CERT-In in India:
In an increasingly connected digital economy, cyberattacks can affect individuals, businesses, government institutions and critical infrastructure within minutes. Ransomware, phishing, data breaches, malware, identity theft and unauthorized access have therefore become matters of national concern. In India, the organisation responsible for coordinating the national response to cyber-security incidents is the Indian Computer Emergency Response Team (CERT-In).
CERT-In operates under the Ministry of Electronics and Information Technology (MeitY) and derives its statutory authority from Section 70B of the Information Technology Act, 2000. It functions as India’s national agency for responding to cyber-security incidents, issuing alerts and advisories, coordinating incident response and providing guidance on information-security practices.
For organisations operating in India, understanding CERT-In is no longer simply an IT-security matter. It is also a matter of legal and regulatory compliance.
What is CERT-In?
CERT-In stands for Indian Computer Emergency Response Team. It was established as the national agency responsible for cyber-security incident response in India.
Under Section 70B of the Information Technology Act, CERT-In performs functions including:
- Collecting, analysing and disseminating information relating to cyber incidents.
- Forecasting and issuing alerts about cyber-security incidents.
- Taking or coordinating emergency measures for handling cyber incidents.
- Coordinating cyber-incident response activities.
- Issuing guidelines, advisories, vulnerability notes and white papers.
- Calling for information from organisations and giving directions relating to cyber-security.
This authority is particularly important because CERT-In is not merely an advisory body. Section 70B gives it statutory powers to seek information and issue directions to specified entities.
Who needs to comply with CERT-In requirements?
The CERT-In Directions of 28 April 2022 apply broadly to service providers, intermediaries, data centres, body corporates and government organisations, among others. The Directions were issued under Section 70B(6) of the IT Act.
Therefore, the subject is relevant to almost every sizeable organisation that operates IT infrastructure or provides digital services.
The requirements can be particularly significant for:
- Large enterprises
- Banks and financial institutions
- E-commerce companies
- IT and IT-enabled services companies
- Cloud-service providers
- Data centres
- Internet service providers
- VPN providers
- Virtual Private Server providers
- Government organisations
- Digital platforms and intermediaries
- Virtual asset service providers
The exact obligations can differ depending on the nature of the organisation and the services it provides.
The six-hour cyber-incident reporting requirement
One of the most widely discussed CERT-In requirements is the six-hour reporting rule.
Under the 2022 Directions, specified cyber-security incidents must be reported to CERT-In within six hours of noticing the incident or being brought to notice of the incident.
This is important because the six-hour clock is not necessarily calculated from the moment the attack originally occurred. It is linked to when the organisation becomes aware of the incident or is informed about it.
This requirement creates an important operational responsibility for an organisation’s Security Operations Centre (SOC), IT team, CISO, incident-response team and management.
Examples of incidents covered by CERT-In reporting requirements include:
- Unauthorised access to computer systems or data
- Malware attacks
- Ransomware
- Phishing and spoofing
- Website defacement
- Data breaches
- Distributed Denial-of-Service (DDoS) attacks
- Attacks affecting critical systems
- Identity theft
- Fake mobile applications
- Attacks involving cloud or digital infrastructure
- Certain incidents involving unauthorised access to social-media accounts
CERT-In’s FAQs provide additional explanations and an illustrative list of reportable cyber-security incidents.
What information may need to be reported?
Incident reporting is intended to help CERT-In understand the nature and scope of a cyber incident and coordinate appropriate response measures.
Depending on the circumstances, an organisation may need to provide information relating to:
- Date and time of the incident
- Nature of the incident
- Systems affected
- IP addresses and other technical indicators
- Attack vectors
- Malware or malicious files
- Impact of the incident
- Actions already taken
- Relevant logs and technical evidence
- Other information requested by CERT-In
An organisation should therefore have a predefined incident-response process rather than trying to determine its reporting obligations for the first time during an attack.
180-day log retention requirement
Another major CERT-In requirement concerns ICT-system logs.
The 2022 Directions require service providers, intermediaries, data centres, body corporates and government organisations to enable logs of their ICT systems and maintain them securely for a rolling period of 180 days. The Directions also state that these logs are to be maintained within Indian jurisdiction and provided to CERT-In along with incident reporting or when CERT-In directs the organisation to provide them.
For an enterprise, this means log management cannot be treated simply as an operational convenience.
Organisations should consider appropriate logging for areas such as:
- Servers
- Firewalls
- Network devices
- Endpoints
- Security appliances
- Applications
- Cloud infrastructure
- Authentication systems
- Database systems
- VPN infrastructure
The precise implementation should be aligned with the organisation’s architecture, applicable laws and CERT-In requirements.
Synchronisation of system clocks
Accurate timestamps are extremely important during cyber investigations.
The CERT-In Directions therefore require organisations to synchronise ICT-system clocks with specified time sources, including Network Time Protocol (NTP) servers of the National Informatics Centre (NIC), National Physical Laboratory (NPL), or servers traceable to them, subject to the provisions and exceptions in the Directions.
Without consistent timestamps, investigators may find it difficult to reconstruct the sequence of events during a cyberattack.
For example, if a firewall shows an intrusion at 10:02, a server records it at 10:07 and an endpoint records it at 09:58 because the clocks are not synchronised, establishing the actual attack timeline becomes considerably more difficult.
Designated Point of Contact
Organisations covered by the Directions are required to designate a Point of Contact (PoC) for communication with CERT-In.
The PoC acts as the organisation’s interface for CERT-In communications, including requests for information and directions relating to cyber incidents. The organisation is expected to keep the information updated.
From a corporate-governance perspective, this responsibility should not depend on a single individual being available.
A mature organisation should have:
- A primary CERT-In PoC.
- A backup PoC.
- Clear escalation procedures.
- Contact details that remain current.
- A defined internal incident-response team.
Cooperation with CERT-In
CERT-In can require organisations to provide information or assistance relating to cyber-security incidents.
The Directions state that organisations may be required to take action or provide information and assistance that contributes to cyber-security mitigation and incident response. Such directions may specify the information required and the timeframe for compliance.
Consequently, an organisation should preserve relevant evidence and ensure that its incident-response procedures allow it to respond quickly to regulatory requests.
Special requirements for cloud, VPS, VPN and data-centre providers
The Directions contain additional requirements for certain service providers.
For example, data-centre, VPS, cloud-service and VPN-service providers are required to maintain specified subscriber/customer information, including validated identity details, service-period information and IP-related information. The Directions specify retention requirements of five years or longer where required by law after cancellation or withdrawal of registration.
These provisions are particularly relevant to organisations operating infrastructure or digital services at scale.
What happens if an organisation does not comply?
This is one of the most important aspects of CERT-In compliance.
Section 70B(7) of the Information Technology Act states that a service provider, intermediary, data centre, body corporate or person who fails to provide information called for by CERT-In or fails to comply with a direction issued under Section 70B(6) may be punished with:
Imprisonment for a term which may extend to one year, or a fine which may extend to ₹1 crore, or both.
The statutory maximum was amended from ₹1 lakh to ₹1 crore with effect from 30 November 2023.
This makes CERT-In compliance a serious legal obligation rather than merely an internal cybersecurity best practice.
CERT-In’s own FAQ states that non-compliance with the 2022 Cyber Security Directions may attract the penal provisions of Section 70B(7), and notes that this power is intended to be exercised reasonably, including in cases of deliberate non-compliance.
Is the penalty automatically ₹1 crore?
No.
The law states that the organisation or person may be punished with a fine which may extend to ₹1 crore, imprisonment up to one year, or both. The figure of ₹1 crore should therefore be understood as the maximum statutory fine, not an automatic penalty imposed for every violation.
The actual consequences can depend on the nature of the non-compliance, facts of the case, regulatory action and applicable legal proceedings.
This distinction is important because organisations sometimes incorrectly describe the CERT-In provision as an automatic ₹1 crore penalty.
Does CERT-In compliance override confidentiality obligations?
CERT-In’s FAQ addresses an important issue concerning contractual confidentiality.
The FAQ states that the obligation to report cyber-security incidents to CERT-In is statutory and, by virtue of Section 81 of the IT Act, can override a confidentiality clause in a contract where the statutory reporting obligation applies.
Therefore, organisations should ensure that vendor agreements, outsourcing contracts, managed-service agreements and incident-response arrangements do not unintentionally prevent legally required reporting.
CERT-In and corporate cybersecurity governance
For CIOs, CISOs and IT leaders, CERT-In compliance should be incorporated into the organisation’s broader cybersecurity governance framework.
A practical CERT-In compliance programme should include:
- Cyber-incident classification.
- 24×7 incident detection capability where appropriate.
- Six-hour reporting procedures.
- CERT-In Point of Contact management.
- Centralised logging.
- 180-day log retention.
- Accurate system time synchronisation.
- Incident-response playbooks.
- Evidence preservation.
- Security monitoring.
- Regular vulnerability assessments.
- Employee cybersecurity awareness.
- Vendor and third-party security controls.
- Periodic compliance audits.
- Management escalation procedures.
The objective should not be simply to “report to CERT-In”. The organisation should build the capability to detect, investigate, contain, report and recover from cyber incidents.
CERT-In is not a replacement for cybersecurity
An important misconception is that CERT-In compliance itself means an organisation is secure.
It does not.
CERT-In establishes important regulatory requirements for incident reporting, information sharing and security practices. But cybersecurity requires much more.
An organisation should also consider:
- Zero Trust architecture
- Multi-factor authentication
- Endpoint Detection and Response
- Security Information and Event Management
- Data-loss prevention
- Vulnerability management
- Patch management
- Backup and disaster recovery
- Privileged-access management
- Security awareness
- Third-party risk management
- Business continuity planning
CERT-In compliance should therefore be considered one component of a comprehensive cybersecurity programme.
Conclusion
CERT-In has become a critical part of India’s cybersecurity ecosystem. Through Section 70B of the Information Technology Act and the Cyber Security Directions issued in 2022, organisations have clear responsibilities relating to cyber-incident reporting, log retention, time synchronisation, designated points of contact and cooperation with the national cyber-response agency.
Ultimately, CERT-In compliance is not merely about avoiding penalties. It is about ensuring that organisations can respond quickly and effectively when cyber incidents occur.
In the digital economy, a cyberattack is no longer only an IT problem. It can become a business continuity, legal, financial, reputational and national-security issue. Organisations that establish strong incident detection, reporting and response capabilities are therefore better positioned not only to comply with CERT-In requirements but also to withstand the rapidly evolving cyber-threat landscape.
Note: This article provides general informational guidance based on the Information Technology Act, CERT-In Directions and publicly available government material. It should not be treated as legal advice. Organisations should obtain professional legal/compliance advice for their specific circumstances and monitor CERT-In for subsequent amendments, FAQs, directions and clarifications.