The 6-Hour Clock Challenge
When you discover a potential breach, the 6-hour reporting window can feel like 6 minutes. The goal isn't to solve the entire breach in 6 hours—it's to get the right information to the right authorities so they can help you respond effectively.
The Reporting Clock
Let's be honest. When you discover a potential breach, the 6-hour reporting window can feel like 6 minutes.
It's stressful. It's urgent. And it's easy to panic. But panic is the enemy of good reporting.
Think of it like an emergency triage center. When someone arrives with a critical injury, you don't perform complex surgery on the spot. You triage. You stabilize. You communicate clearly to the right people.
This guide helps you understand the difference between CERT-In and SEBI CSCRF reporting obligations, how they overlap, and how to prepare so that when the clock starts ticking, you're ready.

Regulatory Reporting Requirements at a Glance
| Aspect | CERT-In Requirements | SEBI CSCRF Reporting | Key Difference |
|---|---|---|---|
| Reporting Window | 6 hours from detection | As per CSCRF timelines (varies by entity type) | CERT-In is fixed at 6 hours; SEBI timelines align with severity |
| Trigger | Cybersecurity incidents (defined in guidelines) | Cyber incidents affecting regulated entities | SEBI has a broader definition of "material" incidents |
| Format | Specific CERT-In format | SEBI prescribed format | Separate templates; don't assume they're identical |
| Authority | CERT-In (MeitY) | SEBI (Markets regulator) | Dual reporting is mandatory for regulated entities |
| Penalties | Legal action, fines | Regulatory action, penalties, reputational damage | Both carry significant consequences |
The 6-Hour Mandate: Understanding CERT-In Requirements
CERT-In expects regulated entities to report cybersecurity incidents within 6 hours of detection. This applies to a wide range of incidents including data breaches, ransomware attacks, and unauthorized system access.
What counts as a reportable incident?
A reportable incident is not every security event. A failed login attempt is an event. A caught phishing email is an event. But a confirmed breach of customer data or a ransomware attack that encrypts systems? That's an incident.
The SEBI Clock: Understanding CSCRF Reporting Obligations
SEBI CSCRF also requires incident reporting, with a focus on incidents affecting market integrity, investor confidence, or operational stability.
The overlap: Most incidents that trigger CERT-In reporting will also trigger SEBI CSCRF reporting.
The difference: CERT-In focuses on national cybersecurity infrastructure. SEBI focuses on market integrity and investor asset protection.
The Reporting Playbook: How to Prepare
Phase 1: Detection
Immediately notify your incident response team. Don't wait for confirmation. Start the clock.
Phase 2: Triage
Gather initial information. Determine if what you've detected is an event or a reportable incident.
Phase 3: Verification
Collect evidence. Document everything. Regulators want to know what happened, when, and what you're doing.
Phase 4: Reporting
Draft and submit notifications to CERT-In and SEBI using prescribed templates.
Phase 5: Follow-Up
Assign a coordinator to provide updates and handle regulator questions promptly.
The "False Alarm" Trap
Over-reporting is better than under-reporting. Regulators aren't penalizing organizations for reporting incidents that turn out to be false alarms. They penalize organizations that fail to report—or report too late.
The 6-hour window isn't a deadline to confirm everything; it's a deadline to start the communication process.
Avoiding Common Reporting Mistakes
- Delaying detection: The clock starts when you detect the incident. Don't wait for "confirmation."
- Incomplete reporting: Provide as much detail as you can. Be transparent about what you don't know.
- Duplicating effort: Use a single team to coordinate notifications for both CERT-In and SEBI.
- Ignoring internal escalation: Keep legal, compliance, and executive teams informed early.
- Not rehearsing: Run a 6-hour simulation exercise annually to test your response.
The 3-Step Reporting Readiness Audit
Define Your Reporting Team
Define decision-making authority, drafting roles, and regulatory liaisons before an incident occurs.
Draft Notification Templates
Prepare pre-formatted templates for CERT-In and SEBI so you aren't writing under pressure.
Conduct a 6-Hour Simulation
Run a tabletop simulation to test your team's ability to detect, triage, and report within 6 hours.
How ARM Innovations Supports Incident Readiness
As a CERT-In-empaneled organization, ARM Innovations helps regulated entities prepare for incident reporting through gap assessments, incident response planning, and regulatory alignment.
Expert FAQ
Be 6-Hour Incident Reporting Ready
Don't wait for a security incident to test your reporting playbook. Build confidence with CERT-In empaneled experts.
Get Incident Playbook Review