Do I have to report this to CERT-In?
India's CERT-In Directions give most organisations six hours to report a cyber incident. Answer four questions about who you are and what happened, and see whether the six-hour duty applies, how to report, and what else follows if personal data is involved. Nothing you enter leaves your browser.
Yes, if it is one of the 20 incident types listed in the CERT-In Directions of 28 April 2022, such as unauthorised access, a data breach or leak, ransomware, DDoS or phishing. Any service provider, intermediary, data centre, body corporate or government organisation must report it to CERT-In within six hours of noticing it, with whatever facts it has. A vulnerability alone need not be reported.
Result
This is one of the 20 incident types in Annexure I of the CERT-In Directions of 28 April 2022, issued under section 70B(6) of the IT Act. Every service provider, intermediary, data centre, body corporate and government organisation must report it to CERT-In within six hours of noticing it or being told about it. You do not need the full picture: report what you know and follow up.
- Draft: start from the breach notification template for India and the incident response plan.
- Deadlines: put the CERT-In, DPDP and GDPR clocks on one timeline with the breach notification deadline calculator.
- Two reports: a CERT-In report does not discharge the DPDP duty, or the other way round. See CERT-In vs DPDP breach reporting.
- Sector: banks, insurers, market intermediaries and telecom operators have their own regulator's reporting rules on top. See the RBI, SEBI and IRDAI guides.
- Standing duties: keep clocks synced to NIC or NPL time, logs kept for 180 days, and a Point of Contact registered with CERT-In. The CERT-In Directions guide covers each.
The six-hour rule
CERT-In's Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, require every service provider, intermediary, data centre, body corporate and government organisation to report the cyber incidents listed in Annexure I within six hours of noticing them or being told about them. They took effect 60 days after issue, and on 25 September 2022 for MSMEs, under a later direction.
Reports go to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969. The incident reporting form on cert-in.org.in sets out the fields: who is reporting, the affected entity and systems, the incident type, and when it occurred and was detected. CERT-In's FAQs say a first report can carry the information available at the time, with the rest sent later. They single out severe incidents on public infrastructure, data breaches and leaks, large-scale or frequent intrusions, and incidents affecting human safety as ones to report within the six hours.
The 20 incident types
Annexure I lists: targeted scanning or probing of critical networks or systems; compromise of critical systems or information; unauthorised access to IT systems or data; website defacement or intrusion; malicious code such as viruses, worms, trojans, bots, spyware, ransomware and cryptominers; attacks on servers such as database, mail and DNS, and on network devices; identity theft, spoofing and phishing; DoS and DDoS; attacks on critical infrastructure, SCADA, operational technology and wireless networks; attacks on applications such as e-governance and e-commerce; data breach; data leak; attacks on IoT devices; attacks affecting digital payment systems; malicious mobile apps; fake mobile apps; unauthorised access to social media accounts; attacks on cloud systems; attacks on big data, blockchain, virtual asset, robotics, 3D printing and drone systems; and attacks on AI and machine learning systems.
Logs, clocks and records you must keep anyway
The reporting duty comes with standing obligations that apply before any incident:
- Logs: enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction, to hand over with a report or on CERT-In's order. CERT-In's FAQ adds that logs may also be stored abroad if they can be produced in reasonable time, while a provider offering services to users in India keeps them in India. Read the two answers with counsel.
- Clocks: synchronise all ICT system clocks with NTP servers of the National Informatics Centre or National Physical Laboratory, or a source that does not deviate from them. Clocks do not have to be set to IST.
- Point of Contact: designate one to deal with CERT-In and send its details in the Annexure II format.
- Data centres, VPS, cloud and VPN providers: keep validated subscriber names, hire periods, allotted IPs, registration email, IP and timestamp, purpose, validated address and contact numbers, and ownership pattern for five years after the service ends. Corporate VPNs used by staff are not covered; the rule is for VPN services offered to the public.
- Virtual asset providers: keep KYC and transaction records for five years.
How CERT-In reporting relates to DPDP breach reporting
They are separate duties under separate laws, and one report does not discharge the other. CERT-In's six hours cover cyber incidents with or without personal data, and go to CERT-In. The DPDP Act's duty covers personal data breaches only, falls on the Data Fiduciary, and from 13 May 2027 requires notice to the Data Protection Board and to each affected person, with a detailed report to the Board within 72 hours. The side-by-side comparison sets out content and channels, and the deadline calculator gives you every clock from one start time.
Penalties
Failing to provide information or comply with the Directions can be punished under section 70B(7) of the IT Act with imprisonment of up to one year, a fine of up to ₹1 lakh, or both. CERT-In's FAQ says the power will be used reasonably and where non-compliance is deliberate. That is not a reason to be late: sector regulators and customers judge the report too.
Sources
- CERT-In: Directions under section 70B(6) of the IT Act, 28 April 2022
- CERT-In: FAQs on the Cyber Security Directions, May 2022
- CERT-In: Extension of timelines for MSMEs and validation, 27 June 2022
- CERT-In: Incident reporting form
- CERT-In: Directions page
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
What is the CERT-In reporting timeline?
Six hours from noticing an Annexure I incident or being told about it. The first report can contain only what you know at that point; further detail can follow within a reasonable time.
Is there an official CERT-In incident reporting form?
Yes. CERT-In publishes an incident reporting form on cert-in.org.in that sets out the fields it wants. Reports go by email to incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969.
Do foreign companies have to report to CERT-In?
CERT-In's FAQ says the Directions apply to any entity in the matter of cyber incidents, and that providers offering services to users in India must designate a Point of Contact. A foreign SaaS company with Indian users should plan on reporting.
Who reports if the incident happened at our vendor?
Any entity that notices the incident must report it. CERT-In's FAQ says the obligation cannot be transferred or waived by contract, so you and the vendor may each have to report.
Do we have to report a vulnerability to CERT-In?
Not on its own. CERT-In's FAQ says reporting a vulnerability that is not connected with an incident is not mandatory at present. Once it has been exploited, the incident is reportable.
How long must logs be kept for CERT-In?
A rolling 180 days for all ICT systems, kept securely and within Indian jurisdiction, and provided with an incident report or when CERT-In orders it.
Does the CERT-In rule apply to startups and MSMEs?
Yes. MSMEs got extra time, to 25 September 2022, and the Directions have applied to them since. Any company in commercial activity is a body corporate under the IT Act.
What is the penalty for not reporting to CERT-In?
Up to one year's imprisonment, a fine of up to ₹1 lakh, or both, under section 70B(7) of the IT Act.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.