CERT-In directions 2022: 6-hour incident reporting and 180-day log retention

What CERT-In's directions of 28 April 2022 require: report listed cyber incidents within 6 hours, keep ICT logs for 180 days, and sync clocks to NIC or NPL.

Ahuva Electronic Technologies · Published

Key points

  • CERT-In's directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, require listed cyber incidents to be reported to CERT-In within 6 hours of noticing them.
  • The CERT-In directions apply to service providers, intermediaries, data centres, body corporate and Government organisations. CERT-In's own FAQ says individual citizens are not covered.
  • Every covered entity must enable logs of all its information and communication technology (ICT) systems and keep them securely for a rolling period of 180 days, within Indian jurisdiction.
  • ICT system clocks must be synchronised to the Network Time Protocol (NTP) servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or to a time source that does not deviate from them.
  • The CERT-In directions took effect 60 days after issue, on 27 June 2022. CERT-In moved the date to 25 September 2022 for micro, small and medium enterprises (MSMEs).
  • As of September 2026, CERT-In's directions page lists no amendment to the 2022 directions. Personal data breaches will also have to be reported to the Data Protection Board of India once the Digital Personal Data Protection (DPDP) Rules take full effect in May 2027.

What are the CERT-In directions of 28 April 2022?

They are six binding directions on cyber security practice and incident reporting, issued by CERT-In on 28 April 2022 under sub-section (6) of section 70B of the Information Technology Act, 2000 (IT Act). The document is numbered 20(3)/2022-CERT-In.

CERT-In, the Indian Computer Emergency Response Team, is the national agency for cyber incident response. It sits under the Ministry of Electronics and Information Technology (MeitY) and was appointed under section 70B(1) of the IT Act by a notification dated 27 October 2009. Section 70B(6) lets CERT-In call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person.

  • Synchronise all ICT system clocks to NIC or NPL time, or to a source traceable to them
  • Report the incident types listed in Annexure I to CERT-In within 6 hours of noticing them
  • Name a Point of Contact for CERT-In, and act on CERT-In's orders within the time it sets
  • Enable logs of all ICT systems and keep them for a rolling 180 days within Indian jurisdiction
  • Data centres, virtual private server (VPS), cloud and virtual private network (VPN) service providers: keep validated subscriber records for 5 years
  • Virtual asset service providers, exchanges and custodian wallets: keep know-your-customer (KYC) and transaction records for 5 years

Who do the CERT-In directions apply to?

The CERT-In directions apply to service providers, intermediaries, data centres, body corporate and Government organisations. CERT-In's FAQ of May 2022 adds VPS providers, cloud service providers, VPN service providers and virtual asset businesses to that list, and says individual citizens are not covered.

Body corporate is read widely. The CERT-In FAQ points to the IT Act's own definition: any company, including a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. The FAQ also says the reporting duty applies to any entity whatsoever in the matter of cyber incidents, including foreign firms serving Indian users. For a public institution, this means a hospital, university, municipal corporation or public sector undertaking (PSU) is covered, and so are the contractors that run its systems.

The reporting duty cannot be handed off by contract. The CERT-In FAQ says any entity that notices a cyber security incident must report it, and that the obligation is neither transferable nor indemnified. It also says the statutory duty overrides a confidentiality clause in a contract, by virtue of section 81 of the IT Act. The 5-year subscriber records apply to data centres, VPS providers, cloud service providers and VPN service providers. For VPNs, CERT-In's FAQ limits this to providers offering proxy-like VPN services to general internet users, and says an enterprise or corporate VPN is not covered.

What has to be reported to CERT-In within 6 hours, and how?

The 20 types of incident listed in Annexure I of the CERT-In directions must be reported within 6 hours of noticing them or being told about them. Reports go by email to incident@cert-in.org.in, by phone to 1800-11-4949 or by fax to 1800-11-6969. CERT-In publishes its reporting formats on www.cert-in.org.in.

The 6 hours is for a first report, not a finished investigation. CERT-In's FAQ says an entity may report the information available at the time and send the rest later, within a reasonable time. The FAQ adds that Annexure I incidents meeting any of these criteria should be reported within the 6 hours: severe incidents such as denial of service, intrusion or ransomware on any part of public information infrastructure; data breaches or data leaks; large-scale or frequent incidents such as intrusion into computer resources or websites; and incidents affecting the safety of human beings.

Each entity must also send CERT-In the details of a Point of Contact, using the format in Annexure II, by email to info@cert-in.org.in. CERT-In sends its information requests and directions to that person.

  • Targeted scanning or probing of critical networks and systems
  • Compromise of critical systems or information, and unauthorised access to IT systems or data
  • Website defacement, or intrusion that inserts malicious code or links
  • Malicious code, including ransomware, trojans, bots, spyware and cryptominers
  • Attacks on database, mail and DNS servers, and on network devices such as routers
  • Denial of service (DoS) and distributed denial of service (DDoS) attacks
  • Attacks on critical infrastructure, supervisory control and data acquisition (SCADA) and operational technology systems, and on wireless networks
  • Data breaches and data leaks
  • Attacks on Internet of Things (IoT) devices and their systems, networks and servers
  • Attacks on e-governance and e-commerce applications, digital payment systems, cloud systems, and AI and machine learning systems

What does the 180-day log retention rule require?

All covered entities must enable logs of all their ICT systems and keep them securely for a rolling 180 days, within Indian jurisdiction. The logs must be given to CERT-In with an incident report, or when CERT-In orders it.

The CERT-In directions do not list which logs. CERT-In's FAQ gives examples: firewall, intrusion prevention system (IPS) and security information and event management (SIEM) logs; web, database, mail, FTP and proxy server logs; event logs of critical systems; application logs; SSH and VPN logs. The FAQ says the list is not exhaustive, and that both successful and unsuccessful events should be recorded. It also says a request for logs comes from a CERT-In officer not below the rank of Deputy Secretary to the Government of India.

The location rule needs care. Direction (iv) says logs shall be maintained within Indian jurisdiction. CERT-In's FAQ says a copy may also be stored outside India as long as logs can be produced to CERT-In in reasonable time, and that any provider serving users in India must keep logs in Indian jurisdiction. The safe reading is to keep the retained copy in India. For Central Government bodies, CERT-In's Guidelines on Information Security Practices for Government Entities, released on 30 June 2023, also ask for logs of perimeter devices and the SIEM to be kept for a rolling 180 days. Sizing a SIEM for this is covered in the SOC, SIEM and SOAR guide.

Which time servers does CERT-In require, and why?

CERT-In requires ICT clocks to be synchronised to the NTP servers of NIC or NPL, or to servers traceable to them. CERT-In's FAQ lists samay1.nic.in and samay2.nic.in for NIC, and time.nplindia.org for NPL.

The reason is evidence. CERT-In's FAQ explains that an incident usually spans many systems, and without accurate timestamps the order of events cannot be rebuilt. Correlation rules in security tools also depend on time. The FAQ says clocks need not be set to Indian Standard Time: NTP gives UTC, and the time zone should be recorded with each log entry. Organisations spanning several countries, and cloud users relying on the cloud's native time service, may use another accurate source as long as it does not deviate from NIC and NPL.

In practice, one or two internal NTP servers take time from NIC or NPL, and every camera, controller, server, firewall and switch takes time from them. Surveillance and access-control devices are often missed, which matters when their records are used as evidence.

What are the penalties, and has anything changed since 2022?

Failing to provide information or comply with a direction under section 70B(6) is punishable under section 70B(7) of the IT Act with imprisonment of up to one year, a fine of up to one lakh rupees, or both. CERT-In's FAQ says this power will be used reasonably, when non-compliance is deliberate.

Three things have happened since April 2022. On 27 June 2022, CERT-In moved the effective date to 25 September 2022 for MSMEs, and for the validated names and addresses that data centre, VPS, cloud and VPN providers must record. On 30 June 2023, CERT-In released baseline guidelines for Central Government entities. And on 14 November 2025, MeitY published the Digital Personal Data Protection (DPDP) Rules, 2025, which add a separate breach-reporting duty to the Data Protection Board of India from May 2027. As of September 2026, CERT-In's directions page lists only the 2022 directions, the May 2022 FAQ and the June 2022 extension.

The CERT-In and DPDP duties do not replace each other. A personal data breach at a covered entity will need both reports.

CERT-In incident reporting compared with DPDP breach intimation
CERT-In directions, 2022DPDP Rules, 2025 (rule 7)
Reported toCERT-InData Protection Board and each affected person
What triggers itAny of 20 listed cyber incident typesAny personal data breach
DeadlineWithin 6 hours of noticingWithout delay; detailed report to the Board within 72 hours
Who must reportEvery covered entity that notices itThe Data Fiduciary
In force from27 June 202218 months after 14 November 2025 (May 2027)

What should a buyer write into a tender or contract?

A buyer should write the CERT-In duties into the contract as measurable obligations on the integrator and operator, because the owner is the one CERT-In will ask.

  • NTP configuration to NIC or NPL time for every device, including cameras, controllers and access-control panels
  • An inventory of log sources, with logging enabled on each at handover
  • 180-day rolling log retention, stored in India, with the storage sized in the design
  • Log export in an open format when CERT-In asks, within hours, not days
  • Escalation to the owner's Point of Contact soon enough for the owner to report within 6 hours
  • The contractor's own duty to report incidents it notices, stated plainly, since CERT-In's FAQ says the duty cannot be transferred

How Ahuva approaches cybersecurity work

Ahuva entered cybersecurity in 2025, covering network and information security. Its scope includes network, endpoint and application security; SOC, SIEM and SOAR; NGFW, IDS/IPS, WAF and zero-trust; and VAPT and compliance. Ahuva holds ISO 27001:2022 for information security management.

Frequently asked questions

Does the CERT-In 6-hour rule apply to government hospitals and universities?
Yes. The CERT-In directions of 28 April 2022 name Government organisations alongside service providers, data centres and body corporate, so public institutions must report listed incidents within 6 hours.
Do I need the full investigation before reporting to CERT-In?
No. CERT-In's FAQ says an entity may report what it knows within 6 hours and send further details later, within a reasonable time.
Can logs required by CERT-In be kept in a cloud outside India?
Direction (iv) says logs shall be maintained within Indian jurisdiction. CERT-In's FAQ allows an additional copy abroad if logs can be produced in reasonable time, so the retained copy is safest kept in India.
Can an integrator or managed service provider report to CERT-In on the owner's behalf?
CERT-In's FAQ says any entity that notices an incident must report it, and that the obligation cannot be transferred by contract. Both the owner and the provider may need to report.
What is the penalty for not following the CERT-In directions?
Section 70B(7) of the IT Act provides for imprisonment of up to one year, a fine of up to one lakh rupees, or both.

Sources

  1. Directions under sub-section (6) of section 70B of the IT Act, 2000 (No. 20(3)/2022-CERT-In, 28 April 2022) · CERT-In, Ministry of Electronics and Information Technology
  2. Frequently Asked Questions on Cyber Security Directions of 28.04.2022 (May 2022) · CERT-In
  3. Extension of timelines for enforcement of Cyber Security Directions for MSMEs (27 June 2022) · CERT-In
  4. Directions by CERT-In under Section 70B, Information Technology Act 2000 · CERT-In
  5. Guidelines on Information Security Practices for Government Entities · CERT-In
  6. Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) · Ministry of Electronics and Information Technology

Scoping a system like this? Talk to the team that designs, builds and maintains it.

Contact us