Skip to main content
Glama

Indian Cyber Regulation Register (BitScore)

US and EU cyber incident reporting deadlines

us_eu_incident_reporting_deadlines
Read-onlyIdempotent

Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
secYesSEC status.
doraYesDORA status.
gdprYesGDPR role for the personal data involved.
nis2YesAn essential or important entity under NIS2.
hipaaYesHIPAA role.
nydfsYesRegulated by the New York DFS (23 NYCRR 500).
us_bankYesA US banking organisation under the 36-hour computer-security incident rule.
aware_atNoOptional. When the entity became aware, ISO 8601 with offset.
decided_atNoOptional. When materiality/reportability/major classification was determined, ISO 8601 with offset.
ftc_safeguardsYesA non-bank financial institution under the FTC Safeguards Rule.
cra_manufacturerYesA manufacturer of products with digital elements under the EU CRA.
bank_service_providerYesA bank service provider under the same rule.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

B3.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, non-destructive and closed-world, so safety is covered. The description adds one genuinely useful behavioral fact: each regime's clock runs from its own distinct trigger, which explains why multiple date inputs matter. It does not describe the shape of the returned deadlines or how regimes with no applicable clock are represented.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tightly packed sentences, front-loaded on scope before the input instruction. The regime list is long but each item is a distinct covered framework, so it earns its space, though it reads as a run-on enumeration.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 12-parameter read-only calculator with no output schema, the description covers scope and required date inputs adequately, but it leaves the returned result unexplained — whether the output is a per-regime due timestamp, a list, or a status when a regime does not apply. That gap matters because no output schema exists to fill it.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and all twelve parameters (including four enums) are documented in-schema, so the baseline is 3. The description adds only a light gloss on aware_at and decided_at ('for materiality/classification clocks'), largely restating what the schema already says about those fields.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a concrete output (incident-reporting clocks / wall-clock due times) and enumerates the specific regimes it covers (SEC 8-K/6-K, NYDFS Part 500, the 36-hour bank rule, HIPAA, FTC Safeguards, NIS2, DORA, GDPR, CRA), which clearly separates it from sibling tools like find_applicable_regulations or india_incident_reporting_deadlines. It never names a sibling explicitly, so the differentiation is by subject matter rather than by contrast.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The second sentence gives input guidance ('Give aware_at (and decided_at...)'), which is invocation detail rather than when-to-use guidance. There is no statement of when this tool is preferable to find_applicable_regulations, find_global_cyber_regulations, or the india equivalent, and no exclusions or prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources