ARM Innovations Logo
ARM Innovations
6-Hour Incident Reporting

CSCRF vs. CERT-In: Navigating the 6-Hour Reporting Window for Regulated Entities

By Compliance TeamPublished July 21, 20267 min read

The 6-Hour Clock Challenge

When you discover a potential breach, the 6-hour reporting window can feel like 6 minutes. The goal isn't to solve the entire breach in 6 hours—it's to get the right information to the right authorities so they can help you respond effectively.


The Reporting Clock

Let's be honest. When you discover a potential breach, the 6-hour reporting window can feel like 6 minutes.

It's stressful. It's urgent. And it's easy to panic. But panic is the enemy of good reporting.

Think of it like an emergency triage center. When someone arrives with a critical injury, you don't perform complex surgery on the spot. You triage. You stabilize. You communicate clearly to the right people.

This guide helps you understand the difference between CERT-In and SEBI CSCRF reporting obligations, how they overlap, and how to prepare so that when the clock starts ticking, you're ready.

Navigating 6-hour reporting requirements

Regulatory Reporting Requirements at a Glance

AspectCERT-In RequirementsSEBI CSCRF ReportingKey Difference
Reporting Window6 hours from detectionAs per CSCRF timelines (varies by entity type)CERT-In is fixed at 6 hours; SEBI timelines align with severity
TriggerCybersecurity incidents (defined in guidelines)Cyber incidents affecting regulated entitiesSEBI has a broader definition of "material" incidents
FormatSpecific CERT-In formatSEBI prescribed formatSeparate templates; don't assume they're identical
AuthorityCERT-In (MeitY)SEBI (Markets regulator)Dual reporting is mandatory for regulated entities
PenaltiesLegal action, finesRegulatory action, penalties, reputational damageBoth carry significant consequences

The 6-Hour Mandate: Understanding CERT-In Requirements

CERT-In expects regulated entities to report cybersecurity incidents within 6 hours of detection. This applies to a wide range of incidents including data breaches, ransomware attacks, and unauthorized system access.

What counts as a reportable incident?

A reportable incident is not every security event. A failed login attempt is an event. A caught phishing email is an event. But a confirmed breach of customer data or a ransomware attack that encrypts systems? That's an incident.

The SEBI Clock: Understanding CSCRF Reporting Obligations

SEBI CSCRF also requires incident reporting, with a focus on incidents affecting market integrity, investor confidence, or operational stability.

The overlap: Most incidents that trigger CERT-In reporting will also trigger SEBI CSCRF reporting.

The difference: CERT-In focuses on national cybersecurity infrastructure. SEBI focuses on market integrity and investor asset protection.

The Reporting Playbook: How to Prepare

Hour 1

Phase 1: Detection

Immediately notify your incident response team. Don't wait for confirmation. Start the clock.

Hour 2

Phase 2: Triage

Gather initial information. Determine if what you've detected is an event or a reportable incident.

Hour 3

Phase 3: Verification

Collect evidence. Document everything. Regulators want to know what happened, when, and what you're doing.

Hours 4-5

Phase 4: Reporting

Draft and submit notifications to CERT-In and SEBI using prescribed templates.

Hour 6+

Phase 5: Follow-Up

Assign a coordinator to provide updates and handle regulator questions promptly.

The "False Alarm" Trap

Over-reporting is better than under-reporting. Regulators aren't penalizing organizations for reporting incidents that turn out to be false alarms. They penalize organizations that fail to report—or report too late.

The 6-hour window isn't a deadline to confirm everything; it's a deadline to start the communication process.

Avoiding Common Reporting Mistakes

  • Delaying detection: The clock starts when you detect the incident. Don't wait for "confirmation."
  • Incomplete reporting: Provide as much detail as you can. Be transparent about what you don't know.
  • Duplicating effort: Use a single team to coordinate notifications for both CERT-In and SEBI.
  • Ignoring internal escalation: Keep legal, compliance, and executive teams informed early.
  • Not rehearsing: Run a 6-hour simulation exercise annually to test your response.

The 3-Step Reporting Readiness Audit

1

Define Your Reporting Team

Define decision-making authority, drafting roles, and regulatory liaisons before an incident occurs.

2

Draft Notification Templates

Prepare pre-formatted templates for CERT-In and SEBI so you aren't writing under pressure.

3

Conduct a 6-Hour Simulation

Run a tabletop simulation to test your team's ability to detect, triage, and report within 6 hours.

How ARM Innovations Supports Incident Readiness

As a CERT-In-empaneled organization, ARM Innovations helps regulated entities prepare for incident reporting through gap assessments, incident response planning, and regulatory alignment.

Expert FAQ

Be 6-Hour Incident Reporting Ready

Don't wait for a security incident to test your reporting playbook. Build confidence with CERT-In empaneled experts.

Get Incident Playbook Review

Incident Readiness Audit

Ensure your team is prepared for CERT-In & SEBI reporting deadlines.

Cyber Insights Newsletter

Get weekly regulatory updates, audit checklists, and security insights delivered to your inbox.

Related Resources

Continue your research with these relevant guides and services.

+91 99104 22411WhatsApp