Skip to content
Back to Blog
·11 min read·compliance

CERT-In VAPT Compliance: What the April 2022 Directive Actually Requires (and What It Doesn't)

CERT-In's 2022 cybersecurity directive explained for Indian businesses. Which companies must comply, what VAPT proves, and the 6-hour breach notification requirement.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder, Bachao.AI

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

The Misconception That's Getting Companies Fined

When CERT-In issued its April 2022 cybersecurity directive, it triggered a wave of procurement calls for VAPT reports. Security vendors — and frankly a lot of compliance consultants — implied that VAPT was what CERT-In was requiring. It is not. Understanding the distinction matters because companies that bought VAPT reports and called it done may still be non-compliant, while companies that dismissed the directive as "just a VAPT requirement" never addressed the actual obligations.

This article explains exactly what the directive requires, what it does not require, and where VAPT fits in a compliant posture.

6 hrsMaximum time to report a cyber incident to CERT-In (CERT-In Direction 20(3)/2022)
28 typesIncident categories that must be reported
180 daysICT log retention period mandated by the directive
Any sizeThe directive applies to ALL entities — no SMB exemption

What the April 2022 Directive Actually Says

The Ministry of Electronics & Information Technology (MeitY) directed CERT-In to issue mandatory directions under Section 70B(6) of the IT Act 2000. The resulting direction — CERT-In Direction No. 20(3)/2022 — was published on 28 April 2022 and came into effect 60 days later.

The Six Core Obligations

1. Synchronise clocks with Indian Standard Time (IST) Every ICT system — servers, workstations, network devices, cloud instances — must synchronise to NTP servers at the National Informatics Centre (NIC) or NPL. This sounds trivial, but mismatched timestamps between your application logs and your firewall logs make forensic investigation impossible. Penalty-triggering scenarios: you report an incident but CERT-In's forensic team finds your timestamps don't match any known attack timeline.

2. Mandatory incident reporting within 6 hours This is the operative clause. If you experience any of the 28 listed incident types, you must report to CERT-In within 6 hours of detection — not 6 hours of becoming certain it was an incident, 6 hours of detection. The 28 categories include:

    1. Targeted scanning of critical networks
    2. Compromise of critical systems
    3. Website defacement
    4. Malware propagation
    5. Unauthorised access to IT systems
    6. Data breach or theft
    7. Attacks on internet infrastructure
    8. Phishing and fraudulent websites
    9. DDoS attacks
    10. Cryptomining / cryptojacking
    11. Ransomware attacks
3. Designate a Point of Contact (PoC) Every covered entity must maintain a designated PoC with CERT-In — name, role, email, and mobile number — and keep this updated. CERT-In may contact this person directly during an active national cyber threat.

4. Maintain ICT system logs for 180 days All logs must be retained for a minimum of 180 days within Indian jurisdiction. If you use a foreign SIEM or cloud logging service, logs must be mirrored to India. This covers: server logs, application logs, network device logs, firewall logs, and VPN logs.

5. Virtual Asset Service Providers (VASPs) must maintain KYC records for 5 years Specifically applicable to crypto exchanges, wallet providers, and custodians. Customer identity records, transaction logs, and financial records must be retained for 5 years.

6. Virtualisation and cloud providers must provide subscriber information on request If you are a cloud, VPN, or hosting provider, you must be able to produce subscriber information on a CERT-In request within the timeframe specified in the request.

ℹ️
INFO
Notice what is NOT in the list: VAPT is not mandated by the CERT-In 2022 directive. The directive does not require a penetration test, a vulnerability assessment, or any security audit. It requires incident reporting infrastructure, log retention, and a point of contact.

So Why Does Everyone Talk About VAPT?

VAPT comes into the CERT-In picture in three legitimate ways:

1. Vulnerability Disclosure Policy (VDP) recommendations CERT-In has separately recommended (not mandated) that organisations maintain a VDP — a published process for security researchers to report vulnerabilities. Running regular VAPT scans is the natural complement: if you're encouraging responsible disclosure, you should also be proactively finding your own vulnerabilities.

2. Sector-specific CERT-In empanelment requirements CERT-In maintains a list of empanelled security auditing organisations. Certain regulated sectors — banking, critical infrastructure, government portals — are required by their own regulators (RBI, SEBI, MoD) to use CERT-In empanelled vendors for security audits. This is where "CERT-In VAPT" as a phrase comes from: it means "VAPT conducted by a CERT-In empanelled vendor," not "VAPT required by CERT-In."

3. DPDP Act "reasonable security safeguards" standard As discussed in our DPDP checklist, the DPDP Act requires reasonable security safeguards. An annual VAPT from a CERT-In empanelled vendor is the most widely accepted evidence of meeting that standard. So VAPT is DPDP-driven, not CERT-In-driven.


Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The Compliance Matrix

RequirementCERT-In Direction 2022DPDP Act 2023Sector Regulator
6-hour breach reporting✅ Mandatory✅ (parallel obligation)Varies
Log retention (180 days)✅ MandatoryImpliedVaries
VAPT audit❌ Not required✅ Implied ("reasonable safeguards")✅ RBI/SEBI/IRDAI
Point of Contact with CERT-In✅ Mandatory
NTP clock sync✅ Mandatory
Incident response plan✅ Implied✅ RBI/SEBI
DPO nomination✅ Mandatory

Building a CERT-In Compliant Posture: Practical Steps

graph TD A[Detect Incident] -->|Within 15 min| B[Classify against 28 categories] B -->|In scope| C[Notify CERT-In PoC — 6 hr clock starts] B -->|Out of scope| D[Log internally, monitor] C --> E[Preserve logs + forensic evidence] E --> F[Parallel: notify DPDP Data Protection Board if personal data involved] F --> G[Internal incident review within 72 hrs] G --> H[CERT-In follow-up report within 30 days] style C fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style F fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0

Step 1: Build your CERT-In reporting infrastructure

    1. Register a PoC with CERT-In at cert-in.org.in — this takes less than 30 minutes and most organisations have not done it
    2. Create an incident classification checklist against the 28 categories — laminate it and put it near whoever is on call
    3. Set up the CERT-In reporting email/portal on a phone that is checked 24/7

Step 2: Implement log retention

Log SourceToolRetention Target
Application logsCloudWatch / ELK / Datadog180 days
Web server logsNginx/Apache log rotation180 days
Firewall/WAF logsCloud-native or SIEM180 days
VPN access logsOpenVPN / WireGuard180 days
Database audit logsPostgreSQL pgaudit180 days

Step 3: NTP synchronisation

bash
# Ubuntu / Debian — configure NIC NTP servers
sudo nano /etc/systemd/timesyncd.conf
# Add:
# NTP=time.nic.in
# FallbackNTP=time2.nic.in

sudo systemctl restart systemd-timesyncd
timedatectl show-timesync

Step 4: Pair CERT-In compliance with VAPT (for DPDP)

Once the CERT-In mechanics are in place, run a VAPT to satisfy the DPDP "reasonable security" standard. The two work together:

    1. CERT-In compliance = your response capability (you can detect, report, and preserve)
    2. VAPT = your prevention capability (you found and fixed vulnerabilities before they were exploited)
A breach investigation where you can show: (a) you detected within hours, (b) you reported to CERT-In within 6 hours, and (c) you had a clean VAPT from 6 months ago — that is a materially different legal position than a company with no controls.

How Bachao.AI Maps to CERT-In Requirements

CERT-In RequirementBachao.AI Output
Evidence of proactive vulnerability managementVAPT Report (CERT-In empanelled vendor)
Incident response procedureIR Playbook template in every Full Report
Log review and anomaly detectionLogging configuration review in VAPT scope
DPDP "reasonable security" evidenceDPDP compliance mapping section in report
Sector audit (RBI/SEBI/IRDAI)Regulator-specific annexure available
💡
TIP
Our reports are CERT-In aligned and formatted to meet the evidence requirements expected by RBI IT examination teams, SEBI compliance officers, and IRDAI auditors. When your regulator asks for the audit report, you can hand them the Bachao.AI report directly.

Get your CERT-In aligned VAPT report at bachao.ai/cert-in-vapt-india. Scope-based pricing, 7–10 business day turnaround, and a report structured to satisfy both CERT-In incident response expectations and DPDP Act compliance requirements.

Written by Shouvik Mukherjee, Founder, Bachao.AI. 15+ years in software engineering, now building AI-powered security products. Fourth-time founder. DPIIT Recognised Startup.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →