Directions · Cyber incidents · India

CERT-In compliance: 6-hour reporting, 180-day logs and audits

CERT-In compliance means following the Directions CERT-In issued on 28 April 2022 under Section 70B(6) of the IT Act. Service providers, intermediaries, data centres, body corporates and government bodies must report 20 types of cyber incident within 6 hours, keep ICT logs in India for 180 days and sync clocks to NIC or NPL.

Key takeaways

What you need to know about CERT-In

Broad scopeIt applies to almost every organisation running ICT systems in India.
Six hoursThe reporting clock starts when you notice the incident or are told about it.
Logs in IndiaKeep 180 days of logs for all ICT systems within Indian jurisdiction.
Named contactDesignate a Point of Contact and answer CERT-In requests on time.
Feeds other rulesRBI, SEBI and DPDP reporting all build on the same incident record.

Who must comply with CERT-In directions?

The Directions name service providers, intermediaries, data centres, body corporates and government organisations.

Companies in IndiaAny body corporate running ICT systems.
Service providers and intermediariesIncluding platforms and ISPs.
Data centre, cloud, VPS and VPN providersWith extra subscriber record duties.
Virtual asset providersExchanges and custodian wallets, with KYC duties.
Government organisationsCentral and state bodies.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the Directions require

What do the CERT-In directions require?

The CERT-In directions require you to report listed cyber incidents within six hours, keep 180 days of ICT logs in India, synchronise clocks to NIC or NPL, name a Point of Contact and answer CERT-In's requests.

(ii) Report

6-hour reporting

20 incident types in Annexure I.

In QULDEX: Six-hour timers
(iv) Logs

180-day logs in India

All ICT systems, kept securely.

In QULDEX: Retention evidence per system
(i) Time

NTP synchronisation

NIC, NPL or traceable sources.

In QULDEX: Time-source evidence
(iii) Contact

Point of Contact

Respond to CERT-In directions on time.

In QULDEX: PoC and request log
(v) Providers

Subscriber records

DC, VPS, cloud and VPN providers, 5 years.

In QULDEX: Record checks
(vi) Virtual assets

KYC records

Virtual asset providers, 5 years.

In QULDEX: Record checks
Direction explorer

What are the CERT-In directions and reportable incidents?

The six directions, the 20 reportable incident types (grouped) and the audit guidance. Select any one to see what it requires and how QULDEX handles it.

Apr 2022Directions issued
Jun 2022in effect
6 hreporting window
Jul 2025audit guidelines

Showing up to 6 per group. Search, filter, or open a group to see all 16.

The six directions 7

  1. Dir. (i)Clock synchronisationApplies to everyone

    Connect to the NTP servers of NIC or NPL, or servers traceable to them, to synchronise all ICT system clocks.

    In QULDEXTime-source settings are evidence per system.

    Typical evidence
    NTP configuration
    Maps to
    ISO 27001 A.8.17

  2. Dir. (ii)Report incidents within 6 hoursApplies to everyone

    Report the cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing them or being told about them.

    In QULDEXEvery incident starts a six-hour timer with the Annexure I type recorded.

    Typical evidence
    Incident reports
    Maps to
    ISO 27001 A.5.24–A.5.26

  3. Dir. (iii)Point of contact and information on request

    Designate a Point of Contact for CERT-In and provide information or take action when CERT-In directs, within the time it sets.

    In QULDEXThe PoC record and CERT-In requests are logged with deadlines.

    Typical evidence
    PoC registration, request log

  4. Dir. (iv)Logs for 180 days in IndiaApplies to everyone

    Enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction.

    In QULDEXLog retention and location are evidenced per system.

    Typical evidence
    Log retention settings
    Maps to
    ISO 27001 A.8.15

  5. Dir. (v)Subscriber records (DCs, VPS, cloud, VPN)

    Data centres, VPS, cloud and VPN providers record validated subscriber details, IPs, purpose and ownership for 5 years.

    In QULDEXRecord-keeping is a control with sample checks.

    Typical evidence
    Subscriber records

  6. Dir. (vi)KYC for virtual asset providers

    Virtual asset service providers, exchanges and custodian wallets keep KYC and transaction records for 5 years.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

    Typical evidence
    KYC and transaction records

  7. Sec. 70B(7)Penalty for non-compliance

    Failure to provide information or comply can attract action under Section 70B(7) of the IT Act: imprisonment up to one year, a fine up to ₹1 lakh, or both.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

Reportable incidents (Annexure I) 6

  1. Annex I (i–iii)Scanning, compromise, unauthorised access

    Targeted scanning of critical systems, compromise of critical systems or information, and unauthorised access to IT systems or data.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

  2. Annex I (iv–vi)Defacement, malware, server attacks

    Website defacement or intrusion, malicious code including ransomware, and attacks on servers and network devices.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

  3. Annex I (vii–viii)Phishing and DoS

    Identity theft, spoofing and phishing, and DoS or DDoS attacks.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

  4. Annex I (ix–x)Critical infrastructure and applications

    Attacks on critical infrastructure, SCADA, OT and wireless networks, and on applications such as e-governance and e-commerce.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

  5. Annex I (xi–xii)Data breach and data leak

    Data breaches and data leaks.

    In QULDEXA personal-data breach also triggers DPDP duties, tracked on the same record.

    Maps to
    DPDP Act Sec. 8(6)

  6. Annex I (xiii–xx)IoT, payments, apps, cloud, emerging tech

    Attacks on IoT, digital payment systems, malicious or fake mobile apps, social media accounts, cloud systems, blockchain and virtual assets, and AI and ML systems.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

Audits 3

  1. Audit 2025Comprehensive Cyber Security Audit Policy Guidelines

    CERT-In's July 2025 guidelines set a national, evidence-based approach to cyber security audits by empanelled auditors.

    In QULDEXAudits run in the audit workspace with evidence-based workpapers.

    Typical evidence
    Audit report

  2. EmpanelmentCERT-In empanelled auditors

    Many sector regulators require audits by CERT-In empanelled auditing organisations.

    In QULDEXAuditor details and scope are recorded per audit.

    Typical evidence
    Auditor engagement

  3. FAQsCERT-In FAQs on the Directions

    CERT-In's FAQs of May 2022 clarify scope, reporting and log questions.

    In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.

Direction numbers follow CERT-In Directions No. 20(3)/2022-CERT-In of 28 April 2022; incident types follow its Annexure I. Summaries are QULDEX paraphrases.

Compliance path

How do you comply with the CERT-In directions?

Name a Point of Contact, fix log retention and time sync, and build a six-hour reporting process you have actually tested. Most organisations need 1 to 3 months.

  1. Designate the Point of Contact

    Send PoC details to CERT-In in the Annexure II format and keep them current.

  2. Fix logging and retention

    Enable logs on all ICT systems and keep 180 days within India.

  3. Synchronise clocks

    Point systems at NIC or NPL NTP servers or traceable sources.

  4. Build six-hour reporting

    Map Annexure I types to your incident categories and set up the reporting workflow.

  5. Test it

    Run a tabletop exercise to prove a report can go out within six hours.

  6. Keep it running

    Every incidentReport within 6 hours
    Rolling180 days of logs
    YearlyCyber security audit where required

Durations are QULDEX planning ranges.

Records to keep

Which records do the CERT-In directions need?

Keep these ready for CERT-In and for auditors.

RecordDirectionWhere it lives in QULDEX
Point of Contact registration(iii), Annexure IIEvidence vault
Incident reports to CERT-In(ii)CAPA automation
Incident classification against Annexure I(ii)CAPA automation
Log retention evidence (180 days, in India)(iv)Evidence vault
NTP configuration(i)Evidence vault
Subscriber records (DC, VPS, cloud, VPN)(v)Evidence vault
KYC and transaction records (virtual assets)(vi)Evidence vault
Cyber security audit reportsAudit guidelinesAudit workspace

Record names are QULDEX recommendations based on the Directions.

Time and cost

How long does CERT-In compliance take and what drives the effort?

Most organisations need 1 to 3 months. Log retention across many systems, especially cloud and SaaS, takes longest.

Where the time goes

Point of Contact1 wk
Logging and retention3–8 wk
Clock sync1–2 wk
Reporting process2–4 wk
Testing1 day

Bars show the upper end of each range on one scale (3 months = full width).

What changes the effort

  • Number of ICT systems: each needs logs and time sync
  • Cloud and SaaS: log location and retention need checking
  • Provider type: DC, cloud, VPN and VPS providers keep subscriber records
  • Other regulators: RBI and SEBI add their own reporting
  • Existing SOC: makes six-hour reporting realistic
Readiness check · 2 minutes

How ready are you for the CERT-In directions?

Check these eight things first. Nothing you enter leaves this page.

(iii)Have you designated and registered a Point of Contact with CERT-In?
(ii)Can you report an Annexure I incident within 6 hours?
(ii)Are Annexure I incident types mapped to your categories?
(iv)Are logs of all ICT systems enabled?
(iv)Are logs kept for 180 days within India?
(i)Are clocks synced to NIC, NPL or traceable NTP servers?
(v)If you provide cloud, DC, VPS or VPN services, do you keep subscriber records for 5 years?
TestHave you tested the reporting process this year?
Crosswalk

How CERT-In maps to the RBI directions, SEBI CSCRF, DPDP and ISO 27001

CERT-In reporting is the common layer under India's sector rules: RBI and SEBI both require CERT-In notification, and a personal-data breach also triggers DPDP duties.

CERT-In vs DPDP breach reporting

CERT-In Directions 2022DPDP Act 2023
What triggers it20 types of cyber incidentAny personal data breach
Report toCERT-InData Protection Board and affected people
Deadline6 hours from noticingAs the DPDP Rules set
Applies toService providers, intermediaries, DCs, body corporates, governmentData Fiduciaries
PenaltyUp to 1 year or ₹1 lakh fine (Sec. 70B(7))Up to ₹200 crore for breach notification failures
In QULDEXQULDEX runs one incident record that drives both reports, each with its own deadline.

India incident and log crosswalk

CERT-In DirectionsRBI Directions 2026SEBI CSCRFISO 27001:2022Shared evidence
(ii) 6-hour reporting6-hour DAKSH reportingRS.MAA.5.24–A.5.26Incident reports
(iv) 180-day logsC-SOC monitoringPR.DS, DE.CMA.8.15Log retention
(i) NTP syncBaseline controlsPRA.8.17NTP settings
(iii) Point of ContactCISOGV.RR5.3PoC record
Audit guidelinesIS auditCyber audit9.2Audit reports

Indicative mapping for planning, not legal advice.

Where QULDEX fits

How QULDEX runs CERT-In compliance from log retention to six-hour reports

QULDEX is CERT-In compliance and audit management software built from EGV Group's audit delivery, used by organisations in India, their advisors and the CERT-In empanelled auditors who test them. Pick your role to see who does what.

For companies, providers and government bodies.

  1. ContactRegister the PoCPoC record with update reminders
  2. LogsKeep 180 days in IndiaRetention evidence per system
  3. TimeSync clocksNTP evidence per system
  4. IncidentsReport within 6 hoursSix-hour timers and Annexure I types
  5. RequestsAnswer CERT-InRequest log with deadlines
  6. AuditHost the auditControlled evidence sharing
Without one systemWith QULDEX
Six-hour deadline found out mid-incidentTimers from the moment an incident is logged
Log retention assumedRetention evidence per system
PoC details out of datePoC record with reminders
Separate RBI, SEBI and CERT-In reportsOne incident record, several reports
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

CERT-In questions people ask

What are the CERT-In directions?

Directions issued on 28 April 2022 under Section 70B(6) of the IT Act, 2000, covering incident reporting, log retention, clock synchronisation, a Point of Contact and record-keeping for some providers. They took effect 60 days after issue.

What must be reported to CERT-In within 6 hours?

Any of the 20 incident types in Annexure I, including unauthorised access, ransomware and other malicious code, data breaches and leaks, DoS attacks, phishing, and attacks on cloud, payment, IoT or AI systems.

How long must logs be kept under the CERT-In directions?

Logs of all ICT systems must be kept securely for a rolling 180 days within Indian jurisdiction and provided to CERT-In with incident reports or on request.

Who must comply with the CERT-In directions?

Service providers, intermediaries, data centres, body corporates and government organisations. Data centre, VPS, cloud and VPN providers, and virtual asset providers, have extra record-keeping duties.

What is the penalty for not following CERT-In directions?

Action under Section 70B(7) of the IT Act: imprisonment of up to one year, a fine of up to ₹1 lakh, or both, plus other applicable laws.

Sources

References

  1. CERT-In Directions No. 20(3)/2022-CERT-In under Section 70B(6), 28 Apr 2022. cert-in.org.in
  2. CERT-In FAQs on the Directions, May 2022. cert-in.org.in
  3. CERT-In Comprehensive Cyber Security Audit Policy Guidelines, 25 Jul 2025. cert-in.org.in
  4. Information Technology Act, 2000, Section 70B. indiacode.nic.in
  5. Digital Personal Data Protection Act, 2023. meity.gov.in

Reviewed by

Abhishek Yadav

Lead Auditor · QULDEX

Reviewed this page against the CERT-In Directions of 28 April 2022 and the 2025 audit guidelines.

Page history
  • : Page first built: the six directions, Annexure I incident types, audit guidance and readiness check

Prove you can report within six hours

Answer a short readiness check and get a gap summary across the six directions. No sales call needed to see the result.

Schedule
Book a Demo