CERT-In Directions (6-Hour Incident Reporting), 2022

CERT-In All Direction Active 28 Apr 2022

Applies to: All entities operating IT systems in India — no minimum threshold

The national baseline. Covered entities must report any of 20 categories of cyber incident to CERT-In within 6 hours of becoming aware of it — the clock starts at awareness, not at occurrence. Logs of all ICT systems must be maintained for a rolling 180 days and stored within Indian jurisdiction. The Directions also impose NTP time-synchronisation requirements and KYC/record-retention obligations on data centres, VPS and VPN providers, and cloud platforms. There is no size threshold — a freelancer on a VPS carries the same reporting obligation as a large enterprise. Penalty exposure under Section 70B(7) is currently up to INR 1 lakh; a proposed Jan Vishwas amendment to raise it to INR 1 crore is not yet in force as of mid-2026.
Why it matters
The 6-hour window is the common denominator across every Indian financial regulator (RBI, SEBI, IRDAI and PFRDA all reference or mirror it) — build your incident-response runbook to this SLA and you satisfy all of them at once. Two recurring failure points worth pre-empting: the 180-day retention must be held in-country (centralising logs to a US or EU SIEM without an India copy is non-compliant), and the clock runs from awareness, so your detection-to-triage handoff, not your forensics, decides whether you make the window. The widely circulated "5-year retention" figure is wrong — it is 180 days.