CERT-In
CERT-In Directions, 2022
The cyber-incident reporting and logging rules every entity operating in India must follow.
Issuer
CERT-In (under MeitY)
Region
India
Legal basis
IT Act, 2000 — §70B(6)
In force
Since 28 June 2022
Overview
What is CERT-In?
Issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B(6) of the IT Act, the 2022 Directions set baseline cyber-security obligations for organisations operating in India. Unlike sector-specific rules, they apply broadly — to companies, intermediaries, data centres and cloud/VPS/VPN providers alike.
The headline duties are sharp and time-bound: report specified cyber incidents to CERT-In within 6 hours, keep system logs for a rolling 180 days within India, synchronise clocks to Indian time sources, and — for infrastructure providers — hold validated subscriber KYC. Non-compliance can attract penalties under the IT Act.
Who needs it: Effectively every body corporate, intermediary, data centre and cloud / VPS / VPN / virtual-asset service provider operating in India — the obligations are general, not sector-specific.
Inside the framework
Core obligations
6-hour incident reporting
Mandatorily report the specified categories of cyber incidents to CERT-In within six hours of noticing them.
180-day logging in India
Enable logs for all ICT systems and retain them for a rolling 180 days, held within Indian jurisdiction.
Time synchronisation
Synchronise all system clocks to the NTP servers of NIC or NPL, or sources traceable to them.
Subscriber KYC & records
Data-centre, VPS, cloud and VPN providers must hold validated KYC and subscriber records for at least five years.
Point of contact & cooperation
Designate a CERT-In point of contact and comply with its orders and information requests.
With RegShield
Get CERT-In-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right CERT-In controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for CERT-In is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your CERT-In readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who must comply?
The Directions apply broadly to service providers, intermediaries, data centres, body corporates and government organisations operating in India — not a single regulated sector.
What is the 6-hour rule?
Specified cyber incidents (per Annexure I) must be reported to CERT-In within six hours of being noticed. RegShield maps your incident-response evidence to this and the other Directions.
Do logs really have to stay in India?
Yes — logs of ICT systems must be kept for a rolling 180 days within Indian jurisdiction and furnished to CERT-In on order. We track that as a control with the evidence it needs.