Skip to content
Back to Blog
·9 min read·compliance

Sectoral CERTs and CSIRT-Fin: India's Incident Reporting Guide

Learn which body to report a cyber incident to in India — CERT-In, RBI, SEBI, CSIRT-Fin, or DoT — and how these reporting obligations stack up by sector.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

If your business suffers a cyber incident in India, CERT-In is not always the only body you must notify — which one depends on your sector. Banks and NBFCs report to the Reserve Bank of India, securities-market entities report to SEBI, telecom licensees report to the Department of Telecommunications, and every other organisation reports to CERT-In — while CSIRT-Fin, a nodal CSIRT under CERT-In, coordinates incident response across the wider financial sector (banking, securities, insurance, and pension). Knowing which regulator applies to you — and reporting to CERT-In in every case regardless of sector — is a compliance obligation, not an optional courtesy.

CERT-In: the national nodal agency

The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology (MeitY), is designated under the Information Technology Act, 2000 as the national agency for responding to cybersecurity incidents. CERT-In's mandate covers collecting, analysing, and disseminating information on cyber incidents; issuing alerts and advisories; and — most relevant to businesses — receiving mandatory incident reports from a wide range of entities under its 2022 cybersecurity directions.

CERT-In's role is deliberately broad: it is the default reporting destination for any Indian organisation experiencing a significant cyber incident, and it also functions as the coordinating hub that sectoral CERTs and CSIRTs plug into. Full details of what must be reported, and how, are published at cert-in.org.in.

ℹ️
INFO
A "sectoral CERT" or "sectoral CSIRT" does not replace CERT-In reporting — it sits alongside it. Regulated entities in banking, securities, or telecom typically have obligations to both their sector regulator and to CERT-In. Skipping the CERT-In leg because you already reported to your sector regulator is a common, avoidable mistake.

Why sectoral bodies exist at all

A single national CERT cannot realistically hold the domain expertise needed to assess incident severity across every sector — a fraudulent NEFT transaction pattern at a bank looks nothing like a manipulated order-flow anomaly at a stock exchange, and neither resembles a SIM-swap wave at a telecom operator. India's regulatory response has been to let domain regulators — RBI for banking, SEBI for securities, DoT for telecom — build sector-specific incident-reporting and response capability, while CERT-In retains the national coordinating role and the authority under the IT Act to require reporting from any entity.

This is a common pattern internationally: national CERTs paired with sector-specific CSIRTs is how many mature cyber-incident ecosystems are structured, because sector regulators already have the supervisory relationship, the domain context, and in some cases the enforcement teeth to act on what they learn from an incident report.

CSIRT-Fin: the financial sector's nodal CSIRT

CSIRT-Fin (Computer Security Incident Response Team for the Financial Sector) is a nodal sectoral CSIRT that sits under CERT-In and MeitY, set up with the Department of Economic Affairs and Department of Financial Services, Ministry of Finance. It is not a SEBI body and it is not limited to the securities market — its mandate spans the whole financial sector (banking, securities, insurance, and pension), and it coordinates incident prevention and response with all four financial regulators: RBI, SEBI, IRDAI, and PFRDA.

For a securities-market entity specifically, SEBI remains the direct sector regulator with supervisory authority, and it publishes its own cybersecurity and cyber-resilience framework circulars setting out incident-reporting expectations for regulated market entities — stock exchanges, depositories, clearing corporations, stockbrokers, mutual funds, and other SEBI-regulated intermediaries. CSIRT-Fin sits alongside that relationship as a coordinating layer feeding into CERT-In, rather than as a body SEBI runs itself. In practice, a securities-market entity reports incident details to SEBI as its direct regulator, with the same incident also reportable to CERT-In under the IT Act — CSIRT-Fin coordinates in the background. SEBI publishes its cybersecurity and cyber-resilience framework requirements at sebi.gov.in.

💡
TIP
If your business is a SEBI-registered intermediary — a broker, portfolio manager, investment adviser, or mutual fund — check your specific SEBI circular for the applicable cybersecurity and cyber-resilience framework. Reporting timelines and formats are set by SEBI for your registration category, and generic "report to CERT-In" guidance does not substitute for that sector-specific obligation.
graph TD A[Cyber incident detected] --> B{What sector is the entity in} B -->|Bank or NBFC| C[Report to RBI] B -->|Securities market entity| D[Report to SEBI] B -->|Telecom licensee| E[Report to DoT] B -->|Any other sector| F[Report to CERT-In only] C --> CF[Financial sector routes through CSIRT-Fin] D --> CF CF --> G[Also report to CERT-In] E --> G G --> H[CERT-In coordinates national response] style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style D fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style E fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style F fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style CF fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style G fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style H fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

RBI: banking and NBFC incident reporting

The Reserve Bank of India requires regulated entities — scheduled commercial banks, cooperative banks, and non-banking financial companies (NBFCs) above applicable thresholds — to report cybersecurity incidents through its supervisory and cyber-security frameworks. RBI has, over successive circulars and master directions, built out expectations around board-level cybersecurity oversight, incident reporting timelines, and cyber-resilience frameworks specific to the banking and NBFC sector. Full current requirements are published at rbi.org.in.

As with SEBI-regulated securities-market entities, RBI reporting for a bank or NBFC does not remove the separate obligation to report significant incidents to CERT-In under the IT Act framework — the two run in parallel, addressed to different regulators with different statutory bases.

DoT: telecom sector incident reporting

Telecom licensees — internet service providers, telecom operators, and related licensed entities — have incident-reporting obligations to the Department of Telecommunications (DoT) as their sector regulator, tied to their telecom licence conditions and security requirements. This sits alongside, not instead of, CERT-In reporting for the same incident where CERT-In's economy-wide mandate applies.

⚠️
WARNING
A common failure mode for regulated businesses is treating sector-regulator reporting and CERT-In reporting as interchangeable. They are governed by different instruments — licence conditions or RBI/SEBI directions on one side, the IT Act and CERT-In's 2022 directions on the other — and satisfying one does not automatically satisfy the other. Build both into your incident-response runbook explicitly.

Which body applies to you — a practical breakdown

Most Indian businesses fall into one of a small number of buckets. This table is a starting orientation, not a substitute for checking the current circular that applies to your specific registration or licence category.

Your business typePrimary sector regulatorAlso report to
Bank or NBFCRBICERT-In
Stock exchange, depository, clearing corporation, broker, mutual fund, other SEBI-registered intermediarySEBICERT-In
Telecom licensee, ISPDoTCERT-In
E-commerce, SaaS, IT services, healthtech, and most other unregulated-sector businessesCERT-In
Government / critical information infrastructure entitySector-specific CII authority where designatedCERT-In (and NCIIPC where applicable)
CSIRT-Fin isn't its own row above — it's the nodal CSIRT under CERT-In that coordinates across the RBI and SEBI rows (and, more broadly, insurance and pension).
2022Year CERT-In issued its current cybersecurity incident-reporting directions (CERT-In 2022)
6Hours-scale reporting window CERT-In directions set for specified categories of significant incidents (CERT-In 2022)
🛡️
SECURITY
If you're unsure whether your organisation falls under a sectoral reporting obligation, the safe default is to treat CERT-In reporting as mandatory for any significant incident, and separately confirm with your legal or compliance advisor whether an additional sector-regulator obligation applies. Under-reporting is the higher-risk failure mode.

Sectoral coverage across India's incident-reporting ecosystem

The chart below is a qualitative illustration of how sector-specific reporting authority is distributed across CERT-In's economy-wide mandate and the sector regulators layered on top of it — not a precise measure of incident volume or entity count, which is not publicly published in a directly comparable form across these bodies. CSIRT-Fin cuts across the RBI and SEBI slices below rather than being its own segment.

pie title Sectoral incident-reporting coverage in India "CERT-In - all sectors baseline" : 40 "RBI - banking and NBFC" : 25 "SEBI - securities market" : 20 "DoT - telecom" : 15

Building this into your incident-response process

For most Indian businesses, the practical takeaway is not "know the entire regulatory map" — it's knowing your own sector's obligation cold, before an incident happens, so a stressful moment doesn't turn into a missed statutory deadline. A workable process looks like:

  1. Identify your applicable regulator(s) at onboarding or annual compliance review — don't leave this discovery to incident day.
  2. Document the reporting channel and expected timeline for each applicable body (CERT-In, and RBI, SEBI, or DoT if relevant) inside your incident-response plan.
  3. Assign an owner — usually your CISO, compliance lead, or, for smaller businesses, the founder or designated IT lead — responsible for triggering both the sector-regulator and CERT-In reports.
  4. Rehearse it. A tabletop exercise that walks through "who do we call" for a plausible incident scenario surfaces gaps in contact details and ownership long before a real breach does.
  5. Keep the technical and reporting workstreams separate but parallel — forensic containment should not wait on reporting-obligation research, and vice versa.
🎯Key Takeaway
CERT-In is India's national, economy-wide incident-reporting authority, but banking, securities, and telecom businesses carry an additional, parallel obligation to their sector regulator — RBI, SEBI, or DoT respectively — with CSIRT-Fin coordinating response across the financial sector under CERT-In. Reporting to your sector regulator does not substitute for reporting to CERT-In, and vice versa; both need a named owner and a documented process in your incident-response plan before an incident happens.

Where technical readiness fits in

Regulatory reporting obligations only get invoked once an incident is detected — and detection depends on having enough visibility into your own attack surface to notice something has gone wrong. A structured vulnerability assessment surfaces the exposed services, misconfigurations, and weak points that are most likely to be exploited in the first place, which is a prerequisite for reducing how often you need to exercise any of this reporting machinery at all. If your organisation hasn't had its external attack surface independently reviewed, a free VAPT scan is a practical starting point, and for regulated entities that need a formal, empanelled sign-off, that work can be delivered with a CERT-In empanelled partner.

Businesses that also process personal data as part of their operations should review their separate obligations under India's data protection law — see our DPDP compliance guide for what applies. Dhisattva AI Pvt Ltd built Bachao.AI to make the technical half of cyber-risk readiness accessible to Indian businesses that don't have a dedicated security team to track every regulator's requirements alone.

For more guides on India's cybersecurity compliance landscape, visit the Bachao.AI blog.

Frequently Asked Questions

Do I report a cyber incident to CERT-In or to my sector regulator?
Both, if you're in a regulated sector. CERT-In is India's national reporting authority under the IT Act and applies to virtually every organisation, while banks/NBFCs (RBI), securities-market entities (SEBI), and telecom licensees (DoT) carry an additional, parallel reporting obligation to their sector regulator — with CSIRT-Fin coordinating incident response across the wider financial sector under CERT-In. One does not replace the other.
What is CSIRT-Fin and who does it apply to?
CSIRT-Fin is the nodal sectoral CSIRT for India's financial sector, operating under CERT-In and MeitY in coordination with the Department of Economic Affairs and Department of Financial Services. It is not run by SEBI and it is not securities-only — its mandate spans banking, securities, insurance, and pension, coordinating with RBI, SEBI, IRDAI, and PFRDA. A securities-market entity's direct reporting relationship is with SEBI; CSIRT-Fin and CERT-In sit on top as coordinating and national-reporting layers.
My business is a SaaS company with no financial, telecom, or banking licence — who do I report to?
CERT-In. Most unregulated-sector businesses — SaaS, e-commerce, IT services, healthtech, and similar — have their incident-reporting obligation run through CERT-In alone, since there is no additional sector regulator layered on top for that industry.
Does reporting to RBI, SEBI, or DoT satisfy my CERT-In obligation automatically?
No. These are separate reporting relationships governed by different legal instruments — sector licence conditions or regulator directions on one side, CERT-In's IT Act-based directions on the other. Treat them as two distinct checklist items in your incident-response plan, not one.
Where can I find the authoritative, current requirements for CERT-In and SEBI reporting?
CERT-In publishes its directions, advisories, and CSIRT-Fin's mandate at cert-in.org.in, and SEBI publishes its own cybersecurity and cyber-resilience framework circulars for regulated market entities at sebi.gov.in. Always check the current circular for your specific registration category rather than relying on general guidance.
How quickly does a significant incident need to be reported?
CERT-In's published directions set out a reporting window measured in hours for specified categories of significant incidents — check the current CERT-In directions at cert-in.org.in for the exact timeline and incident categories that trigger it, since this is updated periodically and precision matters for compliance.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →