CERT-In is India's national cyber-incident agency — and its rules give every business just six hours to report an attack once you notice it. Here's what that means, who it applies to, and how to be ready before it happens — in plain words.
Not true — and it catches people out. CERT-In's rules apply to virtually every organisation running digital systems in India: companies, service providers, data centres, government bodies — and even foreign firms serving Indian customers. If you have email, a website, or customer data, the six-hour clock applies to you too.
A finance server starts sending odd traffic late on a Sunday. Your team wants to wait for Monday's sign-off from legal and leadership. But the six-hour window opened the moment someone noticed — and it's already running.
To report, you need to say what happened and what was hit. But firewall logs are in one tool, email logs in another, cloud logs somewhere else — and stitching them together burns the very hours you don't have.
Was that an incident, or a near-miss? If your team has to debate the definition each time, you lose an hour to arguing instead of acting — and a genuine incident slips past the deadline.
An alert, a ticket, or a tip-off. The clock starts here — at awareness, not at proof.
Is it reportable? A ready severity matrix answers this in minutes, not meetings.
Limit the damage and pull the facts — affected systems, timeline, actions taken.
File the initial report to CERT-In in the prescribed format. Updates can follow.
All under Section 70B of the IT Act and the CERT-In Directions of 28 April 2022.
Report any of 20 categories of cyber incident within six hours of noticing it.
Retain logs of all ICT systems for 180 days, stored within Indian jurisdiction.
Sync system clocks to NIC/NPL time servers so incident timestamps line up.
Designate a person to interface with CERT-In and receive its directions.
Use CERT-In's format (Annexure A) — reporter, timeline, impact, actions taken.
VPN, cloud, data-centre & virtual-asset providers keep KYC and records for five years.
Companies & body corporatesAny business running digital systems in India.
Service providers & intermediariesIncluding cloud, hosting, VPN, and data centres.
Government organisationsCentral, state, and public-sector bodies.
Foreign firms serving IndiaIf you serve Indian customers, you're in scope too.
The bigger cost is rarely the fine. Missing the six-hour window signals to regulators, insurers, and enterprise clients that your incident-handling isn't in order — and that's what loses contracts and trust.
CERT-In established as India's national cyber-incident agency.
Incident reporting required — but only "within a reasonable time."
The six-hour rule, 180-day logs, and 20 incident types introduced.
Directions become binding on all covered entities — and remain so today.
Most can't — not because they lack tools, but because the process has never been tested. Our CERT-In readiness assessment sets up your logging, point of contact, severity matrix, and a rehearsed six-hour workflow, so a bad day doesn't become a compliance failure too.
Sources: CERT-In Directions dated 28 April 2022 (No. 20(3)/2022-CERT-In), effective 28 June 2022, under Section 70B of the Information Technology Act, 2000. Proposed penalty increase per the Jan Vishwas (Amendment) Bill, 2023 (not yet in force as reviewed). This page is general information, not legal advice.