CERT-In 6-Hour Incident Reporting
CERT-In requires Indian organizations to report cyber incidents within 6 hours. Here is what counts as reportable, how to file, and how to operationalize the timeline.
The CERT-In Mandate
CERT-In (Indian Computer Emergency Response Team) issued directions in April 2022 requiring service providers, intermediaries, data centers, body corporates, and government organizations to report specific cybersecurity incidents within 6 hours of noticing or being brought to notice.
The 6-hour reporting requirement is one of the shortest in the world. Most jurisdictions require 24-72 hour reporting. The compressed timeline drives specific operational requirements: detection capability, escalation procedures, and reporting templates ready before incidents occur.
Non-compliance with CERT-In directions can result in penalties under Section 70B of the Information Technology Act, including imprisonment and fines. Beyond legal penalties, non-reporting damages relationships with regulators and may lead to additional scrutiny.
Reference the CERT-In framework guide for the complete directions and the list of specified incidents.
Reportable Incident Types
CERT-In specifies 20 incident types that require reporting. Major categories:
- Targeted scanning and probing: Of critical networks, systems
- Compromise of critical systems and information
- Unauthorized access to IT systems and data
- Defacement of websites or intrusion into a website
- Malicious code attacks: Including spreading of viruses, worms, trojans, bots, spyware, ransomware, cryptominers
- Identity theft, spoofing, and phishing attacks
- DoS and DDoS attacks
- Data breach and data leakage
- Attacks on Internet of Things (IoT) devices
- Attacks on cloud computing systems: AI/ML systems, BPO systems, CRM systems
- Attacks affecting digital payment systems
- Attacks through malicious mobile apps
- Fake mobile apps
- Attacks on AI/ML and big data systems
- Attacks targeting blockchain and digital assets
Some categories are broad. "Unauthorized access" covers many scenarios. Apply judgment based on the threshold of materiality and notify in close cases.
Reporting Process
CERT-In provides multiple reporting channels:
- Email: incident@cert-in.org.in
- Phone: +91-1800-11-4949 (toll-free)
- Fax: +91-11-24368546
- Web form: Available on CERT-In website
The required information for an incident report:
- Time of incident detection
- Description of the incident
- Type of incident from the specified categories
- Affected systems, applications, networks
- Geographic location of affected systems
- Any other relevant information
Reporting in 6 hours often means submitting an initial report with limited information, then following up with details as the investigation progresses. CERT-In accepts initial reports with subsequent updates. Do not delay the initial report waiting for a complete picture.
Maintain a CERT-In reporting template with pre-populated organizational information so the on-duty team only fills in incident-specific details when an incident occurs.
Operational Implications
The 6-hour timeline drives specific operational requirements:
- 24/7 monitoring: Incidents can occur any time. Detection capability must run continuously.
- Escalation procedures: From initial detection to incident commander to reporting authority within hours, not days.
- Pre-authorized reporting: Someone must have authority to file the report without waiting for executive approval. The authority to report should be designated in advance.
- Reporting template ready: Pre-built template with organizational details, contacts, and incident format.
- On-call rotation: Defined on-call team that can mobilize on short notice.
For organizations operating in India, CERT-In reporting capability should be integrated into the standard incident response process, not treated as a separate workflow. The IR runbook should include CERT-In notification as a step that fires automatically based on incident classification.
Additional CERT-In Requirements
Beyond the 6-hour incident reporting, CERT-In directions impose additional obligations:
- Log retention: ICT systems logs must be maintained for 180 days, securely stored within India
- Time synchronization: Server time must be synchronized to the National Informatics Centre (NIC) or NPL time
- VPN and VPS providers: Must maintain customer KYC information and IP allocation logs for 5 years
- Cryptocurrency exchanges and intermediaries: Must maintain customer KYC and transaction records for 5 years
The log retention requirement has architectural implications. Logs must be stored within India and retained for 180 days minimum. Cloud-native organizations may need to evaluate their log infrastructure to ensure compliance, including data residency for log storage.
Time synchronization with NIC/NPL is important for ensuring log consistency across systems and supporting forensic investigations. NTP synchronization to government time servers is the standard implementation.
Frequently Asked Questions
Related Articles
India DPDPA 2023 Compliance Guide
India's DPDPA 2023 is the country's first comprehensive personal data protection law. Here is what data fiduciaries must do to comply, including consent, notice, and breach handling.
RBI Cybersecurity Framework
The RBI Cybersecurity Framework establishes mandatory cybersecurity requirements for banks and financial institutions in India. Here is what it covers and how to operationalize compliance.
AI Governance Policy Template
An AI governance policy is the foundational document for any AI program. Here is a template covering scope, principles, lifecycle controls, and accountability.