file to SEBI and CERT-In within six hours, then the portal within twenty-four. IRDAI is six hours, with no second step. A listed entity owes the exchanges twelve hours. DPDP does not commence until 13 May 2027.

What this case turns on

This is the case where the market-disclosure track is most often forgotten and most often mis-timed. A listed bank works three clocks from the same moment: CERT-In at six hours, DAKSH at six hours from detection, and the stock exchanges at twelve hours where the authorised KMP determines the event is material. The twelve-hour limb can fall due before some of the technical work is finished, and Reg. 27(2)(ba) then requires the incident in the quarterly governance report whether it was material or not.

InstrumentWhat you fileWindowStarts from
CERT-In Directions, 2022Report the incident to CERT-In6 hours from noticing, or being brought to noticeNoticing, or being brought to notice
RBI Cyber Directions, 2026 — Commercial bankReport the cyber incident on the DAKSH platform6 hours from detectionDetection
SEBI LODR, Reg. 30(6)Market disclosure of the event, if the KMP determines it is material12 hours from occurrence of a material eventOccurrence of a material event
SEBI LODR, Reg. 27(2)(ba)Disclose details of the incident in the quarterly corporate governance reportNext quarterly corporate governance reportOccurrence of a material event
DPDP Act, 2023 and DPDP Rules, 2025Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force
Every filing owed on this scenario, with the window each one runs for.

Adjust it to your own facts

The tool below opens on this scenario. Change anything that does not match your entity, and add the moment you noticed to turn the windows into wall-clock IST deadlines.

Your entity
When you noticed
4filings owed — windows from each trigger
InstrumentWhat you fileWindowGoes to
CERT-In Directions, 2022No. 20(3)/2022-CERT-InReport the incident to CERT-Inwithin 6 hours of noticing such incidents or being brought to notice about such incidents6 hours from noticing, or being brought to noticefrom: noticing, or being brought to noticeCERT-Inincident@cert-in.org.in · 1800-11-4949
RBI Cyber Directions, 2026 — Commercial bankRBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182Report the cyber incident on the DAKSH platformshall report cyber incidents within six hours of detection on DAKSH platformOne of seven parallel Directions issued on 31 July 2026, one per entity class. Quote this instrument and its own paragraph number — the numbering differs between them.6 hours from detectionfrom: detectionReserve Bank of Indiadaksh.rbi.org.in
SEBI LODR, Reg. 30(6)SEBI LODR Regulations, 2015, as amended 14 July 2026Market disclosure of the event, if the KMP determines it is materialtwelve hours from the occurrence of the event or informationTwelve hours, not twenty-four. A ransomware event, data breach or IT outage emanates from within the listed entity, which is limb (ii). Limb (iii)’s twenty-four hours is for events arising outside it. Materiality is the authorised KMP’s determination, not a technical one.12 hours from occurrence of a material eventfrom: occurrence of a material eventStock exchanges
SEBI LODR, Reg. 27(2)(ba)SEBI LODR Regulations, 2015, as amended 14 July 2026Disclose details of the incident in the quarterly corporate governance reportDetails of cyber security incidents or breaches or loss of data or documents shall be disclosed along with the reportNo materiality test. An incident correctly judged immaterial for Reg. 30 is still reportable here — so this belongs on the post-incident checklist, not the first-24-hours one.Next quarterly corporate governance reportStock exchanges
DPDP Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) · Rule 7 · G.S.R. 843(E), section 8Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force. Rule 7 falls in the eighteen-month tranche under Rule 1(4), and section 8 commences on the same date — 13 May 2027. There is no DPDP breach clock running on an incident today. Plan and rehearse against it; do not file against it.Not in forceData Principals and the Data Protection Board of India

Indicative, and not legal advice. Whether an instrument applies to a particular entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Verify every citation against the published text before a notification is filed.

Take this away as an escalation pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

For the full picture — every clock, how they overlap, and the standing obligations that decide how the first six hours go — see the complete incident reporting clock.

This page is indicative and is not legal advice. Whether an instrument applies to your entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

How long do you have to report a cyber incident in India?
Six hours to CERT-In, from noticing the incident or being brought to notice of it. Most sectoral clocks are also six hours: RBI regulated entities report on DAKSH within six hours of detection, SEBI regulated entities notify SEBI and CERT-In within six hours, and insurers report to CERT-In within six hours copied to IRDAI. A listed entity separately owes its stock exchanges a disclosure within twelve hours where the incident is material.
Does the six-hour clock start when an incident is confirmed?
No. The CERT-In Directions run from noticing the incident or being brought to notice of it, which means a vendor, a researcher or a regulator telling you starts the clock exactly as your own alerting does. The RBI Directions run from detection. In neither case does an incomplete investigation pause the clock — draft on what is known, mark the unknowns as under investigation, and file the update.
Is the SEBI LODR deadline for a cyber incident 12 hours or 24 hours?
Twelve hours. Regulation 30(6) sets twelve hours for an event emanating from within the listed entity and twenty-four for an event arising outside it. A ransomware event, data breach or IT outage originates within the entity, so it falls in the twelve-hour limb. The twenty-four hour figure is the one most commonly repeated, and quoting it puts the disclosure twelve hours late.
Does the DPDP Act require breach notification within 72 hours today?
No. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act both commence eighteen months after the Rules were notified on 13 November 2025, which is 13 May 2027. There is no DPDP breach-intimation clock running on an incident today. The regime is worth planning and rehearsing against, but a notification filed against it now is filed against an obligation that has not commenced.
How long does a GIFT City entity have to report a cyber incident?
Six hours from detection, to the Authority at cyber-incidents@ifsca.gov.in with a copy to the CISO, IFSCA, under the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025. The obligation then continues: an interim report at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. An IFSC licence displaces the mainland regulator, so a GIFT City banking unit does not file under the RBI Directions — but CERT-In still binds it.
Which RBI Direction applies to an NBFC after a cyber incident?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies instrument — not the Commercial Banks Directions at 410. Its chapters are graded: a Base Layer NBFC below ₹500 crore sits under Chapter III, which carries no six-hour DAKSH clause at all, while Chapter IV covers Base Layer at ₹500 crore and above and Chapter V covers the Middle, Upper and Top Layers. CERT-In’s six hours binds every one of them.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools