io.github.nimitt-IN/india-cyber-regulations

Indian Cyber Regulation Register (BitScore)

Indian cyber regulation register and incident-reporting deadlines (India, US, EU), read at source.

1.0.0
Version
remote
Transport
8
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 8 tools scanned
  • metadata: scanned

No findings.

Tools (8)

  • search_instruments

    Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one entry in full.

  • get_instrument

    Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulator’s own URL and the date it was last re-read there.

  • find_applicable_regulations

    Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions; RRBs and LABs have none, and the result says so.

  • india_incident_reporting_deadlines

    Every incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.

  • us_eu_incident_reporting_deadlines

    Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.

  • find_global_cyber_regulations

    For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.

  • sebi_cscrf_category

    Works out a SEBI regulated entity’s CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave uncategorised are reported as such, not guessed.

  • india_threat_scorecard

    Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.