Framework

CERT-In Guidelines

India's national CERT directives on cybersecurity incident reporting.

What Is CERT-In Guidelines?

CERT-In (Indian Computer Emergency Response Team) directions require organizations to report specified categories of cyber security incidents within 6 hours of detection, maintain ICT system logs for 180 days within India, and synchronize system clocks to NTP servers.

Why It Matters

Rapid, mandatory incident reporting is designed to help India build a national picture of cyber threats in near real-time. For organizations, it means incident response processes must be fast and well-documented — 6 hours is a tight window if you haven't prepared for it in advance.

Who Needs This

All Indian organizations, especially those operating critical digital infrastructure, data centers, and service providers.

Cost of Non-Compliance

Non-compliance can attract action under the IT Act, 2000, including imprisonment up to 1 year or fines, under Section 70B provisions.

Key Benefits

Avoids regulatory non-compliance penalties and scrutiny
Forces faster, more disciplined incident response processes
Improves log retention hygiene, which also aids forensic investigations
Builds a defensible compliance posture if a regulator ever asks
Typical TimelineTypically 4–6 weeks to establish logging, monitoring and the 6-hour reporting playbook.

Need help becoming CERT-In Guidelines compliant?

Our compliance consultants can guide you from gap assessment to audit-ready.

Request a Consultation

Other Frameworks

Ready to Secure & Comply
with Confidence?

Partner with CyberK7 for robust security, compliance and peace of mind.

Request a Consultation Let's build a secure future together!