MCP 서버

Indian Cyber Regulation Register (BitScore)

io.github.nimitt-IN/india-cyber-regulations
법률 및 컴플라이언스 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Searches Indian, US, and EU cyber and data-protection regulations, including applicability, incident-reporting deadlines, obligations, and threat summaries.

find_applicable_regulations
Which Indian cyber regulations apply to an entity
Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions; RRBs and LABs have none, and the result says so.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['entity_class', 'listed', 'handles_personal_data'], 'properties': {'listed': {'type': 'boolean', 'description': 'Listed on an Indian stock exchange (brings SEBI LODR disclosure).'}, 'entity_class': {'enum': ['commercial-bank', 'sfb', 'payments-bank', 'ucb', 'aifi', 'nbfc', 'cic', 'rrb', 'lab', 'sebi-re', 'insurer', 'ifsca-re', 'other'], 'type': 'string', 'description': 'The entity’s class.'}, 'handles_personal_data': {'type': 'boolean', 'description': 'Processes digital personal data of individuals in India (brings DPDP).'}}, 'additionalProperties': False}
find_global_cyber_regulations
Which cyber regulations apply across India, the US and the EU
For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'sec': {'enum': ['none', 'domestic', 'fpi'], 'type': 'string', 'description': 'SEC status.'}, 'size': {'enum': ['small', 'medium', 'large'], 'type': 'string', 'description': 'Enterprise size.'}, 'hipaa': {'type': 'boolean', 'description': 'Covered entity or business associate under HIPAA.'}, 'nydfs': {'type': 'boolean', 'description': 'Regulated by the New York DFS.'}, 'us_bank': {'type': 'boolean', 'description': 'US banking organisation.'}, 'nis2_sector': {'enum': ['none', 'annex-i', 'annex-ii'], 'type': 'string', 'description': 'NIS2 sector annex.'}, 'india_listed': {'type': 'boolean', 'description': 'Listed on an Indian stock exchange.'}, 'ftc_safeguards': {'type': 'boolean', 'description': 'Non-bank financial institution under the FTC Safeguards Rule.'}, 'cra_manufacturer': {'type': 'boolean', 'description': 'Manufacturer of products with digital elements sold in the EU.'}, 'eu_personal_data': {'type': 'boolean', 'description': 'Processes personal data of people in the EU.'}, 'india_operations': {'type': 'boolean', 'description': 'Operates in India.'}, 'us_personal_data': {'type': 'boolean', 'description': 'Holds personal data of US residents.'}, 'india_personal_data': {'type': 'boolean', 'description': 'Processes digital personal data of individuals in India.'}, 'dora_financial_entity': {'type': 'boolean', 'description': 'EU financial entity under DORA.'}, 'india_financial_regulated': {'type': 'boolean', 'description': 'Regulated by RBI, SEBI, IRDAI or IFSCA.'}, 'ict_provider_to_eu_finance': {'type': 'boolean', 'description': 'ICT third-party provider to EU financial entities.'}, 'us_critical_infrastructure': {'type': 'boolean', 'description': 'US critical-infrastructure sector.'}}, 'additionalProperties': False}
get_instrument
Get one instrument from the register
Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulator’s own URL and the date it was last re-read there.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'maxLength': 100, 'description': 'Register id, e.g. "rbi-cyber-2026-nbfc" or "sebi-cscrf".'}}, 'additionalProperties': False}
india_incident_reporting_deadlines
Indian cyber incident reporting deadlines
Every incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['sector', 'listed', 'protected_system', 'personal_data'], 'properties': {'listed': {'type': 'boolean', 'description': 'Listed on an Indian stock exchange.'}, 'sector': {'enum': ['rbi', 'sebi', 'irdai', 'ifsca', 'none'], 'type': 'string', 'description': 'Sectoral regulator, or "none".'}, 'ifsca_mii': {'type': 'boolean', 'description': 'IFSC market infrastructure institution (stock exchange, clearing corporation, depository).'}, 'rbi_class': {'enum': ['commercial-bank', 'sfb', 'payments-bank', 'ucb', 'aifi', 'nbfc', 'cic'], 'type': 'string', 'description': 'Required when sector is "rbi".'}, 'nbfc_layer': {'enum': ['base-below-500', 'base-500-plus', 'middle-upper-top'], 'type': 'string', 'description': 'For an NBFC: its layer under Scale-Based Regulation.'}, 'noticed_at': {'type': 'string', 'maxLength': 40, 'description': 'Optional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30.'}, 'ifsca_exempt': {'type': 'boolean', 'description': 'IFSCA RE inside either exemption tier of the 2025 Guidelines.'}, 'personal_data': {'type': 'boolean', 'description': 'The incident involves digital personal data.'}, 'protected_system': {'type': 'boolean', 'description': 'Operates a notified Protected System (brings NCIIPC).'}, 'sebi_broker_or_dp': {'type': 'boolean', 'description': 'SEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories).'}}, 'additionalProperties': False}
india_threat_scorecard
India Cyber Threat Scorecard
Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'edition': {'enum': ['2026-09', '2026-08'], 'type': 'string', 'description': 'Edition slug, YYYY-MM. Omit for the latest.'}}, 'additionalProperties': False}
search_instruments
Search the Indian cyber regulation register
Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one entry in full.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Maximum results, 1–50. Default 20.'}, 'query': {'type': 'string', 'maxLength': 200, 'description': 'Words to match against the name, reference number and who it binds, e.g. "outsourcing", "NBFC", "2024/113".'}, 'issuer': {'enum': ['RBI', 'SEBI', 'IRDAI', 'IFSCA', 'CERT-In', 'MeitY'], 'type': 'string', 'description': 'Only instruments from this issuer.'}, 'status': {'enum': ['in-force', 'partly-in-force', 'superseded'], 'type': 'string', 'description': 'Only instruments with this status.'}}, 'additionalProperties': False}
sebi_cscrf_category
SEBI CSCRF category for a regulated entity
Works out a SEBI regulated entity’s CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave uncategorised are reported as such, not guessed.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['entity_type'], 'properties': {'auc': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "auc" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'aum': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "aum" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'corpus': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "corpus" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'folios': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "folios" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'entity_type': {'enum': ['mii', 'stock-broker', 'proprietary-stock-broker', 'depository-participant', 'portfolio-manager', 'merchant-banker', 'aif-vcf-manager', 'mutual-fund-amc', 'custodian', 'rta', 'kra', 'investment-adviser', 'research-analyst', 'ddp', 'debenture-trustee', 'credit-rating-agency', 'collective-investment-scheme', 'banker-to-issue', 'excluded'], 'type': 'string', 'description': 'The SEBI entity type.'}, 'registered_clients': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "registered-clients" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'collateral_with_ccs': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "collateral-with-ccs" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}, 'clientele_trading_volume': {'type': 'number', 'minimum': 0, 'description': 'Figure for the "clientele-trading-volume" criterion (see entity_type\'s required figures). ₹ crore values in crore; counts as plain numbers.'}}, 'additionalProperties': False}
us_eu_incident_reporting_deadlines
US and EU cyber incident reporting deadlines
Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['sec', 'nydfs', 'us_bank', 'bank_service_provider', 'hipaa', 'ftc_safeguards', 'nis2', 'dora', 'gdpr', 'cra_manufacturer'], 'properties': {'sec': {'enum': ['none', 'domestic', 'fpi'], 'type': 'string', 'description': 'SEC status.'}, 'dora': {'enum': ['none', 'financial-entity', 'no-weekend-relief'], 'type': 'string', 'description': 'DORA status.'}, 'gdpr': {'enum': ['none', 'controller', 'processor'], 'type': 'string', 'description': 'GDPR role for the personal data involved.'}, 'nis2': {'type': 'boolean', 'description': 'An essential or important entity under NIS2.'}, 'hipaa': {'enum': ['none', 'covered-entity', 'business-associate'], 'type': 'string', 'description': 'HIPAA role.'}, 'nydfs': {'type': 'boolean', 'description': 'Regulated by the New York DFS (23 NYCRR 500).'}, 'us_bank': {'type': 'boolean', 'description': 'A US banking organisation under the 36-hour computer-security incident rule.'}, 'aware_at': {'type': 'string', 'maxLength': 40, 'description': 'Optional. When the entity became aware, ISO 8601 with offset.'}, 'decided_at': {'type': 'string', 'maxLength': 40, 'description': 'Optional. When materiality/reportability/major classification was determined, ISO 8601 with offset.'}, 'ftc_safeguards': {'type': 'boolean', 'description': 'A non-bank financial institution under the FTC Safeguards Rule.'}, 'cra_manufacturer': {'type': 'boolean', 'description': 'A manufacturer of products with digital elements under the EU CRA.'}, 'bank_service_provider': {'type': 'boolean', 'description': 'A bank service provider under the same rule.'}}, 'additionalProperties': False}
변경됨
india_threat_scorecard
2026년 10월 1일 2:40 AM
변경됨
sebi_cscrf_category
2026년 10월 1일 2:40 AM
추가됨
india_threat_scorecard
2026년 9월 29일 2:40 AM
추가됨
sebi_cscrf_category
2026년 9월 29일 2:40 AM
추가됨
find_global_cyber_regulations
2026년 9월 29일 2:40 AM
추가됨
us_eu_incident_reporting_deadlines
2026년 9월 29일 2:40 AM
추가됨
india_incident_reporting_deadlines
2026년 9월 29일 2:40 AM
추가됨
find_applicable_regulations
2026년 9월 29일 2:40 AM
추가됨
get_instrument
2026년 9월 29일 2:40 AM
추가됨
search_instruments
2026년 9월 29일 2:40 AM