For Category I REs, all incidents, including data breaches, data leaks, malicious activities affecting cloud computing, malicious code attacks, etc., along with the remedies taken, should be reported to CERT-IN and PFRDA on a quarterly basis. In addition to it, if an incident, which, in RE’s opinion, can affect subscribers or other stakeholders, it should be reported to PFRDA within 48 hours of the occurrence of any such incident. Besides, an annual compliance report should be sent to PFRDA within 30 days of the close of the FY.