Published 24 June 2026 · Dravincon Security Team
CERT-In's directions of 28 April 2022 under Section 70B of the IT Act apply to service providers, intermediaries, data centres, body corporates and government organisations. Four requirements catch organisations out most often.
1. Report within 6 hours
Reportable cyber incidents — including targeted scanning, compromise of critical systems, unauthorised access, website defacement, malicious code, identity theft, data breaches and attacks on servers and applications — must be reported to CERT-In within 6 hours of noticing them or being told about them.
2. Keep logs for 180 days, in India
Logs of all ICT systems must be maintained securely for a rolling period of 180 days within Indian jurisdiction and provided to CERT-In on request.
3. Synchronise clocks
System clocks should be synchronised with NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or with sources traceable to them — so that timelines across systems line up during an investigation.
4. Name a point of contact
Designate a Point of Contact to interface with CERT-In and share their details in the prescribed format.
Checklist
- Incident severity matrix that flags CERT-In-reportable events
- On-call rota that can make the 6-hour deadline at night and weekends
- Pre-filled reporting template and contact details
- Central log collection with 180-day retention in India
- NTP configured to NIC/NPL on all servers and network devices
- Annual tabletop exercise including a DPDP breach-notification step
Our SOC and MDR services are built around these requirements.