Indian Cyber Regulation Register (BitScore)

Indian cyber regulation register and incident-reporting deadlines (India, US, EU), read at source.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
96%
Naming quality
85%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (2)

  • LOWTool 'india_incident_reporting_deadlines' name length outside 3-30 rangein india_incident_reporting_deadlines
  • LOWTool 'us_eu_incident_reporting_deadlines' name length outside 3-30 rangein us_eu_incident_reporting_deadlines

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,825Tokens (tool definitions)
~2.9 KBTypical response size
Significant attention impact (2.21% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "india-cyber-regulations": {
      "url": "https://www.bitscore.in/mcp"
    }
  }
}

Remote endpoints

https://www.bitscore.in/mcpstreamable-http

What it can do

Tool inventory

Tools (8)

🟒 Read-only🟑 WriteπŸ”΄ Deleteβšͺ Unknown
🟒search_instruments(query, issuer, status, limit)

Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one entry in full.

Input Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Words to match against the name, reference number and who it binds, e.g. \"outsourcing\", \"NBFC\", \"2024/113\".",
      "maxLength": 200
    },
    "issuer": {
      "type": "string",
      "description": "Only instruments from this issuer.",
      "enum": [
        "RBI",
        "SEBI",
        "IRDAI",
        "IFSCA",
        "CERT-In",
        "MeitY"
      ]
    },
    "status": {
      "type": "string",
      "description": "Only instruments with this status.",
      "enum": [
        "in-force",
        "partly-in-force",
        "superseded"
      ]
    },
    "limit": {
      "type": "integer",
      "description": "Maximum results, 1–50. Default 20.",
      "minimum": 1,
      "maximum": 50
    }
  },
  "additionalProperties": false
}
🟒get_instrument(id)

Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulator’s own URL and the date it was last re-read there.

Input Schema

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "Register id, e.g. \"rbi-cyber-2026-nbfc\" or \"sebi-cscrf\".",
      "maxLength": 100
    }
  },
  "required": [
    "id"
  ],
  "additionalProperties": false
}
🟒find_applicable_regulations(entity_class, listed, handles_personal_data)

Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions; RRBs and LABs have none, and the result says so.

Input Schema

{
  "type": "object",
  "properties": {
    "entity_class": {
      "type": "string",
      "description": "The entity’s class.",
      "enum": [
        "commercial-bank",
        "sfb",
        "payments-bank",
        "ucb",
        "aifi",
        "nbfc",
        "cic",
        "rrb",
        "lab",
        "sebi-re",
        "insurer",
        "ifsca-re",
        "other"
      ]
    },
    "listed": {
      "type": "boolean",
      "description": "Listed on an Indian stock exchange (brings SEBI LODR disclosure)."
    },
    "handles_personal_data": {
      "type": "boolean",
      "description": "Processes digital personal data of individuals in India (brings DPDP)."
    }
  },
  "required": [
    "entity_class",
    "listed",
    "handles_personal_data"
  ],
  "additionalProperties": false
}
🟒india_incident_reporting_deadlines(sector, rbi_class, nbfc_layer, sebi_broker_or_dp, ifsca_exempt, ...)

Every incident-reporting clock an Indian entity owes β€” CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP β€” each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.

Input Schema

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string",
      "description": "Sectoral regulator, or \"none\".",
      "enum": [
        "rbi",
        "sebi",
        "irdai",
        "ifsca",
        "none"
      ]
    },
    "rbi_class": {
      "type": "string",
      "description": "Required when sector is \"rbi\".",
      "enum": [
        "commercial-bank",
        "sfb",
        "payments-bank",
        "ucb",
        "aifi",
        "nbfc",
        "cic"
      ]
    },
    "nbfc_layer": {
      "type": "string",
      "description": "For an NBFC: its layer under Scale-Based Regulation.",
      "enum": [
        "base-below-500",
        "base-500-plus",
        "middle-upper-top"
      ]
    },
    "sebi_broker_or_dp": {
      "type": "boolean",
      "description": "SEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories)."
    },
    "ifsca_exempt": {
      "type": "boolean",
      "description": "IFSCA RE inside either exemption tier of the 2025 Guidelines."
    },
    "ifsca_mii": {
      "type": "boolean",
      "description": "IFSC market infrastructure institution (stock exchange, clearing corporation, depository)."
    },
    "listed": {
      "type": "boolean",
      "description": "Listed on an Indian stock exchange."
    },
    "protected_system": {
      "type": "boolean",
      "description": "Operates a notified Protected System (brings NCIIPC)."
    },
    "personal_data": {
      "type": "boolean",
      "description": "The incident involves digital personal data."
    },
    "noticed_at": {
      "type": "string",
      "description": "Optional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30.",
      "maxLength": 40
    }
  },
  "required": [
    "sector",
    "listed",
    "protected_system",
    "personal_data"
  ],
  "additionalProperties": false
}
🟒us_eu_incident_reporting_deadlines(sec, nydfs, us_bank, bank_service_provider, hipaa, ...)

Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.

Input Schema

{
  "type": "object",
  "properties": {
    "sec": {
      "type": "string",
      "description": "SEC status.",
      "enum": [
        "none",
        "domestic",
        "fpi"
      ]
    },
    "nydfs": {
      "type": "boolean",
      "description": "Regulated by the New York DFS (23 NYCRR 500)."
    },
    "us_bank": {
      "type": "boolean",
      "description": "A US banking organisation under the 36-hour computer-security incident rule."
    },
    "bank_service_provider": {
      "type": "boolean",
      "description": "A bank service provider under the same rule."
    },
    "hipaa": {
      "type": "string",
      "description": "HIPAA role.",
      "enum": [
        "none",
        "covered-entity",
        "business-associate"
      ]
    },
    "ftc_safeguards": {
      "type": "boolean",
      "description": "A non-bank financial institution under the FTC Safeguards Rule."
    },
    "nis2": {
      "type": "boolean",
      "description": "An essential or important entity under NIS2."
    },
    "dora": {
      "type": "string",
      "description": "DORA status.",
      "enum": [
        "none",
        "financial-entity",
        "no-weekend-relief"
      ]
    },
    "gdpr": {
      "type": "string",
      "description": "GDPR role for the personal data involved.",
      "enum": [
        "none",
        "controller",
        "processor"
      ]
    },
    "cra_manufacturer": {
      "type": "boolean",
      "description": "A manufacturer of products with digital elements under the EU CRA."
    },
    "aware_at": {
      "type": "string",
      "description": "Optional. When the entity became aware, ISO 8601 with offset.",
      "maxLength": 40
    },
    "decided_at": {
      "type": "string",
      "description": "Optional. When materiality/reportability/major classification was determined, ISO 8601 with offset.",
      "maxLength": 40
    }
  },
  "required": [
    "sec",
    "nydfs",
    "us_bank",
    "bank_service_provider",
    "hipaa",
    "ftc_safeguards",
    "nis2",
    "dora",
    "gdpr",
    "cra_manufacturer"
  ],
  "additionalProperties": false
}
🟒find_global_cyber_regulations(india_operations, india_personal_data, india_listed, india_financial_regulated, sec, ...)

For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.

Input Schema

{
  "type": "object",
  "properties": {
    "india_operations": {
      "type": "boolean",
      "description": "Operates in India."
    },
    "india_personal_data": {
      "type": "boolean",
      "description": "Processes digital personal data of individuals in India."
    },
    "india_listed": {
      "type": "boolean",
      "description": "Listed on an Indian stock exchange."
    },
    "india_financial_regulated": {
      "type": "boolean",
      "description": "Regulated by RBI, SEBI, IRDAI or IFSCA."
    },
    "sec": {
      "type": "string",
      "description": "SEC status.",
      "enum": [
        "none",
        "domestic",
        "fpi"
      ]
    },
    "nydfs": {
      "type": "boolean",
      "description": "Regulated by the New York DFS."
    },
    "us_bank": {
      "type": "boolean",
      "description": "US banking organisation."
    },
    "ftc_safeguards": {
      "type": "boolean",
      "description": "Non-bank financial institution under the FTC Safeguards Rule."
    },
    "hipaa": {
      "type": "boolean",
      "description": "Covered entity or business associate under HIPAA."
    },
    "us_personal_data": {
      "type": "boolean",
      "description": "Holds personal data of US residents."
    },
    "us_critical_infrastructure": {
      "type": "boolean",
      "description": "US critical-infrastructure sector."
    },
    "eu_personal_data": {
      "type": "boolean",
      "description": "Processes personal data of people in the EU."
    },
    "nis2_sector": {
      "type": "string",
      "description": "NIS2 sector annex.",
      "enum": [
        "none",
        "annex-i",
        "annex-ii"
      ]
    },
    "size": {
      "type": "string",
      "description": "Enterprise size.",
      "enum": [
        "small",
        "medium",
        "large"
      ]
    },
    "dora_financial_entity": {
      "type": "boolean",
      "description": "EU financial entity under DORA."
    },
    "ict_provider_to_eu_finance": {
      "type": "boolean",
      "description": "ICT third-party provider to EU financial entities."
    },
    "cra_manufacturer": {
      "type": "boolean",
      "description": "Manufacturer of products with digital elements sold in the EU."
    }
  },
  "additionalProperties": false
}
🟒sebi_cscrf_category(entity_type, registered_clients, clientele_trading_volume, collateral_with_ccs, aum, ...)

Works out a SEBI regulated entity’s CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave uncategorised are reported as such, not guessed.

Input Schema

{
  "type": "object",
  "properties": {
    "entity_type": {
      "type": "string",
      "description": "The SEBI entity type.",
      "enum": [
        "mii",
        "stock-broker",
        "proprietary-stock-broker",
        "depository-participant",
        "portfolio-manager",
        "merchant-banker",
        "aif-vcf-manager",
        "mutual-fund-amc",
        "custodian",
        "rta",
        "kra",
        "investment-adviser",
        "research-analyst",
        "ddp",
        "debenture-trustee",
        "credit-rating-agency",
        "collective-investment-scheme",
        "banker-to-issue",
        "excluded"
      ]
    },
    "registered_clients": {
      "type": "number",
      "description": "Figure for the \"registered-clients\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "clientele_trading_volume": {
      "type": "number",
      "description": "Figure for the \"clientele-trading-volume\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "collateral_with_ccs": {
      "type": "number",
      "description": "Figure for the \"collateral-with-ccs\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "aum": {
      "type": "number",
      "description": "Figure for the \"aum\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "corpus": {
      "type": "number",
      "description": "Figure for the \"corpus\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "auc": {
      "type": "number",
      "description": "Figure for the \"auc\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    },
    "folios": {
      "type": "number",
      "description": "Figure for the \"folios\" criterion (see entity_type's required figures). β‚Ή crore values in crore; counts as plain numbers."
    }
  },
  "required": [
    "entity_type"
  ],
  "additionalProperties": false
}
🟒india_threat_scorecard(edition)

Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.

Input Schema

{
  "type": "object",
  "properties": {
    "edition": {
      "type": "string",
      "description": "Edition slug, YYYY-MM. Omit for the latest.",
      "enum": [
        "2026-08"
      ]
    }
  },
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded8 tools