CERT-In · Directions

CERT-In Directions under sub-section (6) of section 70B of the Information Technology Act, 2000

No. 20(3)/2022-CERT-In

In short
No. 20(3)/2022-CERT-In is the set of Directions issued on 28 April 2022 under sub-section (6) of section 70B of the Information Technology Act, 2000, in force from 27 June 2022. They bind service providers, intermediaries, data centres, body corporates and government organisations — which is very nearly every organisation in India — and require cyber incidents to be reported to CERT-In within six hours of noticing them.

The record

ReferenceNo. 20(3)/2022-CERT-In
Issued byIndian Computer Emergency Response Team (CERT-In)
Instrument typeDirections
Date of issue28 April 2022
StatusIn force
BindsService providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them.
Dates it sets
  • 27 June 2022In force, sixty days after issue.
CERT-In Directions, 2022 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds service providers, intermediaries, data centres, body corporates and government organisations, regardless of sector or regulator.
  • Requires cyber incidents to be reported to CERT-In within six hours of noticing them.
  • Came into force sixty days after issue, on 27 June 2022.
  • Applies in addition to every sectoral obligation: an RBI, SEBI, IRDAI or IFSCA entity owes this as well as its own regulator’s clock.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • DPDP Rules, 2025 G.S.R. 846(E)Data Fiduciaries, in three tranches, with the substantive duties commencing 13 May 2027.
  • SEBI incident portal — FIRE format HO/(449)2026-ITD-5_DIV1/I/19448/2026Moved SEBI incident filing to the FIRE format and staged it, without moving either clock.
  • IRDAI Guidelines, 2026 IRDAI/GA&HR/CIR/MISC/51/4/2026All insurers, insurance intermediaries and the Insurance Information Bureau of India.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The six-hour incident reporting clock