CERT-In’s six-hour rule: what the 2022 Directions actually require
Every body corporate in India must report twenty categories of incident to CERT-In within six hours of noticing them — plus five continuous obligations, including 180 days of logs held inside Indian jurisdiction.
The CERT-In Directions are the most widely applicable cyber instrument in India and the least often read. They bind every body corporate in the country, not a sector; they have been in force since June 2022; and the obligation most people know about — six-hour incident reporting — is one of six, of which the other five are the ones organisations are usually found short on.
Who this binds
The Directions were issued under sub-section (6) of section 70B of the Information Technology Act, 2000, which empowers CERT-In to call for information and give directions to five classes of entity: service providers, intermediaries, data centres, body corporate and Government organisations. There is no revenue threshold, no sector test and no carve-out for small entities.
“Body corporate” is the phrase that does the work. Practically every company operating in India falls inside it, which is what separates this instrument from the sectoral frameworks: a bank answers to the RBI and to CERT-In, a broker to SEBI and to CERT-In, and a manufacturer with no financial regulator at all still answers to CERT-In.
The six-hour clock
The reporting obligation is the second of the six directions, and its wording matters more than the number does. An incident must be reported within six hours of noticing it or being brought to notice about it. The clock does not start when the incident began, when it was confirmed, or when the response team finished triaging. It starts at the moment of awareness, however that awareness arrived — including from a customer, a journalist or a researcher.
Reports go to CERT-In by email at incident@cert-in.org.in, by phone on 1800-11-4949 or by fax on 1800-11-6969, with methods and formats published on the CERT-In website and updated from time to time.
CERT-In is rarely the only filing. To see every notification your entity owes on the same incident — and what each clock runs from — use the incident reporting clock.
Six hours is short enough that it is an operational constraint rather than a reporting one. An organisation that cannot establish, inside six hours, that something has happened and roughly what it is has already failed the timeline regardless of how good its eventual report is. That is the part worth designing for.
What has to be reported
Annexure I lists twenty categories. The list is broader than the phrase “cyber incident” usually implies — it includes targeted scanning of critical systems, which is a precursor rather than a breach, and it reaches technologies that were unusual in 2022:
Intrusion and compromise
- Targeted scanning or probing of critical networks and systems
- Compromise of critical systems or information
- Unauthorised access of IT systems or data
- Website defacement, or intrusion and unauthorised changes such as inserting malicious code or links
- Malicious code attacks — virus, worm, Trojan, bots, spyware, ransomware, cryptominers
- Attacks on servers such as database, mail and DNS, and on network devices such as routers
Identity, availability and data
- Identity theft, spoofing and phishing attacks
- Denial of Service and Distributed Denial of Service attacks
- Data breach
- Data leak
- Unauthorised access to social media accounts
Infrastructure and applications
- Attacks on critical infrastructure, SCADA and operational technology systems, and wireless networks
- Attacks on applications such as e-governance and e-commerce
- Attacks affecting digital payment systems
- Attacks or suspicious activity affecting cloud computing systems, servers, software and applications
Devices and emerging technology
- Attacks on Internet of Things devices and associated systems, networks, software and servers
- Attacks through malicious mobile applications
- Fake mobile applications
- Attacks affecting Big Data, blockchain, virtual assets, virtual asset exchanges, custodian wallets, robotics, 3D and 4D printing, additive manufacturing and drones
- Attacks affecting systems related to Artificial Intelligence and Machine Learning
Two of those categories are worth pausing on. Targeted scanning or probing of critical networks is reportable, and most organisations see it continuously — which makes the definition of “critical” and “targeted” a decision to take deliberately rather than during an incident. And the final category reaches attacks affecting Artificial Intelligence and Machine Learning systems, written into the Annexure in 2022 and increasingly less theoretical.
The five obligations that are not reporting
The reporting clock gets the attention. The other five directions are continuous obligations that either exist in your estate today or do not, and they are what an inspection actually looks at.
| Direction | Who | What |
|---|---|---|
| Clock synchronisation | All five classes | Synchronise all ICT system clocks to NIC or NPL NTP servers, or to sources traceable to them. Entities spanning multiple geographies may use another accurate standard source, provided it does not deviate from NPL and NIC |
| Incident reporting | All five classes | Annexure I incidents, within six hours of noticing or being notified |
| Point of Contact, and response to directions | All five classes | Designate a Point of Contact to interface with CERT-In, in the Annexure II format, kept updated. Provide information, action or assistance when ordered — in the format specified, up to and including near real-time, within the timeframe given |
| Log retention | All five classes | Enable logs of all ICT systems and maintain them securely for a rolling 180 days, within Indian jurisdiction, produced to CERT-In with an incident report or on direction |
| Subscriber records | Data centres, VPS, cloud and VPN service providers | Register and maintain validated subscriber details for five years after the registration is cancelled or withdrawn — names, period of hire, IPs allotted, registration email, IP and timestamp, purpose, validated address and contact numbers, and ownership pattern |
| Virtual asset records | Virtual asset service providers, exchanges and custodian wallet providers | Maintain KYC and financial transaction records for five years, in a form that lets an individual transaction be reconstructed — parties, IP addresses with timestamps and time zones, transaction ID, public keys or equivalent identifiers, accounts, nature, date and amount |
The two that catch people out
Logs within Indian jurisdiction. The 180-day retention is unremarkable; the location requirement is not. An organisation whose logging pipeline terminates in a cloud region outside India is not compliant on the face of the direction, however good the logging is. This is the provision most likely to be inherited unnoticed from a platform decision taken for unrelated reasons.
Clock synchronisation. It reads like housekeeping and is the reason the rest works: correlating an incident across systems, and producing logs that stand up when CERT-In asks for them, both depend on the timestamps agreeing. It is also trivially auditable, which makes it a poor thing to be found wrong on.
What non-compliance carries
Failure to furnish information when called for, or non-compliance with the directions, may invite punitive action under sub-section (7) of section 70B of the IT Act, 2000, and under other laws as applicable. The Directions state this in terms and do not qualify it by entity size.
The practical exposure is usually not the penalty in isolation. It is that an organisation which cannot produce 180 days of logs, or cannot show when it became aware of an incident, is in a materially worse position in every conversation that follows — with CERT-In, with a sector regulator running its own clock, and with customers under contractual notification terms of their own.
What to have in place before you need it
- A named Point of Contact, registered and current. The Annexure II format is short. An out-of-date PoC means CERT-In's directions arrive at someone who has left, and the timeframe in them runs anyway.
- A decision, taken in advance, about what “critical” means. Several Annexure I categories are scoped by criticality. Deciding which systems and networks are critical during an incident is deciding it badly.
- Evidence of when you became aware. The clock runs from awareness, so the defensible position is a record of when the alert fired or the report arrived — not a reconstruction offered afterwards.
- Logs that are complete, retained 180 days, and in India. Check where they actually live rather than where the architecture diagram says they do.
- One filing plan covering every regulator you answer to. A bank runs the CERT-In clock and the RBI's DAKSH clock simultaneously; an insurer may add IRDAI. Six hours is not long enough to work out who files what.
Where BitScore fits, and where it does not
A security rating does not discharge any part of these Directions. Reporting, logging, clock synchronisation and record retention are internal obligations, and an externally calculated rating has no view of them. Anyone suggesting otherwise is selling something.
What continuous external monitoring changes is the input to the six-hour clock. The clock starts when you notice, and a substantial share of organisations notice through someone else — a customer, a researcher, or the news. Independent observation of your internet-facing estate is one more way of noticing first, which is the only part of the timeline you control.
Read next
- Cyber security regulations in India — the whole picture, and which sector instrument applies on top of this one.
- The RBI Directions of 31 July 2026 — the second six-hour clock, and which of the seven binds you.
- What SEBI's CDSL order says about the assets you forgot to list — what happens when an internet-facing system is not on the inventory.
Read from the CERT-In Directions themselves — No. 20(3)/2022-CERT-In of 28 April 2022, including Annexures I to III. Every instrument cited here was verified against the issuing regulator's own notification on . This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
Questions this page answers
- Who must report incidents to CERT-In?
- Service providers, intermediaries, data centres, body corporate and Government organisations — the five classes named in the Directions. There is no revenue threshold, no sector test and no exemption for small entities. “Body corporate” reaches practically every company operating in India, which is what makes this the most widely applicable cyber instrument in the country.
- When does the six-hour clock start?
- At the moment of awareness. The Directions require reporting within six hours of noticing an incident or being brought to notice about it, so the clock does not start when the incident began, when it was confirmed, or when triage finished. Awareness arriving from a customer or a researcher starts it just the same.
- Does reporting to the RBI or SEBI satisfy CERT-In?
- No. These are separate obligations to separate recipients under separate instruments. A bank reporting an incident to the RBI on DAKSH has not thereby reported it to CERT-In, and the two six-hour clocks run concurrently rather than one instead of the other. Decide in advance who files what.
- How long must logs be kept, and where?
- Logs of all ICT systems must be enabled and maintained securely for a rolling 180 days, within Indian jurisdiction, and produced to CERT-In alongside an incident report or when directed. A logging pipeline that terminates in a cloud region outside India does not meet the location requirement, however good the logging itself is.
- What does non-compliance carry?
- Failure to furnish information when called for, or non-compliance with the Directions, may invite punitive action under sub-section (7) of section 70B of the IT Act, 2000, and under other laws as applicable. The Directions state this in terms and do not qualify it by entity size.