Skip to content
Back to Blog
·9 min read·compliance

CERT-In 2022 Directions Compliance: Complete Guide for India

CERT-In 2022 directions compliance is legally mandatory for all Indian businesses. Learn how 6-hour reporting, 180-day log retention, and NTP sync apply to you.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

CERT-In 2022 directions compliance is a legal obligation under Section 70B(6) of the Information Technology Act, 2000, binding every organisation operating digital infrastructure in India. Issued on April 28, 2022, the Directions mandate 6-hour cybersecurity incident reporting to CERT-In, 180-day log retention within Indian jurisdiction, NTP clock synchronisation, and 5-year subscriber data retention for VPN and cloud providers. Non-compliance is a legal violation — not a policy gap — carrying civil penalties under the IT Act. Every service provider, intermediary, data centre, body corporate, and government organisation in India must comply, regardless of size or revenue.

What the CERT-In 2022 Directions Actually Require

The CERT-In 2022 Directions, formally titled "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet," were issued after CERT-In identified systematic gaps in how Indian organisations detect, log, and report security incidents.

The directions cover four primary obligations:

Mandatory Incident Reporting within Six Hours. Any of the 20 listed incident types must be reported to CERT-In at incident@cert-in.org.in within six hours of the organisation becoming aware of the incident. This is not six hours after resolution — it is six hours after detection.

Log Retention for 180 Days. All ICT system logs — including server logs, firewall logs, application logs, and authentication logs — must be maintained and stored within Indian jurisdiction for a minimum of 180 days. Logs must be produced on demand when requested by CERT-In.

Accurate Clock Synchronisation. All ICT infrastructure must synchronise clocks with the Network Time Protocol servers operated by the National Informatics Centre or STQC, or with NTP servers traceable to them. This ensures forensic accuracy across log timestamps during incident investigations.

VPN and Cloud Provider Data Retention. Virtual Private Network service providers, virtual asset service providers, cloud service providers, and data centres must maintain verified subscriber records and usage logs for a minimum of five years.

Who Must Comply with CERT-In 2022 Directions in India

The scope of the CERT-In 2022 Directions is intentionally broad. Compliance is mandatory for:

Entity TypeObligation
Service providers and ISPs6-hour incident reporting, 180-day log retention
Cloud service providers6-hour reporting, 5-year subscriber log retention
VPN providers6-hour reporting, 5-year subscriber KYC and usage logs
Data centres and co-location6-hour reporting, 180-day log retention, NTP sync
Body corporates handling digital services6-hour reporting, 180-day log retention
Virtual asset service providers6-hour reporting, 5-year transaction log retention
Government organisationsFull compliance with all four obligations
The directions explicitly include entities incorporated outside India that provide services to Indian users or operate infrastructure in India. There is no minimum company size or revenue threshold. A ten-person SaaS startup and a large enterprise face the same six-hour obligation if they experience a covered incident.
⚠️
WARNING
The six-hour window starts at the moment of detection, not at the moment of full investigation or remediation. Organisations that delay internal escalation to "understand the full scope" before reporting will already be non-compliant by the time they file the notification.

Not sure whether your current security posture can meet CERT-In's six-hour reporting obligation? Run a free VAPT scan to map your control gaps against these requirements — before CERT-In asks.

The 6-Hour Incident Reporting Process

Understanding the compliance flow is as important as knowing the obligation exists. The following diagram maps the mandatory process from detection through to documented compliance:

graph TD A[Incident Detected]:::normal --> B{Classify Against 20 Types}:::normal B --> C[Covered Incident Confirmed]:::danger B --> D[Not a Listed Incident]:::normal C --> E[Notify CERT-In within 6 Hours]:::danger E --> F[Preserve All Relevant Logs]:::normal F --> G[Internal RCA and Containment]:::normal G --> H[Submit Full Technical Report in 30 Days]:::normal H --> I[Retain Logs for Minimum 180 Days]:::normal I --> J[Compliance Documented]:::success D --> K[Continue Standard IR Procedures]:::normal classDef normal fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 classDef danger fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 classDef success fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

The critical design principle here is that incident response and compliance reporting run in parallel, not in sequence. Your IR team begins containment while your compliance team files the initial CERT-In notification simultaneously. The 30-day full technical report is your opportunity to provide complete root cause analysis, timeline reconstruction, and remediation evidence.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

20 Incident Types That Trigger 6-Hour Reporting

CERT-In's 2022 Directions enumerate exactly 20 incident categories that trigger mandatory six-hour reporting. These span infrastructure attacks, financial fraud, data theft, and malware — reflecting the full breadth of the modern threat landscape in India.

pie title 20 CERT-In Mandated Incident Types Grouped by Category "Infrastructure Attacks" : 6 "Data and Unauthorized Access" : 4 "Financial Fraud and Social Engineering" : 4 "Malware and APT" : 2 "Web and Social Media" : 2 "Critical Systems Compromise" : 2

Breaking these down by category:

    1. Infrastructure Attacks cover targeted scanning and probing, attacks on servers and network devices, DNS and routing attacks, DDoS, and attacks on IoT devices.
    2. Data and Unauthorized Access covers unauthorized access to IT systems or data, data breaches, identity theft, and intellectual property theft.
    3. Financial Fraud and Social Engineering covers attacks on digital payment systems, online fraud, fake mobile applications, and fraudulent calls or SMS.
    4. Malware and APT covers malicious code attacks (ransomware, trojans, worms) and Advanced Persistent Threats.
    5. Web and Social Media covers website intrusion and defacement, and unauthorized access to social media accounts.
    6. Critical Systems Compromise covers attacks on critical infrastructure and compromise of critical systems.
🚨
DANGER
Ransomware is explicitly listed under "Malicious code attacks" — one of the highest-frequency incident types affecting Indian organisations. If your systems are encrypted by ransomware and you do not notify CERT-In within six hours of detection, you face compounding legal exposure: the attack itself and the failure to report are separate compliance failures.

Technical Compliance Obligations for Indian Companies Under CERT-In

CERT-In 2022 compliance is not limited to filing notifications after incidents occur. Three structural technical obligations apply continuously and must be embedded into your infrastructure architecture.

Log Architecture for 180-Day Retention

Your log infrastructure must retain data at the Indian jurisdiction level. Practically, this requires:

    1. Centralised SIEM or log management platform with enforced 180-day retention policies
    2. Immutable log storage to prevent tampering or deletion
    3. Ability to produce specific log sets within 24 hours of a CERT-In request
    4. Coverage across all ICT layers: network, server, application, authentication, and endpoint
Organisations relying on cloud-native logging tools with default 30-day or 90-day retention windows are immediately non-compliant. Extending retention periods and exporting logs to India-resident storage must be part of your baseline infrastructure configuration.

NTP Clock Synchronisation

The NTP requirement exists because log timestamps from unsynchronised systems are unreliable as forensic evidence. Inconsistent timestamps across server logs, network device logs, and application logs make it impossible to reconstruct a coherent attack timeline — which undermines both your incident response and any subsequent legal proceedings.

Organisations using commercial cloud providers that default to external global NTP pools need explicit configuration to synchronise with NIC or STQC NTP servers. This is a low-effort, high-impact configuration change that is frequently overlooked.

VPN and Cloud Infrastructure Data Retention

If your organisation provides VPN services, cloud infrastructure, or virtual asset services to Indian customers, the data retention obligation extends to subscriber KYC records and usage logs for five years. This obligation applies even if your infrastructure is hosted outside India. Virtual asset service providers — including cryptocurrency exchanges operating in India — face additional obligations covering transaction records.

Building CERT-In Compliance into Daily Operations

Most organisations fail CERT-In compliance not because they ignore it, but because their operational processes were never designed around a six-hour external notification deadline. A typical non-compliant incident response flows like this: detection triggers internal escalation, leadership gets briefed, legal is consulted, external notification is eventually filed — a process that routinely takes 24 to 72 hours in practice. The CERT-In Directions compress that external notification step to six hours, which means the entire internal escalation chain must be redesigned.

Practical steps for building lasting compliance:

Designate a CERT-In Reporting Officer. This named individual has authority to submit incident reports to CERT-In without waiting for full investigation completion. The initial report can include partial information — CERT-In accepts supplementary details in the 30-day full report. The bottleneck in most organisations is authority, not information.

Automate Log Collection and Retention. Manual log collection cannot meet a 180-day mandate at scale. Implement centralised log management with automatic ingestion from all systems, retention policy enforcement, and integrity verification. Test the ability to retrieve logs from a specific date range on demand — before CERT-In asks.

Run the Six-Hour Tabletop Exercise. Conduct incident response exercises that include CERT-In reporting as a mandatory milestone. Time the exercise from "detection" to "initial report submitted." Most organisations discover their first run far exceeds six hours, but the exercise reveals exactly where the process breaks.

Audit Your Third-Party Vendors. If you use third-party VPN, cloud, or virtual asset services, verify that those vendors are themselves compliant with the Directions. A log retention gap in a vendor's infrastructure can create compliance exposure even when your own systems are correctly configured.

Organisations beginning their compliance journey can start with a free VAPT scan to identify security control gaps before moving into formal compliance assessment. Bachao.AI, the automated VAPT platform built by Dhisattva AI Pvt Ltd, surfaces misconfigurations and control weaknesses that typically map directly to CERT-In compliance requirements. For data protection compliance obligations that run alongside CERT-In requirements, see the DPDP compliance guide.

The full text of the CERT-In 2022 Directions is published on the official CERT-In website. DSCI's published frameworks at dsci.in provide additional implementation guidance for Indian organisations navigating the compliance landscape.

13,91,457Cybersecurity incidents handled by CERT-In in 2022 (CERT-In Annual Report 2022)
20Incident types mandating 6-hour reporting under CERT-In 2022 Directions (CERT-In 2022)
6 hoursMaximum window to report a covered incident after detection (CERT-In 2022 Directions)
180 daysMinimum log retention period mandated for all ICT systems (CERT-In 2022 Directions)
5 yearsSubscriber and log retention period for VPN and cloud providers (CERT-In 2022 Directions)
🎯Key Takeaway
The CERT-In 2022 Directions are legally binding obligations under the IT Act for every organisation operating digital infrastructure in India — not aspirational guidelines. The six-hour reporting window, 180-day log retention, NTP synchronisation, and five-year VPN and cloud data retention requirements demand structural changes to how organisations architect their security operations. Compliance starts with knowing your current posture and closing the gaps before CERT-In asks.

Frequently Asked Questions

Does the CERT-In 6-hour reporting rule apply to small businesses and startups in India?
Yes. The CERT-In 2022 Directions apply to all service providers, intermediaries, data centres, and body corporates operating in India regardless of company size, revenue, or headcount. A ten-person startup running a SaaS product faces the same six-hour reporting obligation as a large enterprise if they experience one of the 20 covered incident types.
What information must be included in the initial six-hour CERT-In incident report?
The initial report should include the nature of the incident, the systems affected, the approximate time of detection, and the immediate containment steps taken. CERT-In explicitly allows supplementary information to be submitted within 30 days in the full technical report. A complete root cause analysis is not required to file the initial notification — speed of reporting takes precedence over completeness at the six-hour mark.
What penalties does an Indian company face for failing to report a cybersecurity incident to CERT-In within six hours?
Failure to comply with a CERT-In Direction issued under Section 70B(6) of the IT Act constitutes a legal violation. CERT-In has authority to direct organisations to comply and can escalate to appropriate enforcement bodies. Repeated or wilful non-compliance can result in civil penalties and reputational consequences, independent of any damage caused by the incident itself.
Are foreign companies with Indian users required to comply with the CERT-In 2022 Directions?
Yes. The Directions explicitly cover entities incorporated outside India that provide services to Indian users or operate infrastructure within India. A company headquartered abroad that serves Indian customers through digital services is subject to the same incident reporting and log retention obligations as a domestically incorporated company.
How does the 6-hour CERT-In notification differ from the 30-day technical incident report for Indian organisations?
The 6-hour notification is a mandatory initial alert to CERT-In that a covered incident has occurred. It can be preliminary. The 30-day report is a full technical account of the incident: root cause analysis, systems and data affected, complete timeline, containment and remediation steps taken, and preventive measures implemented going forward. Both are mandatory; neither substitutes for the other.
Do the CERT-In 2022 Directions interact with the DPDP Act 2023 data breach obligations?
Yes, they operate in parallel. CERT-In Directions govern incident reporting and log retention for cybersecurity purposes under the IT Act. The Digital Personal Data Protection Act 2023 governs data breach notification to the Data Protection Board of India and to affected data principals. An organisation experiencing a personal data breach will typically need to comply with obligations under both frameworks simultaneously. See the DPDP compliance guide for detail on the data protection obligations.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →