Directions · Cyber incidents · India
CERT-In compliance means following the Directions CERT-In issued on 28 April 2022 under Section 70B(6) of the IT Act. Service providers, intermediaries, data centres, body corporates and government bodies must report 20 types of cyber incident within 6 hours, keep ICT logs in India for 180 days and sync clocks to NIC or NPL.
The Directions name service providers, intermediaries, data centres, body corporates and government organisations.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The CERT-In directions require you to report listed cyber incidents within six hours, keep 180 days of ICT logs in India, synchronise clocks to NIC or NPL, name a Point of Contact and answer CERT-In's requests.
20 incident types in Annexure I.
In QULDEX: Six-hour timersAll ICT systems, kept securely.
In QULDEX: Retention evidence per systemNIC, NPL or traceable sources.
In QULDEX: Time-source evidenceRespond to CERT-In directions on time.
In QULDEX: PoC and request logDC, VPS, cloud and VPN providers, 5 years.
In QULDEX: Record checksVirtual asset providers, 5 years.
In QULDEX: Record checksThe six directions, the 20 reportable incident types (grouped) and the audit guidance. Select any one to see what it requires and how QULDEX handles it.
Showing up to 6 per group. Search, filter, or open a group to see all 16.
Dir. (i)Clock synchronisationApplies to everyoneConnect to the NTP servers of NIC or NPL, or servers traceable to them, to synchronise all ICT system clocks.
In QULDEXTime-source settings are evidence per system.
Dir. (ii)Report incidents within 6 hoursApplies to everyoneReport the cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing them or being told about them.
In QULDEXEvery incident starts a six-hour timer with the Annexure I type recorded.
Dir. (iii)Point of contact and information on requestDesignate a Point of Contact for CERT-In and provide information or take action when CERT-In directs, within the time it sets.
In QULDEXThe PoC record and CERT-In requests are logged with deadlines.
Dir. (iv)Logs for 180 days in IndiaApplies to everyoneEnable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction.
In QULDEXLog retention and location are evidenced per system.
Dir. (v)Subscriber records (DCs, VPS, cloud, VPN)Data centres, VPS, cloud and VPN providers record validated subscriber details, IPs, purpose and ownership for 5 years.
In QULDEXRecord-keeping is a control with sample checks.
Dir. (vi)KYC for virtual asset providersVirtual asset service providers, exchanges and custodian wallets keep KYC and transaction records for 5 years.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Sec. 70B(7)Penalty for non-complianceFailure to provide information or comply can attract action under Section 70B(7) of the IT Act: imprisonment up to one year, a fine up to ₹1 lakh, or both.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Annex I (i–iii)Scanning, compromise, unauthorised accessTargeted scanning of critical systems, compromise of critical systems or information, and unauthorised access to IT systems or data.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Annex I (iv–vi)Defacement, malware, server attacksWebsite defacement or intrusion, malicious code including ransomware, and attacks on servers and network devices.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Annex I (vii–viii)Phishing and DoSIdentity theft, spoofing and phishing, and DoS or DDoS attacks.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Annex I (ix–x)Critical infrastructure and applicationsAttacks on critical infrastructure, SCADA, OT and wireless networks, and on applications such as e-governance and e-commerce.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Annex I (xi–xii)Data breach and data leakData breaches and data leaks.
In QULDEXA personal-data breach also triggers DPDP duties, tracked on the same record.
Annex I (xiii–xx)IoT, payments, apps, cloud, emerging techAttacks on IoT, digital payment systems, malicious or fake mobile apps, social media accounts, cloud systems, blockchain and virtual assets, and AI and ML systems.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Audit 2025Comprehensive Cyber Security Audit Policy GuidelinesCERT-In's July 2025 guidelines set a national, evidence-based approach to cyber security audits by empanelled auditors.
In QULDEXAudits run in the audit workspace with evidence-based workpapers.
EmpanelmentCERT-In empanelled auditorsMany sector regulators require audits by CERT-In empanelled auditing organisations.
In QULDEXAuditor details and scope are recorded per audit.
FAQsCERT-In FAQs on the DirectionsCERT-In's FAQs of May 2022 clarify scope, reporting and log questions.
In QULDEXQULDEX gives this direction an owner, evidence and a review date, and links it to the incident and log controls you already run.
Nothing matches that search.
Direction numbers follow CERT-In Directions No. 20(3)/2022-CERT-In of 28 April 2022; incident types follow its Annexure I. Summaries are QULDEX paraphrases.
Name a Point of Contact, fix log retention and time sync, and build a six-hour reporting process you have actually tested. Most organisations need 1 to 3 months.
Send PoC details to CERT-In in the Annexure II format and keep them current.
Enable logs on all ICT systems and keep 180 days within India.
Point systems at NIC or NPL NTP servers or traceable sources.
Map Annexure I types to your incident categories and set up the reporting workflow.
Run a tabletop exercise to prove a report can go out within six hours.
Durations are QULDEX planning ranges.
Keep these ready for CERT-In and for auditors.
| Record | Direction | Where it lives in QULDEX |
|---|---|---|
| Point of Contact registration | (iii), Annexure II | Evidence vault |
| Incident reports to CERT-In | (ii) | CAPA automation |
| Incident classification against Annexure I | (ii) | CAPA automation |
| Log retention evidence (180 days, in India) | (iv) | Evidence vault |
| NTP configuration | (i) | Evidence vault |
| Subscriber records (DC, VPS, cloud, VPN) | (v) | Evidence vault |
| KYC and transaction records (virtual assets) | (vi) | Evidence vault |
| Cyber security audit reports | Audit guidelines | Audit workspace |
Record names are QULDEX recommendations based on the Directions.
Most organisations need 1 to 3 months. Log retention across many systems, especially cloud and SaaS, takes longest.
Bars show the upper end of each range on one scale (3 months = full width).
Check these eight things first. Nothing you enter leaves this page.
CERT-In reporting is the common layer under India's sector rules: RBI and SEBI both require CERT-In notification, and a personal-data breach also triggers DPDP duties.
| CERT-In Directions 2022 | DPDP Act 2023 | |
|---|---|---|
| What triggers it | 20 types of cyber incident | Any personal data breach |
| Report to | CERT-In | Data Protection Board and affected people |
| Deadline | 6 hours from noticing | As the DPDP Rules set |
| Applies to | Service providers, intermediaries, DCs, body corporates, government | Data Fiduciaries |
| Penalty | Up to 1 year or ₹1 lakh fine (Sec. 70B(7)) | Up to ₹200 crore for breach notification failures |
| In QULDEX | QULDEX runs one incident record that drives both reports, each with its own deadline. | |
| CERT-In Directions | RBI Directions 2026 | SEBI CSCRF | ISO 27001:2022 | Shared evidence |
|---|---|---|---|---|
| (ii) 6-hour reporting | 6-hour DAKSH reporting | RS.MA | A.5.24–A.5.26 | Incident reports |
| (iv) 180-day logs | C-SOC monitoring | PR.DS, DE.CM | A.8.15 | Log retention |
| (i) NTP sync | Baseline controls | PR | A.8.17 | NTP settings |
| (iii) Point of Contact | CISO | GV.RR | 5.3 | PoC record |
| Audit guidelines | IS audit | Cyber audit | 9.2 | Audit reports |
Indicative mapping for planning, not legal advice.
QULDEX is CERT-In compliance and audit management software built from EGV Group's audit delivery, used by organisations in India, their advisors and the CERT-In empanelled auditors who test them. Pick your role to see who does what.
For companies, providers and government bodies.
For security consultants and internal audit.
For CERT-In empanelled auditing organisations.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →Directions issued on 28 April 2022 under Section 70B(6) of the IT Act, 2000, covering incident reporting, log retention, clock synchronisation, a Point of Contact and record-keeping for some providers. They took effect 60 days after issue.
Any of the 20 incident types in Annexure I, including unauthorised access, ransomware and other malicious code, data breaches and leaks, DoS attacks, phishing, and attacks on cloud, payment, IoT or AI systems.
Logs of all ICT systems must be kept securely for a rolling 180 days within Indian jurisdiction and provided to CERT-In with incident reports or on request.
Service providers, intermediaries, data centres, body corporates and government organisations. Data centre, VPS, cloud and VPN providers, and virtual asset providers, have extra record-keeping duties.
Action under Section 70B(7) of the IT Act: imprisonment of up to one year, a fine of up to ₹1 lakh, or both, plus other applicable laws.
DPDP, CERT-In, RBI and SEBI coverage.
blog.quldex.comHow breach duties under DPDP sit alongside CERT-In reporting.
blog.quldex.comHow RBI builds on CERT-In reporting.
blog.quldex.comA file-naming scheme auditors can follow.
Reviewed by
Answer a short readiness check and get a gap summary across the six directions. No sales call needed to see the result.