CERT-In, explained for everyone

When a breach hits, the clock starts. You have six hours.

CERT-In is India's national cyber-incident agency — and its rules give every business just six hours to report an attack once you notice it. Here's what that means, who it applies to, and how to be ready before it happens — in plain words.

✔ Verified against CERT-In Directions (28 Apr 2022) & Section 70B, IT Act · Last reviewed 12 Jul 2026
6 HOURS TO REPORT NOTICE 3h DEADLINE
0 hrs
To report, from noticing
0 days
Log retention, within India
0
Reportable incident types
Every
Business serving India
✕

"CERT-In is only for IT and telecom giants."

Not true — and it catches people out. CERT-In's rules apply to virtually every organisation running digital systems in India: companies, service providers, data centres, government bodies — and even foreign firms serving Indian customers. If you have email, a website, or customer data, the six-hour clock applies to you too.

Six hours. The world's tightest deadline.

How long you have to report a serious cyber incident, by regime
India · CERT-Infrom noticing
6h
EU · GDPRfrom awareness
72 hours
US · CIRCIAcovered entities
72 hours
In plain words: where Europe and the US give businesses three days to report an attack, India gives you six hours — twelve times less time. That's not a deadline you can meet by scrambling; it only works if you're ready in advance.
Why six hours is harder than it sounds

The clock doesn't care what day it is.

Scenario 01 · The Sunday breach

It surfaces at 2am on a weekend.

A finance server starts sending odd traffic late on a Sunday. Your team wants to wait for Monday's sign-off from legal and leadership. But the six-hour window opened the moment someone noticed — and it's already running.

HOW TO BE READYA 24×7 point of contact and a pre-agreed decision path, so reporting doesn't wait for office hours.
Scenario 02 · The scattered logs

The evidence is in five places.

To report, you need to say what happened and what was hit. But firewall logs are in one tool, email logs in another, cloud logs somewhere else — and stitching them together burns the very hours you don't have.

HOW TO BE READYCentral, searchable logging kept 180 days in India — so the facts are one query away, not a scavenger hunt.
Scenario 03 · Is it even reportable?

A staffer clicked a strange link.

Was that an incident, or a near-miss? If your team has to debate the definition each time, you lose an hour to arguing instead of acting — and a genuine incident slips past the deadline.

HOW TO BE READYA simple severity matrix mapped to CERT-In's categories, so the "report or not" call takes minutes.
Inside the six hours

From "something's wrong" to "reported"

0h

Notice

An alert, a ticket, or a tip-off. The clock starts here — at awareness, not at proof.

~1h

Classify

Is it reportable? A ready severity matrix answers this in minutes, not meetings.

~3h

Contain & gather

Limit the damage and pull the facts — affected systems, timeline, actions taken.

≤6h

Report

File the initial report to CERT-In in the prescribed format. Updates can follow.

What the rules actually require

Your CERT-In duties, in plain terms

All under Section 70B of the IT Act and the CERT-In Directions of 28 April 2022.

6-hour rule

Report incidents fast

Report any of 20 categories of cyber incident within six hours of noticing it.

180 days · in India

Keep your logs

Retain logs of all ICT systems for 180 days, stored within Indian jurisdiction.

NTP sync

Synchronise clocks

Sync system clocks to NIC/NPL time servers so incident timestamps line up.

Point of contact

Name a contact

Designate a person to interface with CERT-In and receive its directions.

Prescribed format

Report the right way

Use CERT-In's format (Annexure A) — reporter, timeline, impact, actions taken.

5 years · providers

KYC & records

VPN, cloud, data-centre & virtual-asset providers keep KYC and records for five years.

Does this apply to you?

Almost certainly, yes.

✓

Companies & body corporatesAny business running digital systems in India.

✓

Service providers & intermediariesIncluding cloud, hosting, VPN, and data centres.

✓

Government organisationsCentral, state, and public-sector bodies.

✓

Foreign firms serving IndiaIf you serve Indian customers, you're in scope too.

What non-compliance costs

The fine isn't the whole story

₹1 Lakh & / or 1 yr
Current penalty under Section 70B(7) — fine and/or imprisonment for not complying with CERT-In directions.
✔ In force today
up to ₹1 Crore
Proposed increase under the Jan Vishwas (Amendment) Bill, 2023 — a large jump in the maximum fine.
⚠ Proposed · not yet in force

The bigger cost is rarely the fine. Missing the six-hour window signals to regulators, insurers, and enterprise clients that your incident-handling isn't in order — and that's what loses contracts and trust.

How we got here

From "reasonable time" to six hours

2000

IT Act · §70B

CERT-In established as India's national cyber-incident agency.

2013

CERT-In Rules

Incident reporting required — but only "within a reasonable time."

Apr 2022

New Directions

The six-hour rule, 180-day logs, and 20 incident types introduced.

Jun 2022

In force

Directions become binding on all covered entities — and remain so today.

Straight answers

CERT-In questions we hear most

Does the six-hour clock start at the breach or when we find it?+
When you find it. The clock starts the moment you notice the incident — or are told about it — not when the attack technically began. That's why fast detection and a clear escalation path matter so much.
Do we need the full investigation done in six hours?+
No. You send a timely initial report with what you know — affected systems, timeline, and actions taken — and follow up with updates as the picture clears. Don't wait for perfect forensics; report on the facts you have.
Is every odd event a reportable incident?+
Not always. A vulnerability with no sign of exploitation may not require reporting. The safe approach is a simple, pre-agreed classification so your team can decide quickly rather than debating each time — the cost of a fast check is far lower than missing the deadline.
We're a small business — are we really covered?+
Yes. The rules are worded broadly enough to cover almost every organisation running digital systems in India, regardless of size — and even foreign firms serving Indian customers. Size doesn't exempt you from the six-hour duty.
Where do we even start?+
With a readiness check: confirm your logging and retention, name a point of contact, build a simple severity matrix, and rehearse the six-hour workflow once. That's exactly what our CERT-In readiness assessment sets up.
From understanding to readiness

Could your business report a breach in six hours?

Most can't — not because they lack tools, but because the process has never been tested. Our CERT-In readiness assessment sets up your logging, point of contact, severity matrix, and a rehearsed six-hour workflow, so a bad day doesn't become a compliance failure too.

Book a CERT-In readiness check hello@indicshield.ai LOGGING · POC · SEVERITY MATRIX · DRILL

Sources: CERT-In Directions dated 28 April 2022 (No. 20(3)/2022-CERT-In), effective 28 June 2022, under Section 70B of the Information Technology Act, 2000. Proposed penalty increase per the Jan Vishwas (Amendment) Bill, 2023 (not yet in force as reviewed). This page is general information, not legal advice.