Which cyber security regulations apply to you in India, the US and the EU
Answer a few questions about where you operate and what you do. Get the cyber and data-protection laws likely to bind you in India, the US and the EU, and why.
Find your instruments
Tick what is true of your organisation in each jurisdiction, and leave the rest. Every instrument shown says why it was included and what is most often got wrong about it, and links to the issuing body's own text.
| Instrument | Status | Why |
|---|---|---|
| CERT-In Directions, 2022No. 20(3)/2022-CERT-In | Likely applies | The Directions bind service providers, intermediaries, data centres, body corporates and Government organisations — which reaches almost every entity operating IT systems in India.Six hours from noticing an incident, or being brought to notice of it. A sectoral filing never discharges it.Next: India incident clock |
| Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) | Likely applies | Section 3 reaches digital personal data processed in India, and processing outside India connected with offering goods or services to people in India.Phased. The breach-intimation duty in Rule 7 and section 8 of the Act commence on 13 May 2027, so no DPDP breach clock runs today. |
| Instrument | Status | Why |
|---|---|---|
| SEC Form 8-K, Item 1.05 | Likely applies | SEC registrants disclose a material cybersecurity incident on Form 8-K.Four business days from determining the incident is material — and the determination itself must be made without unreasonable delay.Next: US and EU incident clock |
| SEC Regulation S-K, Item 10617 CFR 229.106 | Likely applies | The annual report describes how you assess and manage material cyber risk — including whether you oversee risk from third-party service providers — and how the board oversees it. |
| State breach-notification laws | Check | Every US state has a breach-notification law, triggered by the residency of the people affected rather than where you are.Thresholds, windows and regulator notices differ state by state. This tool does not resolve them. |
| Instrument | Status | Why |
|---|---|---|
| General Data Protection RegulationRegulation (EU) 2016/679 | Likely applies | Article 3 reaches processing by an establishment in the EU, and processing by a non-EU business that offers goods or services to people in the EU or monitors their behaviour there.72 hours from becoming aware of a personal data breach, where feasible.Next: US and EU incident clock |
| DORA, through your customers’ contractsRegulation (EU) 2022/2554, Chapter V | Check | ICT third-party service providers are within DORA’s scope. For most, the obligations arrive as contract terms your EU financial-entity customers must impose, not as direct supervision.Next: What DORA asks of vendors |
| NIS2 Directive — likely an essential entityDirective (EU) 2022/2555 | Likely applies | An Annex I entity above the medium-sized ceilings is an essential entity under Article 3(1)(a).NIS2 is a directive: the obligations, the authority and the penalties come from your Member State’s transposing law. Early warning within 24 hours of becoming aware of a significant incident.Next: US and EU incident clock |
| Cyber Resilience ActRegulation (EU) 2024/2847 | Likely applies | Manufacturers of products with digital elements made available on the EU market — hardware and software alike.Reporting under Article 14 has applied since 11 September 2026; most other obligations from 11 December 2027.Next: CRA reporting guide |
Indicative, and not a determination that any instrument applies. Scope turns on facts a form cannot settle; every entry says why it was included so the reasoning can be checked. Links go to the issuing body's own text.
Take this away as an obligation map
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, an owner column against every action, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Where the reach comes from
- Whose data you hold. GDPR reaches a business outside the EU that offers goods or services to people there or monitors their behaviour. DPDP reaches processing outside India connected with offering goods or services to people in India. US state laws follow the residency of the people affected.
- What you do, and how big you are. NIS2 covers the sectors in its two annexes, generally from medium size upwards. DORA covers EU financial entities by type. The US bank rule, NYDFS, HIPAA and the FTC Safeguards Rule each follow a regulated activity.
- Where you are listed. An SEC registrant owes Form 8-K and Item 106 disclosure; a foreign private issuer furnishes Form 6-K on the back of its home disclosure. An Indian listing brings SEBI LODR.
- Whom you supply. An ICT provider to EU financial entities meets DORA through its customers' contracts, and a hardware or software maker meets the Cyber Resilience Act by selling into the EU at all.
Where instruments run together
The instruments are cumulative. A filing under one never discharges another, and three overlaps catch people out.
- DORA displaces NIS2 for financial entities. Banking is an NIS2 sector, but a bank reports under DORA instead, as NIS2 Recital 28 and Article 4 provide.
- One incident, several clocks. A breach of customer data at a US-listed group with EU and Indian operations can owe CERT-In in six hours, GDPR in 72, and the SEC four business days after a materiality decision — each from a different starting point. The US and EU incident clock and the India incident clock resolve them.
- Indian financial regulation is its own map. The RBI issued seven parallel Directions on 31 July 2026, one per entity class. The India regulation finder resolves which one binds you.
Scope read from the issuing body's own text: GDPR Article 3, NIS2 Articles 2 and 3 and Annexes I and II, DORA Article 2, the Cyber Resilience Act and Commission Recommendation 2003/361/EC on EUR-Lex; Forms 8-K and 6-K on sec.gov; 23 NYCRR Part 500 on dfs.ny.gov; 17 CFR 229.106, 12 CFR Part 53, 16 CFR Part 314 and 45 CFR Part 164 on the eCFR; CISA's CIRCIA page; and section 3 of the DPDP Act, 2023 on meity.gov.in. This tool is indicative and is not a determination that any instrument applies. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- Does GDPR apply to a company outside the EU?
- It can. Article 3 applies GDPR to a controller or processor not established in the EU where its processing relates to offering goods or services to people in the EU, whether or not payment is required, or to monitoring their behaviour in the EU. Being established in the EU brings any processing in the context of that establishment into scope, wherever the processing happens.
- Does India’s DPDP Act apply to a foreign company?
- It can. Section 3 of the Digital Personal Data Protection Act, 2023 applies to processing of digital personal data outside India where it is connected with offering goods or services to people in India. Processing inside India is in scope wherever the business is based. The breach-intimation duty commences on 13 May 2027.
- Which companies are covered by NIS2?
- Entities of a type listed in Annex I or II of the Directive — sectors from energy, banking and health to manufacturing and digital providers — that are at least medium-sized and provide services in the EU. Some are covered regardless of size, including telecoms, trust service and DNS providers. An Annex I entity above the medium-sized ceilings is essential; most others in scope are important.
- Does NIS2 apply to banks?
- Banking is an Annex I sector, but for financial entities DORA is the sector-specific act that applies instead of NIS2’s risk-management and incident-reporting rules, as NIS2 Recital 28 and Article 4 provide. A bank reports major ICT-related incidents under DORA, not significant incidents under NIS2.
- Is there a single US cyber security regulation?
- No. US obligations come from several directions at once: the SEC for listed companies, sector regulators such as NYDFS, the federal banking agencies, the FTC and HHS for health data, and a breach-notification law in every state. CIRCIA will add critical-infrastructure reporting to CISA once its final rule takes effect.