Indian Cyber Regulation Register (BitScore)
Indian cyber regulation register and incident-reporting deadlines (India, US, EU), read at source.
Should I use this
Quality & Safety
Findings (2)
- LOWin india_incident_reporting_deadlines
- LOWin us_eu_incident_reporting_deadlines
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"india-cyber-regulations": {
"url": "https://www.bitscore.in/mcp"
}
}
}Remote endpoints
https://www.bitscore.in/mcpstreamable-httpWhat it can do
Tool inventory
Tools (8)
π’search_instruments(query, issuer, status, limit)
Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one entry in full.
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Words to match against the name, reference number and who it binds, e.g. \"outsourcing\", \"NBFC\", \"2024/113\".",
"maxLength": 200
},
"issuer": {
"type": "string",
"description": "Only instruments from this issuer.",
"enum": [
"RBI",
"SEBI",
"IRDAI",
"IFSCA",
"CERT-In",
"MeitY"
]
},
"status": {
"type": "string",
"description": "Only instruments with this status.",
"enum": [
"in-force",
"partly-in-force",
"superseded"
]
},
"limit": {
"type": "integer",
"description": "Maximum results, 1β50. Default 20.",
"minimum": 1,
"maximum": 50
}
},
"additionalProperties": false
}π’get_instrument(id)
Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulatorβs own URL and the date it was last re-read there.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Register id, e.g. \"rbi-cyber-2026-nbfc\" or \"sebi-cscrf\".",
"maxLength": 100
}
},
"required": [
"id"
],
"additionalProperties": false
}π’find_applicable_regulations(entity_class, listed, handles_personal_data)
Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions; RRBs and LABs have none, and the result says so.
Input Schema
{
"type": "object",
"properties": {
"entity_class": {
"type": "string",
"description": "The entityβs class.",
"enum": [
"commercial-bank",
"sfb",
"payments-bank",
"ucb",
"aifi",
"nbfc",
"cic",
"rrb",
"lab",
"sebi-re",
"insurer",
"ifsca-re",
"other"
]
},
"listed": {
"type": "boolean",
"description": "Listed on an Indian stock exchange (brings SEBI LODR disclosure)."
},
"handles_personal_data": {
"type": "boolean",
"description": "Processes digital personal data of individuals in India (brings DPDP)."
}
},
"required": [
"entity_class",
"listed",
"handles_personal_data"
],
"additionalProperties": false
}π’india_incident_reporting_deadlines(sector, rbi_class, nbfc_layer, sebi_broker_or_dp, ifsca_exempt, ...)
Every incident-reporting clock an Indian entity owes β CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP β each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.
Input Schema
{
"type": "object",
"properties": {
"sector": {
"type": "string",
"description": "Sectoral regulator, or \"none\".",
"enum": [
"rbi",
"sebi",
"irdai",
"ifsca",
"none"
]
},
"rbi_class": {
"type": "string",
"description": "Required when sector is \"rbi\".",
"enum": [
"commercial-bank",
"sfb",
"payments-bank",
"ucb",
"aifi",
"nbfc",
"cic"
]
},
"nbfc_layer": {
"type": "string",
"description": "For an NBFC: its layer under Scale-Based Regulation.",
"enum": [
"base-below-500",
"base-500-plus",
"middle-upper-top"
]
},
"sebi_broker_or_dp": {
"type": "boolean",
"description": "SEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories)."
},
"ifsca_exempt": {
"type": "boolean",
"description": "IFSCA RE inside either exemption tier of the 2025 Guidelines."
},
"ifsca_mii": {
"type": "boolean",
"description": "IFSC market infrastructure institution (stock exchange, clearing corporation, depository)."
},
"listed": {
"type": "boolean",
"description": "Listed on an Indian stock exchange."
},
"protected_system": {
"type": "boolean",
"description": "Operates a notified Protected System (brings NCIIPC)."
},
"personal_data": {
"type": "boolean",
"description": "The incident involves digital personal data."
},
"noticed_at": {
"type": "string",
"description": "Optional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30.",
"maxLength": 40
}
},
"required": [
"sector",
"listed",
"protected_system",
"personal_data"
],
"additionalProperties": false
}π’us_eu_incident_reporting_deadlines(sec, nydfs, us_bank, bank_service_provider, hipaa, ...)
Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.
Input Schema
{
"type": "object",
"properties": {
"sec": {
"type": "string",
"description": "SEC status.",
"enum": [
"none",
"domestic",
"fpi"
]
},
"nydfs": {
"type": "boolean",
"description": "Regulated by the New York DFS (23 NYCRR 500)."
},
"us_bank": {
"type": "boolean",
"description": "A US banking organisation under the 36-hour computer-security incident rule."
},
"bank_service_provider": {
"type": "boolean",
"description": "A bank service provider under the same rule."
},
"hipaa": {
"type": "string",
"description": "HIPAA role.",
"enum": [
"none",
"covered-entity",
"business-associate"
]
},
"ftc_safeguards": {
"type": "boolean",
"description": "A non-bank financial institution under the FTC Safeguards Rule."
},
"nis2": {
"type": "boolean",
"description": "An essential or important entity under NIS2."
},
"dora": {
"type": "string",
"description": "DORA status.",
"enum": [
"none",
"financial-entity",
"no-weekend-relief"
]
},
"gdpr": {
"type": "string",
"description": "GDPR role for the personal data involved.",
"enum": [
"none",
"controller",
"processor"
]
},
"cra_manufacturer": {
"type": "boolean",
"description": "A manufacturer of products with digital elements under the EU CRA."
},
"aware_at": {
"type": "string",
"description": "Optional. When the entity became aware, ISO 8601 with offset.",
"maxLength": 40
},
"decided_at": {
"type": "string",
"description": "Optional. When materiality/reportability/major classification was determined, ISO 8601 with offset.",
"maxLength": 40
}
},
"required": [
"sec",
"nydfs",
"us_bank",
"bank_service_provider",
"hipaa",
"ftc_safeguards",
"nis2",
"dora",
"gdpr",
"cra_manufacturer"
],
"additionalProperties": false
}π’find_global_cyber_regulations(india_operations, india_personal_data, india_listed, india_financial_regulated, sec, ...)
For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.
Input Schema
{
"type": "object",
"properties": {
"india_operations": {
"type": "boolean",
"description": "Operates in India."
},
"india_personal_data": {
"type": "boolean",
"description": "Processes digital personal data of individuals in India."
},
"india_listed": {
"type": "boolean",
"description": "Listed on an Indian stock exchange."
},
"india_financial_regulated": {
"type": "boolean",
"description": "Regulated by RBI, SEBI, IRDAI or IFSCA."
},
"sec": {
"type": "string",
"description": "SEC status.",
"enum": [
"none",
"domestic",
"fpi"
]
},
"nydfs": {
"type": "boolean",
"description": "Regulated by the New York DFS."
},
"us_bank": {
"type": "boolean",
"description": "US banking organisation."
},
"ftc_safeguards": {
"type": "boolean",
"description": "Non-bank financial institution under the FTC Safeguards Rule."
},
"hipaa": {
"type": "boolean",
"description": "Covered entity or business associate under HIPAA."
},
"us_personal_data": {
"type": "boolean",
"description": "Holds personal data of US residents."
},
"us_critical_infrastructure": {
"type": "boolean",
"description": "US critical-infrastructure sector."
},
"eu_personal_data": {
"type": "boolean",
"description": "Processes personal data of people in the EU."
},
"nis2_sector": {
"type": "string",
"description": "NIS2 sector annex.",
"enum": [
"none",
"annex-i",
"annex-ii"
]
},
"size": {
"type": "string",
"description": "Enterprise size.",
"enum": [
"small",
"medium",
"large"
]
},
"dora_financial_entity": {
"type": "boolean",
"description": "EU financial entity under DORA."
},
"ict_provider_to_eu_finance": {
"type": "boolean",
"description": "ICT third-party provider to EU financial entities."
},
"cra_manufacturer": {
"type": "boolean",
"description": "Manufacturer of products with digital elements sold in the EU."
}
},
"additionalProperties": false
}π’sebi_cscrf_category(entity_type, registered_clients, clientele_trading_volume, collateral_with_ccs, aum, ...)
Works out a SEBI regulated entityβs CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave uncategorised are reported as such, not guessed.
Input Schema
{
"type": "object",
"properties": {
"entity_type": {
"type": "string",
"description": "The SEBI entity type.",
"enum": [
"mii",
"stock-broker",
"proprietary-stock-broker",
"depository-participant",
"portfolio-manager",
"merchant-banker",
"aif-vcf-manager",
"mutual-fund-amc",
"custodian",
"rta",
"kra",
"investment-adviser",
"research-analyst",
"ddp",
"debenture-trustee",
"credit-rating-agency",
"collective-investment-scheme",
"banker-to-issue",
"excluded"
]
},
"registered_clients": {
"type": "number",
"description": "Figure for the \"registered-clients\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"clientele_trading_volume": {
"type": "number",
"description": "Figure for the \"clientele-trading-volume\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"collateral_with_ccs": {
"type": "number",
"description": "Figure for the \"collateral-with-ccs\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"aum": {
"type": "number",
"description": "Figure for the \"aum\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"corpus": {
"type": "number",
"description": "Figure for the \"corpus\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"auc": {
"type": "number",
"description": "Figure for the \"auc\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
},
"folios": {
"type": "number",
"description": "Figure for the \"folios\" criterion (see entity_type's required figures). βΉ crore values in crore; counts as plain numbers."
}
},
"required": [
"entity_type"
],
"additionalProperties": false
}π’india_threat_scorecard(edition)
Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.
Input Schema
{
"type": "object",
"properties": {
"edition": {
"type": "string",
"description": "Edition slug, YYYY-MM. Omit for the latest.",
"enum": [
"2026-08"
]
}
},
"additionalProperties": false
}Community
Evidence