CERT-In Directions 2022
Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and IT · Version 2022 · April 28, 2022; effective September 28, 2022
Mandatory cybersecurity directions for Indian organizations covering incident reporting, log retention, and NTP synchronization.
Overview
CERT-In issued directions under Section 70B(6) of the Information Technology Act, 2000, on April 28, 2022. These directions became effective on September 28, 2022, after an initial implementation period. The directions apply to service providers, intermediaries, data centers, body corporates, and government organizations in India. Three core obligations were introduced: mandatory reporting of twenty categories of cyber security incidents to CERT-In within six hours of becoming aware of the incident, mandatory retention of ICT logs including system and network logs for a rolling 180-day period within India, and mandatory synchronization of all ICT system clocks with the National Physical Laboratory or National Informatics Centre's Network Time Protocol servers.
The six-hour reporting timeline for cyber incidents is among the shortest mandatory incident reporting windows in the world. The twenty incident types requiring mandatory reporting include targeted scanning or probing of networks, compromise of critical systems, unauthorized access to IT systems, identity theft, spoofing, phishing, denial of service attacks, attacks on critical infrastructure, attacks on Internet of Things devices, and malware deployment. VPN service providers, virtual asset service providers, virtual asset exchange providers, and cloud service providers are required to maintain accurate and comprehensive subscriber records including names, validated addresses, contact numbers, IP addresses assigned, and usage patterns for five years after subscriber cancellation. CERT-In has the power to direct any organization to provide information or assistance, inspect systems, and issue directions for enhancement of cybersecurity practices.
Who Needs This
All service providers and intermediaries operating in India under the IT Act 2000
Data centers hosting infrastructure for Indian organizations or international organizations with Indian operations
VPN service providers offering services to users in India
Cloud service providers with Indian customers or infrastructure in India
Body corporates and companies with IT systems operating in India, regardless of size
Structure at a Glance
Mandatory reporting of 20 defined cyber incident types to CERT-In within 6 hours of awareness, using the prescribed reporting format through the CERT-In portal.
Mandatory retention of logs of ICT systems including servers, networks, applications, and security devices for a rolling 180-day period. Logs must be stored within India.
All ICT infrastructure within India must synchronize clocks with NTP servers of the National Physical Laboratory or National Informatics Centre.
VPN providers, cloud service providers, and virtual asset service providers must maintain verified subscriber records for five years after the subscriber relationship ends.
AI Prompt Recipes
Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.
Cyber Incident Notification Drafting
Use this when preparing a mandatory CERT-In incident notification within the 6-hour window.
You are a cybersecurity compliance officer at an Indian organization subject to CERT-In Directions 2022. A cyber incident occurred: [DESCRIBE THE INCIDENT, WHEN IT WAS DISCOVERED, AND INITIAL IMPACT ASSESSMENT]. Incident category from CERT-In's 20 defined types that applies: [IDENTIFY APPLICABLE CATEGORY]. Draft a mandatory incident report for submission to CERT-In through the cybercrime portal. The report must include: incident type and category, date and time of discovery, affected systems and estimated number of affected users, initial impact description, steps already taken in response, and contact details for the incident response point of contact. Note any information not yet available due to ongoing investigation.
Log Retention Architecture Review
Use this to assess whether your log infrastructure satisfies the 180-day in-India requirement.
Review my organization's log retention architecture for compliance with CERT-In Directions 2022. Our current setup: [DESCRIBE LOG SOURCES, COLLECTION SYSTEMS, STORAGE LOCATIONS, AND RETENTION SETTINGS]. We operate: [DESCRIBE YOUR INDIA FOOTPRINT — DATA CENTERS, CLOUD REGIONS, OFFICES]. For each log category — server logs, network device logs, application logs, and security device logs — assess: (1) whether current retention meets the 180-day rolling requirement, (2) whether all storage is located within India or whether any logs are sent to overseas SIEM or log management systems, (3) gaps in log source coverage, and (4) recommended remediation for any gaps.
VPN or Cloud Provider Compliance Assessment
Use this if your organization provides VPN or cloud services to Indian subscribers.
My organization provides [VPN SERVICES / CLOUD SERVICES / VIRTUAL ASSET SERVICES] to users in India. Assess our compliance with CERT-In Directions 2022 subscriber record requirements. Current subscriber data collected: [DESCRIBE WHAT IS COLLECTED AT ONBOARDING AND ONGOING]. Current retention period: [DESCRIBE]. For compliance with the five-year post-cancellation retention requirement, identify: (1) what specific data elements must be collected and validated at onboarding, (2) what usage data must be retained and for which period, (3) what process changes are needed to verify subscriber identity, and (4) how to structure data storage to provide CERT-In access on demand within the required response window.
Common Pitfalls
These are the mistakes practitioners see repeatedly in real assessments and implementation projects.
Misunderstanding the six-hour clock. The window starts when the organization becomes aware of the incident, not when the incident occurred or when the investigation concludes. Reporting with incomplete information is expected and accepted. Delayed reporting while awaiting a complete picture is not.
Log storage sent to overseas SIEM systems. Many organizations route their India logs to cloud-based SIEM systems hosted outside India. The CERT-In Directions require logs to be stored within India. A local copy or India-region storage must be maintained.
NTP synchronization treated as a default system setting. Many organizations assume their systems are already synchronizing correctly. The Directions specifically require synchronization with NPL or NIC servers. Third-party NTP pools, even reputable ones, do not satisfy the requirement.
Assuming applicability only to large organizations. The Directions apply to all body corporates and organizations under the IT Act, not just those above a turnover or employee threshold. Small and mid-sized technology companies are equally subject.
Treating the 20 incident categories as an exhaustive list for internal detection. The 20 categories define what must be reported to CERT-In. Internal incident response should cover a much broader set of events. Conflating reporting scope with detection scope weakens overall security posture.
Cross-Framework Mapping
DPDPA
CERT-In Directions and DPDPA operate simultaneously in India. CERT-In mandates incident reporting to the government. DPDPA requires breach notification to affected individuals. An organization experiencing a data breach involving personal data must comply with both independently.
ISO 27001
ISO 27001 Annex A.5.24 through A.5.28 cover incident management. Certified organizations have incident management processes in place but must adapt them specifically to meet the six-hour CERT-In reporting window and the prescribed report format.
NIST CSF 2.0
The RESPOND function of NIST CSF 2.0 covers incident management and reporting. The six-hour CERT-In window imposes a specific operational requirement on the RS.MA and RS.CO categories.
All content sourced from official issuing body documentation.
Official source ↗