Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · CERT-In

CERT-In Directions compliance and incident reporting

The Indian Computer Emergency Response Team (CERT-In) issued directions in April 2022 to improve how cyber incidents are reported and investigated in India. They apply widely — not only to regulated financial entities.

Overview

In plain English

The best-known requirement is reporting specified cyber incidents to CERT-In within 6 hours of noticing them. Meeting it depends on preparation: logs, clear roles and a reporting playbook ready before an incident happens.

Instruments covered

  • Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 — dated 28 April 2022

Last reviewed:

Key requirements

What CERT-In expects

  1. 6-hour incident reporting

    Report the types of cyber incidents listed in the Directions to CERT-In within 6 hours of noticing them or being told about them.

  2. 180-day log retention

    Enable logs of ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction.

  3. Time synchronisation

    Synchronise ICT system clocks with the NTP servers of NIC or NPL, or servers traceable to them.

  4. Point of contact

    Designate a point of contact to liaise with CERT-In and share their details.

  5. Provide information on request

    Share information and assistance with CERT-In when directed, within the time it specifies.

  6. Additional provider obligations

    Data centres, VPS, cloud and VPN providers, and virtual asset service providers have further record-keeping obligations.

How TrustNet helps

From gap to evidence

  • 6-hour reporting playbook with templates and roles
  • 180-day log retention design and review
  • NTP synchronisation checks
  • Point-of-contact setup and runbook
  • Incident reporting support when an incident happens

Official sources

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to CERT-In

FAQ

CERT-In FAQ

What is the CERT-In 6-hour rule?

Covered entities must report specified types of cyber incidents to CERT-In within 6 hours of noticing them or being made aware of them.

Do CERT-In Directions apply to small companies?

They apply broadly to service providers, intermediaries, data centres, body corporates and government organisations. Most businesses operating in India should assume they are covered and check the details.

Where must logs be stored?

The Directions require logs to be maintained within Indian jurisdiction for a rolling period of 180 days.

Book a consultation

Get CERT-In-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us