Open resource, CC BY 4.0
India incident reporting map
One incident can trigger four different reporting duties on four different clocks. This shows you all of them on one page.
The table itself
This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.
Showing 10 of 10 rows
| Regulator | Who reports | Clock starts | Deadline | First report needs |
|---|---|---|---|---|
| CERT-In | Any entity in scope of the 2022 Directions | When you become aware | 6 hours | Incident type, when noticed, systems affected, and your point of contact |
| DPDP Board | Data Fiduciary | On becoming aware of a personal data breach | As prescribed by the Rules | Nature and extent of the breach, likely consequences, measures taken |
| Data Principals | Data Fiduciary | On becoming aware | As prescribed by the Rules | Plain language description of the breach and what the person should do |
| RBI | Banks and regulated entities | On detection | 2 to 6 hours depending on the direction that applies | Nature of incident, systems affected, customer impact, action taken |
| SEBI | Market infrastructure and intermediaries | On detection | Per the CSCRF timeline for your category | Incident details and impact on market operations |
| IRDAI | Insurers and intermediaries | On detection | Per the cyber security guidelines | Incident details and policyholder impact |
| NPCI | Members on affected rails | On detection | Per the rail circular | Impact on the payment rail and transactions affected |
| UIDAI | AUA and KUA entities | On detection | Per UIDAI circulars | Impact on authentication and Aadhaar data |
| NCIIPC | Entities with protected systems | On detection | As directed | Impact on the designated protected system |
| Stock exchanges | Listed entities, where material | On determining materiality | Per LODR disclosure requirements | Material impact on operations or finances |
One incident routinely triggers several of these at once. Drive them from a single runbook, because three separate runbooks means two get forgotten at 2am.
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- CERT-In Directions 2022
- RBI master directions on cyber security
- SEBI CSCRF
- DPDP Act 2023
What people use it for
Pinning to the wall of the room you will run the incident from. That is genuinely the intended use.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- India compliance registryEvery cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.Open it
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- DPDP compliance timelineWhat the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.Open it
Why one incident can carry three clocks
An Indian organisation experiencing a serious incident may owe notifications to several bodies on different timelines with different triggers, and the commonest failure is building one process and assuming it satisfies all of them.
CERT-In, within six hours of noticing, for the incident categories in the 2022 Directions. This trigger is about the type of incident, not about what data was involved.
The Data Protection Board and affected data principals, under the DPDP Act 2023, where personal data was breached. This trigger is about the data, not about the incident type.
Your sectoral regulator, if you have one. RBI, SEBI and IRDAI supervised entities carry their own expectations on top of both.
A ransomware incident on a system holding customer records will typically trigger all three, on three different clocks, to three different recipients, in three different formats.
How to build one process with three outputs
Separate detection and triage from reporting. Detection determines that something happened. Triage determines what it is. Only then does routing apply, and routing is a lookup rather than a judgement if you prepare it in advance.
Write the triage rule in your own vocabulary rather than the law's, and map each of your categories to the reporting paths it triggers. An analyst at 02:00 should be reading your table, not the Directions.
Name one decision maker with an out of hours deputy who can start the clock. The six hours are almost always lost in escalation rather than in detection.
Hold the templates somewhere reachable when your own systems may be compromised. Printed, or on a phone, or with a third party. Not on the file server.
What to include in a first notification
Regulators do not expect a complete picture in six hours, and organisations that wait for one miss the deadline. A first notification says what you know, what you do not yet know, what you are doing, and when you will update.
Do not speculate about cause or attribution. Early attribution is wrong often enough that it becomes a credibility problem later, and it is not what the notification is for.
Do record the timeline of your own knowledge, with times, from the first indication onwards. That record is what determines whether your six hours were met, and reconstructing it later from memory is how organisations discover they cannot demonstrate compliance.
Rehearsing it
A reporting process that has never been exercised is documentation. One rehearsal a year, at an inconvenient hour, tests the things that actually fail: whether the on-call rota is current, whether the deputy knows they are the deputy, whether anyone can find the template, and whether the decision maker feels able to decide without escalating.
Run it as a decision exercise rather than a technical one. The scenario matters less than whether a reportable determination gets made inside the window by the person authorised to make it.
Write down what did not work. A rehearsal that surfaces nothing was not a rehearsal.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












