Skip to main content
Glama

Indian Cyber Regulation Register (BitScore)

Indian cyber incident reporting deadlines

india_incident_reporting_deadlines
Read-onlyIdempotent

Every incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
listedYesListed on an Indian stock exchange.
sectorYesSectoral regulator, or "none".
ifsca_miiNoIFSC market infrastructure institution (stock exchange, clearing corporation, depository).
rbi_classNoRequired when sector is "rbi".
nbfc_layerNoFor an NBFC: its layer under Scale-Based Regulation.
noticed_atNoOptional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30.
ifsca_exemptNoIFSCA RE inside either exemption tier of the 2025 Guidelines.
personal_dataYesThe incident involves digital personal data.
protected_systemYesOperates a notified Protected System (brings NCIIPC).
sebi_broker_or_dpNoSEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories).

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish read-only, idempotent, non-destructive behavior, so the bar is lower. The description adds real context beyond that: the parallel-clock semantics, the non-discharge rule, and the dependency of wall-clock output on noticed_at.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two dense sentences with no filler; the scope enumeration comes first and the operational instruction follows. Slightly packed but every clause carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the burden of describing the return shape and does so: each clock comes with trigger, recipient, channel and source clause, plus computed due times. Nothing essential for correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and each of the 10 parameters is documented, so the baseline is 3. The description earns one above baseline by explaining the effect of noticed_at (conversion to IST due times) rather than merely restating its schema text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific computed artifact (Indian incident-reporting clocks) and enumerates the regimes it covers (CERT-In, RBI, SEBI, IRDAI, IFSCA, LODR, NCIIPC, DPDP), which cleanly separates it from the sibling us_eu_incident_reporting_deadlines.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

States the operative input condition clearly: supply noticed_at to get wall-clock IST due times. It also warns that clocks run in parallel and none discharges another, which shapes how results should be used. It stops short of naming when to prefer a sibling tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources