Resources · Playbooks
The 6-hour clock: incident reporting under CSCRF, step by step
From detection to notification inside SEBI's six-hour window: what to prepare before the incident, and what the record must show after it.
Six hours is short. It is short enough that the report cannot be written during the incident, it must be assembled from a record that already exists. That is the design principle: the incident record builds the report as the response happens.
Before the incident: decide what detection means, who declares an incident, and which categories are reportable. Put those definitions in the workflow, not in a PDF. During: the clock starts at noticing, every action is timestamped, and the notification content, nature, impact, actions taken, is captured on the record as fields, not prose.
After: the timestamps are the defence. When SEBI asks why notification took the time it took, the answer is the incident record itself, detection time, declaration time, notification time, not a reconstruction written a week later.
Reviewed September 2026.
See it working on your data
Everything in this article runs live in a proof of concept: your frameworks, your evidence, your vendors.
