India Regulatory Hub
Cross-regulator · India Deep Dive

Multi-Regulator Breach Playbook

The CERT-In 6-hour clock is the fastest breach deadline in the world — it sets the pace for every other notification. Select your entity type and breach type below to generate your notification sequence, then keep your internal detection-to-notification pipeline under 4 hours for a safety margin.

Last verified: 2026-06-17
Interactive decision tree

Breach notification timeline — all regulators

Regulator / BodyDeadline from DetectionReport TriggerWhat to IncludeApplies To
CERT-In6 hoursAny reportable cyber incident (26 types)Incident type, affected systems, impact estimate, initial remediation steps; preliminary report acceptedAll intermediaries, data centres, body corporate
RBI (CSITE)6 hoursCyber incident affecting bank systems, customer data, or payment servicesParallel to CERT-In; use RBI CSITE portal; preliminary report + final RCA within 21 daysBanks, NBFCs, Payment Aggregators
SEBI (Cybercell)6 hoursCyber incident affecting market systems, investor data, or trading platformsSEBI incident report format; simultaneous with CERT-InStock exchanges, brokers, depositories, MIIs
IRDAI6 hours (sector)Cyber incident affecting insurer systems, policyholder data, or claims processingIRDAI notification + CERT-In simultaneously; SAR update requiredInsurers, reinsurers, insurance brokers
Data Protection Board (DPBI)72 hoursPersonal data breach affecting Data PrincipalsNotify DPB + affected Data Principals; breach description, categories of data, remediation stepsAll Data Fiduciaries under DPDP Act (enforceable ~May 2027)
Board / InternalImmediatelyAny material cyber incidentCEO and Board notified immediately; crisis response team activated; legal counsel engagedAll regulated entities

Made with Emergent