Compliance & Risk Advisory
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →The Indian Computer Emergency Response Team (CERT-In) issued directions in April 2022 to improve how cyber incidents are reported and investigated in India. They apply widely — not only to regulated financial entities.
The best-known requirement is reporting specified cyber incidents to CERT-In within 6 hours of noticing them. Meeting it depends on preparation: logs, clear roles and a reporting playbook ready before an incident happens.
Report the types of cyber incidents listed in the Directions to CERT-In within 6 hours of noticing them or being told about them.
Enable logs of ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction.
Synchronise ICT system clocks with the NTP servers of NIC or NPL, or servers traceable to them.
Designate a point of contact to liaise with CERT-In and share their details.
Share information and assistance with CERT-In when directed, within the time it specifies.
Data centres, VPS, cloud and VPN providers, and virtual asset service providers have further record-keeping obligations.
Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →Call us when it matters: triage, containment, recovery and regulator reporting support.
Learn more about 24/7 Incident Response →24/7 SIEM and EDR monitoring, threat hunting and dark-web monitoring for your environment.
Learn more about Managed Security Monitoring (SOC/MDR) →Covered entities must report specified types of cyber incidents to CERT-In within 6 hours of noticing them or being made aware of them.
They apply broadly to service providers, intermediaries, data centres, body corporates and government organisations. Most businesses operating in India should assume they are covered and check the details.
The Directions require logs to be maintained within Indian jurisdiction for a rolling period of 180 days.
We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.
support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438
Under attack right now? Go to emergency help →
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
Source: The Hacker News — headlines only, each linking to the original article.