Skip to content
Back to Blog
·9 min read·compliance

CERT-In 6-Hour Incident Reporting Rule: India Compliance Guide

CERT-In's 2022 Directions require Indian companies to report cyber incidents within 6 hours of detection and retain ICT logs for 180 days. Compliance guide.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

CERT-In's April 2022 Directions require every organisation operating in India to report specified cyber incidents to the Indian Computer Emergency Response Team within 6 hours of noticing them — not 6 hours after investigation, but 6 hours after first detection. Simultaneously, organisations must maintain ICT system logs for 180 days within Indian jurisdiction, synchronise clocks to NTP servers traceable to the National Physical Laboratory or National Informatics Centre, and provide KYC information for VPN and cloud subscribers. These Directions, issued under Section 70B(6) of the Information Technology Act, 2000, are legally binding on every entity — government, private, or public sector — that uses, provides, or manages information infrastructure in India.

20Reportable cyber-incident categories mandated by CERT-In Directions 2022 (CERT-In / MeitY 2022)
180Days organisations must retain ICT logs on Indian servers (CERT-In Directions 2022)
6Hours within which reportable incidents must be notified to CERT-In (CERT-In Directions 2022)

What the CERT-In Directions Actually Say

The CERT-In Directions dated 28 April 2022 (published by the Ministry of Electronics and Information Technology, available at cert-in.org.in) came into force on 27 June 2022. They amend the 2014 CERT-In Operating Rules and make three core compliance obligations non-negotiable:

  1. 6-hour incident reporting — Covered organisations must report any of the listed incident types to CERT-In within 6 hours of becoming aware of the incident, regardless of whether the cause or scope has been established.
  2. 180-day log retention — Logs of ICT systems, including servers, network devices, endpoints, and cloud infrastructure, must be maintained for a rolling 180-day window and stored within India.
  3. NTP synchronisation — All ICT infrastructure clocks must sync to NPL- or NIC-traceable NTP sources to ensure log timestamps are legally defensible.
  4. KYC and subscriber records — VPN service providers, virtual asset service providers, cloud service providers, and data centres must maintain accurate subscriber/customer information for 5 years, even after the customer cancels the service.
The full text of the Directions is published at meity.gov.in.

Who Must Comply

The Directions apply broadly. There is no size threshold and no sector carve-out. If your organisation:

    1. Operates ICT infrastructure in India (servers, cloud workloads, SaaS, or on-premise),
    2. Provides internet services, data centre services, cloud services, or VPN services to Indian customers,
    3. Is a government body, public sector undertaking, or private enterprise using digital infrastructure, or
    4. Handles financial services, critical information infrastructure, or e-commerce,
then the Directions apply to you. Startups, SMBs, and mid-market companies are equally obligated — a common misconception is that only enterprises or critical infrastructure operators are in scope.
⚠️
WARNING
Many Indian SMBs assume CERT-In compliance applies only to large enterprises or regulated sectors. The Directions explicitly cover all entities under the IT Act's jurisdiction. A startup with 20 employees running AWS workloads in ap-south-1 is in scope.

The 20 Reportable Incident Categories

CERT-In's Directions enumerate 20 types of incidents that must be reported within the 6-hour window. These include:

CategoryExamples
Targeted scanning / probingSystematic reconnaissance of critical networks
Compromise of critical systemsServers, databases, authentication infrastructure
Unauthorised accessAccounts, applications, data
Defacement of websites or applicationsGovernment portals, financial apps
Malware attacksRansomware, spyware, trojans on critical systems
Attacks on serversDNS servers, mail servers, directory services
Identity theft and fraudSpoofing, phishing campaigns targeting Indians
Denial-of-service attacksDDoS, volumetric attacks
Attacks on critical infrastructurePower, telecom, financial systems
Attacks on IoT devicesEmbedded systems, industrial control systems
Data breaches / theftPII, financial data, health records
Attacks on digital payment systemsUPI, NEFT, card networks
Attacks on satellites / navigationSpace segment, ground control
Malicious code in supply chainBackdoored software updates, compromised libraries
Attacks on e-governance servicesGovernment portals, Aadhaar-linked services
Attacks on healthcare systemsHospital management, patient data platforms
Fake mobile appsImpersonating banks, government agencies
Cryptocurrency theftExchange hacks, wallet compromises
Attacks on AI/ML systemsModel poisoning, adversarial manipulation
Incidents directed by foreign statesAttribution-confirmed nation-state attacks
The list is intentionally broad. A ransomware hit on a single file server, a successful phishing campaign that compromises one email account with elevated privilege, or a DDoS attack that takes your payment gateway offline for 30 minutes — all are reportable.
🚨
DANGER
The 6-hour clock starts the moment anyone in your organisation becomes aware of an incident — not when IT confirms it, not when a ticket is raised, and not when forensics are complete. An employee forwarding a suspicious email to IT at 9 AM starts the clock. You must file with CERT-In by 3 PM.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Understanding the 6-Hour Window in Practice

Six hours sounds generous until you factor in real-world constraints:

    1. Detection often happens outside business hours (most ransomware activates at 2–3 AM)
    2. Initial responders may not have authority to notify regulators
    3. The CERT-In portal requires structured information: incident type, affected systems, estimated impact, initial containment steps taken
    4. If your team is still in triage mode, you still must file — CERT-In accepts preliminary reports that can be supplemented later
The Directions explicitly permit submitting an initial notification with whatever is known, followed by a detailed follow-up report. The obligation is to notify within 6 hours, not to provide a complete forensic analysis within 6 hours.

What to Include in the Initial Report

CERT-In's reporting format (available at cert-in.org.in) typically asks for:

    1. Organisation name, contact details, and sector
    2. Date and time the incident was first noticed
    3. Type of incident (from the 20-category list)
    4. Affected systems and estimated scope
    5. Initial containment actions taken
    6. Whether law enforcement has been notified
💡
TIP
Pre-fill an incident report template with your organisation's static information — name, sector, primary contact, CERT-In registration details — and keep it in your incident response runbook. Under pressure, having a partially completed form saves critical minutes.

The 180-Day Log Retention Requirement

Log retention is equally non-negotiable. The Directions require:

    1. Scope: Logs from ICT infrastructure — servers, routers, switches, firewalls, endpoints, VPNs, cloud environments, and SaaS tools with API log access
    2. Duration: Minimum 180 days on a rolling basis
    3. Location: Stored within India (organisations using foreign cloud providers must ensure logs flow to Indian regions or a separate India-based SIEM)
    4. Integrity: Logs must be tamper-evident; CERT-In can request them during an investigation
    5. Clock synchronisation: All log timestamps must come from NTP sources traceable to NPL (National Physical Laboratory) or NIC
AWS CloudTrail, Azure Monitor, and Google Cloud Logging can all be configured to retain logs in Indian regions (ap-south-1, centralindia, asia-south1). The key gap for most SMBs is endpoint and on-premise network device logs, which are frequently discarded after 30–90 days.

VPN and Cloud Provider KYC Obligations

Organisations that offer VPN, cloud, or data centre services to Indian customers must collect and verify subscriber identity at onboarding and retain those records for 5 years — including after service termination — making them available to CERT-In on request. The requirement targets service providers, not individual users of commercial VPN products.

Building a 6-Hour Incident Reporting Workflow

Meeting the 6-hour deadline requires process engineering, not just technology. A workflow that depends on the right person being awake, available, and knowing the CERT-In portal password will fail.

graph TD A[Incident Detected
Employee / Tool / Alert] --> B{Classify Severity} B -- Critical / High --> C[Activate Incident Response Team] B -- Low / Unclear --> D[Triage Assessment
max 30 min] D --> E{Is it a CERT-In
Reportable Category?} E -- No --> F[Internal Handling
Document Decision] E -- Yes --> C C --> G[Assign Incident Commander
and Regulatory Contact] G --> H[Begin Containment
Isolate Systems] H --> I[File Initial CERT-In
Report Within 6 Hours] I --> J[Notify Legal and
Management] J --> K[Preserve Logs
180-day retention verified] K --> L[Detailed Follow-up
Report to CERT-In] L --> M[Post-Incident Review
and Remediation] style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style D fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style E fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style F fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style G fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style H fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style I fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style J fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style K fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style L fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style M fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

The Five Process Pillars

1. 24/7 Detection Coverage Alerts from your SIEM, EDR, or cloud monitoring must reach a human within minutes, not hours. On-call rotations and automated escalation are prerequisites, not optional.

2. Documented Classification Matrix Your team must be able to determine within 15 minutes whether an incident falls into one of CERT-In's 20 categories. A single-page classification matrix in your runbook eliminates judgment paralysis during triage.

3. Pre-designated Regulatory Reporting Contact One named person — with a backup — holds the authority and credentials to file the CERT-In report. This should not be discovered during an incident.

4. Pre-populated Report Template Maintain a partially completed incident report with your organisation's static details. When an incident occurs, you fill in the specifics, not the boilerplate.

5. Verified Log Pipeline Confirm that logs from all in-scope systems are flowing to a centralised SIEM or log management platform, that the retention window is set to at least 180 days, and that the storage sits within India. Test this quarterly.

Incident Response Time Budget

The chart below shows how the 6-hour window should be allocated across detection, triage, escalation, and filing — leaving buffer for system slowdowns or off-hours gaps.

xychart-beta title "6-Hour CERT-In Reporting Budget in Minutes" x-axis ["Detection to Alert", "Alert to Triage", "Triage to Classify", "Classify to Escalate", "Escalate to Draft Report", "File to CERT-In", "Buffer"] y-axis "Minutes" 0 --> 120 bar [15, 30, 20, 15, 60, 20, 60]

Penalties for Non-Compliance

The CERT-In Directions are issued under Section 70B(6) of the IT Act, 2000. Non-compliance can result in enforcement action by CERT-In, including:

    1. Formal directions to comply, with timelines
    2. Referral to the Ministry of Electronics and Information Technology
    3. Prosecution under the IT Act, which carries imprisonment and financial penalties at the discretion of adjudicating authorities
    4. In cases involving critical information infrastructure, additional consequences under the National Cyber Security Policy and sector-specific regulations (RBI, SEBI, IRDAI) may apply
The Directions do not specify fixed monetary amounts for non-reporting specifically, and we will not invent numbers. What is clear is that wilful non-compliance — particularly if discovered after a breach causes public harm — will be treated seriously by regulators and can compound liability under other applicable laws, including the Digital Personal Data Protection Act, 2023.
🛡️
SECURITY
CERT-In non-compliance can be discovered indirectly. If a major incident affecting Indian users becomes public — a data breach, a ransomware attack on critical services — and CERT-In has no record of a report from your organisation, investigators will ask why. The absence of a report in CERT-In's systems becomes evidence of non-compliance.

How VAPT Connects to CERT-In Compliance

CERT-In's Directions are reactive — they govern what you do after an incident. Proactive vulnerability management reduces how often those incidents occur and builds the documented evidence trail that regulators expect to see. Organisations that run a regular free VAPT scan identify the misconfigurations, unpatched CVEs, and weak authentication controls that attackers exploit before a breach triggers the 6-hour clock.

Bachao.AI, built by Dhisattva AI Pvt Ltd, automates vulnerability discovery so security and compliance teams have continuous visibility — not just a point-in-time audit once a year. Formal audits requiring CERT-In empanelled sign-off are handled with a CERT-In empanelled partner; Bachao.AI provides the automated scanning and evidence layer that feeds into that process.

Compliance Checklist

RequirementFrequencyOwner
Register with CERT-In portalOnceIT / Compliance Lead
Maintain 20-category incident classification matrixReview annuallySecurity Team
Designate regulatory reporting contact with backupOnce, update on role changesCISO / IT Head
Verify 180-day log retention across all ICT systemsQuarterlyIT / DevOps
Confirm logs stored within IndiaQuarterlyIT / Cloud Admin
Sync all clocks to NPL/NIC NTPContinuousIT / DevOps
Collect and retain VPN/cloud subscriber KYC (if applicable)OngoingCompliance / Legal
Run tabletop incident response exerciseAnnuallySecurity Team
File test CERT-In report to verify processAnnuallyRegulatory Contact
Document VAPT assessment and remediation evidenceBiannuallySecurity Team
🎯Key Takeaway
The 6-hour CERT-In reporting window is non-negotiable and starts the moment any employee notices a potential incident — not when IT confirms it. Build a workflow that can produce an initial report in under 4 hours to leave margin. Log retention, NTP sync, and KYC for VPN/cloud providers are equally binding. CERT-In compliance is not a checkbox — it is an operational capability that must be tested before an incident, not assembled during one.

Frequently Asked Questions

Does the 6-hour CERT-In reporting rule apply to startups and SMBs?
Yes. The CERT-In Directions 2022 apply to all entities operating ICT infrastructure in India under the IT Act, 2000. There is no minimum size threshold or sector carve-out. A startup running cloud workloads or a SaaS platform serving Indian customers is fully in scope.
What happens if I cannot complete an investigation within 6 hours?
You are not required to complete an investigation within 6 hours — only to notify CERT-In that an incident has occurred. Submit an initial report with whatever is known (incident type, affected systems, initial containment steps), and follow up with a detailed report as the investigation progresses. CERT-In's format accommodates preliminary notifications.
Where do I file a CERT-In incident report?
Reports can be filed via the CERT-In online portal at cert-in.org.in, or by email to incident@cert-in.org.in. Phone reporting is also accepted at +91-1800-11-4949 (toll-free). Pre-registering your organisation on the portal before an incident is strongly recommended.
What counts as "becoming aware" of an incident for the 6-hour clock?
Any employee or system in your organisation perceiving the incident starts the clock — an alert from your SIEM, an employee reporting strange behaviour, a vendor notification, or a media report about your organisation. The awareness threshold is low by design to prevent organisations from delaying acknowledgment.
Do the 180-day log retention rules apply to cloud-hosted infrastructure?
Yes. Logs from AWS, Azure, GCP, or any cloud provider must be retained for 180 days and the storage must be within India. Most major cloud providers offer Indian regions; you must configure log export and retention explicitly — default settings in most cloud accounts do not meet this requirement.
Is a CERT-In empanelled auditor required for compliance?
The CERT-In Directions 2022 do not mandate a CERT-In empanelled auditor for ongoing compliance. However, if your sector regulator (RBI, SEBI, IRDAI, NCIIPC) requires a CERT-In empanelled audit, that engagement must be conducted with a CERT-In empanelled partner. Automated VAPT platforms can complement this by providing continuous vulnerability data between formal audits.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →