Indian cyber incident reporting deadlines
india_incident_reporting_deadlinesEvery incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| listed | Yes | Listed on an Indian stock exchange. | |
| sector | Yes | Sectoral regulator, or "none". | |
| ifsca_mii | No | IFSC market infrastructure institution (stock exchange, clearing corporation, depository). | |
| rbi_class | No | Required when sector is "rbi". | |
| nbfc_layer | No | For an NBFC: its layer under Scale-Based Regulation. | |
| noticed_at | No | Optional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30. | |
| ifsca_exempt | No | IFSCA RE inside either exemption tier of the 2025 Guidelines. | |
| personal_data | Yes | The incident involves digital personal data. | |
| protected_system | Yes | Operates a notified Protected System (brings NCIIPC). | |
| sebi_broker_or_dp | No | SEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories). |