CERT-In Directions 2022:
the 6-hour rule and the rest.
The CERT-In Directions of 28 April 2022 require any organisation that notices one of 20 incident types to report it to CERT-In within six hours, keep 180 days of logs in India, synchronise clocks to a standard time source and name a point of contact. Here is what each direction asks, who it covers, and what CERT-In's own FAQs clarified.
Last updated Published by TryTrustableNot legal advice
What are the CERT-In Directions?
The CERT-In Directions are six binding instructions issued on 28 April 2022 by the Indian Computer Emergency Response Team under section 70B(6) of the IT Act. They cover clock synchronisation, six-hour incident reporting, a point of contact, 180-day log retention, customer records for hosting and VPN providers, and KYC records for virtual asset businesses.
The Directions (No. 20(3)/2022-CERT-In) sit on top of the CERT-In Rules of 2013, whose Rule 12 already required certain incidents to be reported. What the 2022 Directions added was a hard clock, a longer list of incident types and the logging and customer-record duties. They took effect 60 days after issue, at the end of June 2022. A CERT-In order of 27 June 2022 moved the date to 25 September 2022 for MSMEs, and for the customer-name and address validation duties of data centres, VPS, cloud and VPN providers.
CERT-In published a set of FAQs in May 2022. They are expressly not a legal document and do not amend the Directions, but they are the regulator's own reading, and several answers below rely on them.
Who must comply with the CERT-In Directions?
Every service provider, intermediary, data centre, body corporate and government organisation must report listed incidents, keep logs, synchronise clocks and name a point of contact. VPS, cloud, VPN and data centre providers have extra customer-record duties, and virtual asset businesses extra KYC duties. Individual citizens are not covered.
'Body corporate' is wide. CERT-In's FAQ 25 points to section 43A of the IT Act: any company, including a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. In practice almost every business with an IT system is in scope for the reporting duty. FAQ 26 says the Directions apply to any entity in the matter of cyber incidents, and FAQ 28 confirms that includes online gaming companies. FAQ 29 requires entities offering services to users in India to designate a point of contact even without a physical presence here.
The six directions, one by one
| Direction | What it requires | Who |
|---|---|---|
| (i) Clock sync | Connect to the NTP servers of NIC or NPL, or to servers traceable to them, for all ICT system clocks. Multi-geography infrastructure may use another accurate standard source that does not deviate from NIC and NPL. | Everyone in scope |
| (ii) 6-hour reporting | Report any Annexure I incident to CERT-In within six hours of noticing it or being told of it, by email to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969. | Everyone in scope |
| (iii) Point of contact | Act on CERT-In orders within the format and timeframe they set, and designate a point of contact using the Annexure II format (name, designation, organisation, address, email, mobile, office phone, fax), sent to info@cert-in.org.in and kept up to date. | Everyone in scope |
| (iv) Logs | Enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction. Provide them with an incident report or when directed. | Everyone in scope |
| (v) Customer records | Keep validated customer names, hire period, IPs allotted, the email, IP and timestamp used at registration, purpose of hire, validated address and contact numbers, and ownership pattern, for five years after the registration ends. | Data centres, VPS, cloud and VPN providers |
| (vi) KYC and transactions | Keep KYC information and financial transaction records for five years, detailed enough to reconstruct individual transactions. | Virtual asset service providers, exchanges and custodian wallet providers |
Paraphrased from the Directions of 28 April 2022. Check the text for the exact wording.
Two clarifications from the FAQs matter most for ordinary companies. On direction (v), FAQ 34 says the VPN duties cover internet-proxy-style VPN services sold to the public, not enterprise VPNs used by staff. On direction (i), FAQ 40 says clocks do not need to be set to IST, but the time zone must be recorded with the time, and FAQ 42 lets cloud customers keep using their provider's native time service.
Which incidents must be reported to CERT-In within 6 hours?
Annexure I lists 20 incident types, from targeted scanning and website defacement to ransomware, data breaches, data leaks, attacks on cloud systems and attacks on AI and machine-learning systems. Any of them must be reported within six hours of noticing it. The list is not limited to incidents that involve personal data.
| # | Incident type (Annexure I) |
|---|---|
| i | Targeted scanning or probing of critical networks and systems |
| ii | Compromise of critical systems or information |
| iii | Unauthorised access of IT systems or data |
| iv | Defacement of a website, or intrusion into a website and unauthorised changes such as inserting malicious code or links to external websites |
| v | Malicious code attacks: virus, worm, Trojan, bots, spyware, ransomware, cryptominers |
| vi | Attacks on servers such as database, mail and DNS, and network devices such as routers |
| vii | Identity theft, spoofing and phishing attacks |
| viii | Denial of service (DoS) and distributed denial of service (DDoS) attacks |
| ix | Attacks on critical infrastructure, SCADA and operational technology systems, and wireless networks |
| x | Attacks on applications such as e-governance and e-commerce |
| xi | Data breach |
| xii | Data leak |
| xiii | Attacks on Internet of Things (IoT) devices and associated systems, networks, software and servers |
| xiv | Attacks or incidents affecting digital payment systems |
| xv | Attacks through malicious mobile apps |
| xvi | Fake mobile apps |
| xvii | Unauthorised access to social media accounts |
| xviii | Attacks or malicious or suspicious activity affecting cloud computing systems, servers, software or applications |
| xix | Attacks or malicious or suspicious activity affecting systems related to big data, blockchain, virtual assets, virtual asset exchanges, custodian wallets, robotics, 3D and 4D printing, additive manufacturing and drones |
| xx | Attacks or malicious or suspicious activity affecting systems related to artificial intelligence and machine learning |
Annexure I lists exactly 20 types, numbered (i) to (xx). CERT-In's FAQs explain each one.
CERT-In's FAQ 30 narrows the practical focus. It says incidents that meet any of these criteria should be reported within the six hours: severe incidents such as DoS, DDoS, intrusion or ransomware on any part of the public information infrastructure; data breaches or data leaks; large-scale or most frequent incidents such as intrusion into computer resources or websites; and incidents affecting human safety. Reporting a standalone vulnerability, unconnected to an incident, is not mandatory (FAQ 15).
The incident reporting form asks for the reporter's details, the affected entity, the incident type, whether the system is mission-critical, the domain, IP, operating system, cloud details, affected application, location, ISP, a description, and the occurrence and detection times. The form itself says filling it in is optional: the same facts in an email are acceptable.
When does the six-hour clock start?
The six hours run from noticing the incident or being brought to notice of it. They do not run from when the attack happened, and they do not wait for the investigation to finish. CERT-In's FAQ 24 says an incident that went undetected for a long time still gets six hours from the point it is noticed.
Two more FAQ answers shape the first six hours. FAQ 13: where a consumer business and its outsourcing partner are both affected, 'any entity which notices the cyber security incident shall report', and the obligation is not transferable, indemnifiable or dispensable by contract. FAQ 22: a confidentiality clause with a customer does not override the duty, because section 81 of the IT Act gives the Act overriding effect.
If the incident involves personal data, the CERT-In report is only the first of several. From 13 May 2027 the DPDP Act adds intimation to the Data Protection Board and each affected person, with a detailed report within 72 hours. The CERT-In vs DPDP breach reporting comparison puts the two side by side with a worked timeline.
Log retention and time sync in practice
The logging direction is short and wide: logs of all ICT systems, kept securely, for a rolling 180 days, in Indian jurisdiction. FAQ 37 gives examples rather than a list: firewall, IPS, SIEM, web, database, mail, FTP and proxy server logs, event logs of critical systems, application logs, ATM switch logs, SSH and VPN logs, recording both successful and unsuccessful events. FAQ 38 says a request for logs comes from a CERT-In officer not below the rank of Deputy Secretary.
On location there is an unresolved tension. The Direction says logs are maintained within Indian jurisdiction. FAQ 35 says they may be stored outside India as long as they can be produced to CERT-In in reasonable time; FAQ 36 says a service provider offering services to users in India must keep logs in Indian jurisdiction. A copy held in an Indian region is the reading that satisfies both.
The DPDP Rules add a separate floor. From 13 May 2027, Rule 6(1)(e) asks every Data Fiduciary to keep logs and personal data for one year so unauthorised access can be detected and investigated, and Rule 8(3) sets a one-year minimum for personal data, traffic data and processing logs. That is longer than CERT-In's 180 days, so a retention policy built only for CERT-In will fall short under DPDP.
How TryTrustable helps, and what it does not do
The CERT-In Directions are among the regimes on our coverage page, under India, for logging and incident reporting. What the platform actually contributes is evidence. The evidence ledger is append-only and hash-chained, timestamped at collection, and records failing control results as well as passes. That lets you show that logging and time-sync controls were operating before an incident, rather than screenshots taken after it.
The ledger is not a log store. Keeping 180 days of ICT logs in India is a job for your logging pipeline and your cloud region choice, and the platform does not report to CERT-In for you. For the notification itself, the breach notification template includes a CERT-In report skeleton, and the incident response plan template puts the six-hour clock into the plan.
The things people ask us
Who do the CERT-In Directions apply to?
Service providers, intermediaries, data centres, body corporate and government organisations. 'Body corporate' takes the IT Act section 43A meaning: any company, firm, sole proprietorship or association engaged in commercial or professional activity. VPS, cloud and VPN providers have extra customer-record duties, and virtual asset providers extra KYC duties. Individual citizens are not covered.
Do the Directions apply to foreign companies serving Indian users?
For incident reporting, yes. CERT-In's FAQs say the Directions apply to any entity in the matter of cyber incidents, and that service providers, intermediaries, data centres and body corporate offering services to users in India must designate a point of contact even without a physical presence here.
What if we do not have all the facts within six hours?
Report what you have. CERT-In's FAQs say entities may give information to the extent available at the time of reporting and send more later within reasonable time. The FAQs also say the six-hour window should be met for severe incidents, data breaches and data leaks, large-scale or frequent intrusions, and incidents affecting human safety.
Must our logs be stored in India?
The Directions say logs must be kept for a rolling 180 days within the Indian jurisdiction. CERT-In's FAQ 35 says logs may be stored outside India if you can produce them to CERT-In in reasonable time, while FAQ 36 says service providers offering services in India must keep them in Indian jurisdiction. The safe reading is a copy in India; take counsel's view.
Do we have to set every clock to IST or use the NIC and NPL servers?
No to IST: the FAQs say clocks need not be set to IST, but time zone must be recorded alongside time. On the servers, you may use another accurate standard source, such as your cloud provider's native time service, provided it does not deviate from NIC and NPL. The NIC servers are samay1.nic.in and samay2.nic.in; NPL's is time.nplindia.org.
Does a confidentiality clause stop us reporting to CERT-In?
No. CERT-In's FAQs say the reporting obligation is statutory and overrides any contractual confidentiality clause, relying on section 81 of the IT Act. They also say the obligation cannot be transferred to, or indemnified by, another party: if you notice an incident, you report it, even if a vendor also does.
Do the VPN customer-record rules apply to our corporate VPN?
No. CERT-In's FAQ 34 says the VPN provisions cover entities offering internet-proxy-like VPN services to general internet users, not enterprise or corporate VPNs used by staff. Data centres, VPS providers, cloud service providers and consumer VPN providers must keep the listed customer records for five years.
What is the penalty for not complying?
Section 70B(7) of the IT Act: imprisonment of up to one year, a fine of up to ₹1 lakh, or both, for failing to provide information called for or to comply with a direction. CERT-In's FAQs say the power will be used reasonably and where non-compliance is deliberate.
Show the control was working before the incident.
Thirty minutes. We connect one cloud account live and show you timestamped, hash-chained evidence landing in the ledger before the call ends.