Skip to main content

Blog

Plain-English writing on the obligations we work with, grounded in the primary sources.

India

CERT-In's 6-hour rule, explained

India requires cyber incidents to be reported to CERT-In within 6 hours. Who it binds, when the clock actually starts, what counts as reportable, and the localisation myth.

US

FDA §524B in plain English

What FDA's cybersecurity law actually requires for a 510(k) or PMA: who it applies to, the four obligations, and what happens if the cybersecurity section is incomplete.