Free tool · CERT-In

Do I have to report this to CERT-In?

India's CERT-In Directions give most organisations six hours to report a cyber incident. Answer four questions about who you are and what happened, and see whether the six-hour duty applies, how to report, and what else follows if personal data is involved. Nothing you enter leaves your browser.

Short answer

Yes, if it is one of the 20 incident types listed in the CERT-In Directions of 28 April 2022, such as unauthorised access, a data breach or leak, ransomware, DDoS or phishing. Any service provider, intermediary, data centre, body corporate or government organisation must report it to CERT-In within six hours of noticing it, with whatever facts it has. A vulnerability alone need not be reported.

Answer for your organisation

Body corporate includes any company, firm, sole proprietorship or association in commercial or professional activity (IT Act s.43A).
Annexure I lists 20 types, including targeted scanning of critical systems, compromise of critical systems, unauthorised access, website defacement, malware and ransomware, attacks on servers, identity theft and phishing, DoS and DDoS, data breach, data leak, attacks on cloud, IoT, payment systems, AI or ML systems, and unauthorised access to social media accounts.
Worked example: an Indian SaaS company with an unauthorised access to customer data

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Required: report it to CERT-In within six hours, and plan the DPDP notice

This is one of the 20 incident types in Annexure I of the CERT-In Directions of 28 April 2022, issued under section 70B(6) of the IT Act. Every service provider, intermediary, data centre, body corporate and government organisation must report it to CERT-In within six hours of noticing it or being told about it. You do not need the full picture: report what you know and follow up.

Report to CERT-In within 6 hours of noticing the incident or being told of it, with what you know; send the rest laterDirections (ii); FAQ Q30
By email to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969. The incident reporting form gives the formatDirections (ii)
Send relevant logs with the report or when CERT-In asks; logs of all ICT systems must be kept for a rolling 180 daysDirections (iv)
Act on CERT-In's follow-up orders and give information in the format and time it sets, through your registered Point of ContactDirections (iii)
Personal data: from 13 May 2027, also tell the Data Protection Board and each affected person without delay, with a detailed report to the Board within 72 hoursDPDP Act s.8(6), Rule 7
If people in the EU or UK are affected, the GDPR or UK GDPR clock is 72 hours to the supervisory authority, where feasibleGDPR Art. 33
Failing to report or comply: up to one year's imprisonment, a fine up to ₹1 lakh, or bothIT Act s.70B(7)
01

The six-hour rule

CERT-In's Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, require every service provider, intermediary, data centre, body corporate and government organisation to report the cyber incidents listed in Annexure I within six hours of noticing them or being told about them. They took effect 60 days after issue, and on 25 September 2022 for MSMEs, under a later direction.

Reports go to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969. The incident reporting form on cert-in.org.in sets out the fields: who is reporting, the affected entity and systems, the incident type, and when it occurred and was detected. CERT-In's FAQs say a first report can carry the information available at the time, with the rest sent later. They single out severe incidents on public infrastructure, data breaches and leaks, large-scale or frequent intrusions, and incidents affecting human safety as ones to report within the six hours.

02

The 20 incident types

Annexure I lists: targeted scanning or probing of critical networks or systems; compromise of critical systems or information; unauthorised access to IT systems or data; website defacement or intrusion; malicious code such as viruses, worms, trojans, bots, spyware, ransomware and cryptominers; attacks on servers such as database, mail and DNS, and on network devices; identity theft, spoofing and phishing; DoS and DDoS; attacks on critical infrastructure, SCADA, operational technology and wireless networks; attacks on applications such as e-governance and e-commerce; data breach; data leak; attacks on IoT devices; attacks affecting digital payment systems; malicious mobile apps; fake mobile apps; unauthorised access to social media accounts; attacks on cloud systems; attacks on big data, blockchain, virtual asset, robotics, 3D printing and drone systems; and attacks on AI and machine learning systems.

03

Logs, clocks and records you must keep anyway

The reporting duty comes with standing obligations that apply before any incident:

  • Logs: enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction, to hand over with a report or on CERT-In's order. CERT-In's FAQ adds that logs may also be stored abroad if they can be produced in reasonable time, while a provider offering services to users in India keeps them in India. Read the two answers with counsel.
  • Clocks: synchronise all ICT system clocks with NTP servers of the National Informatics Centre or National Physical Laboratory, or a source that does not deviate from them. Clocks do not have to be set to IST.
  • Point of Contact: designate one to deal with CERT-In and send its details in the Annexure II format.
  • Data centres, VPS, cloud and VPN providers: keep validated subscriber names, hire periods, allotted IPs, registration email, IP and timestamp, purpose, validated address and contact numbers, and ownership pattern for five years after the service ends. Corporate VPNs used by staff are not covered; the rule is for VPN services offered to the public.
  • Virtual asset providers: keep KYC and transaction records for five years.
04

How CERT-In reporting relates to DPDP breach reporting

They are separate duties under separate laws, and one report does not discharge the other. CERT-In's six hours cover cyber incidents with or without personal data, and go to CERT-In. The DPDP Act's duty covers personal data breaches only, falls on the Data Fiduciary, and from 13 May 2027 requires notice to the Data Protection Board and to each affected person, with a detailed report to the Board within 72 hours. The side-by-side comparison sets out content and channels, and the deadline calculator gives you every clock from one start time.

05

Penalties

Failing to provide information or comply with the Directions can be punished under section 70B(7) of the IT Act with imprisonment of up to one year, a fine of up to ₹1 lakh, or both. CERT-In's FAQ says the power will be used reasonably and where non-compliance is deliberate. That is not a reason to be late: sector regulators and customers judge the report too.

06

Sources

Questions

The things people ask us

What is the CERT-In reporting timeline?

Six hours from noticing an Annexure I incident or being told about it. The first report can contain only what you know at that point; further detail can follow within a reasonable time.

Is there an official CERT-In incident reporting form?

Yes. CERT-In publishes an incident reporting form on cert-in.org.in that sets out the fields it wants. Reports go by email to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969.

Do foreign companies have to report to CERT-In?

CERT-In's FAQ says the Directions apply to any entity in the matter of cyber incidents, and that providers offering services to users in India must designate a Point of Contact. A foreign SaaS company with Indian users should plan on reporting.

Who reports if the incident happened at our vendor?

Any entity that notices the incident must report it. CERT-In's FAQ says the obligation cannot be transferred or waived by contract, so you and the vendor may each have to report.

Do we have to report a vulnerability to CERT-In?

Not on its own. CERT-In's FAQ says reporting a vulnerability that is not connected with an incident is not mandatory at present. Once it has been exploited, the incident is reportable.

How long must logs be kept for CERT-In?

A rolling 180 days for all ICT systems, kept securely and within Indian jurisdiction, and provided with an incident report or when CERT-In orders it.

Does the CERT-In rule apply to startups and MSMEs?

Yes. MSMEs got extra time, to 25 September 2022, and the Directions have applied to them since. Any company in commercial activity is a body corporate under the IT Act.

What is the penalty for not reporting to CERT-In?

Up to one year's imprisonment, a fine of up to ₹1 lakh, or both, under section 70B(7) of the IT Act.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.