CERT-In Directions of 28 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Directions (v) and (vi) of the CERT-In Directions of 28 April 2022 deal with records. Direction (v) requires data centres, Virtual Private Server (VPS) providers, cloud service providers and Virtual Private Network (VPN) service providers to register and maintain stated subscriber information for 5 years or longer after cancellation or withdrawal of the registration. Direction (vi) requires virtual asset service providers, virtual asset exchange providers and custodian wallet providers to maintain KYC information and records of financial transactions for five years. This article explains the Directions as issued on 28 April 2022. Later clarifications and amendments should be checked.
Direction (v) lists seven items, (a) to (g), of "accurate information" to register and keep for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration. Direction (vi) requires virtual asset service providers, exchange providers and custodian wallet providers to keep KYC information and records of financial transactions for a period of five years, with transaction records kept so that each individual transaction can be reconstructed. Annexure III lists the documents for the KYC. The Directions "become effective after 60 days from the date on which it is issued".
Where these directions come from
The Directions are issued under sub-section (6) of section 70B of the Information Technology Act, 2000, which lets the Indian Computer Emergency Response Team call for information and give direction to service providers, intermediaries, data centres, body corporate and any other person. Our article on section 70B explains the section, and our article on cyber incident reporting and log retention covers directions (i) to (iv) and Annexures I and II. CERT-In also published FAQs in May 2022. The text explained here is the Directions themselves.
Direction (v): data centres, VPS, cloud and VPN service providers
Direction (v) says Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers "shall be required to register the following accurate information which must be maintained by them for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration as the case may be":
| Item | Information, as printed |
|---|---|
| a | Validated names of subscribers/customers hiring the services |
| b | Period of hire including dates |
| c | IPs allotted to / being used by the members |
| d | Email address and IP address and time stamp used at the time of registration / on-boarding |
| e | Purpose for hiring services |
| f | Validated address and contact numbers |
| g | Ownership pattern of the subscribers / customers hiring services |
Points to note from the words:
- The groups covered are four: data centres, VPS providers, cloud service providers and VPN service providers.
- The period is "5 years or longer duration as mandated by the law", counted "after any cancellation or withdrawal of the registration".
- The information must be "accurate", and item (a) and item (f) say "validated". The Directions do not say how validation is to be done, and this article adds no method.
- The text says "the members" in item (c) where the other items speak of subscribers or customers; we flag the wording and do not correct it.
If you provide hosting, cloud or VPN services, a legal due diligence review of your customer onboarding form, what you store, and how long you keep it, is a sensible first step. Data kept for this purpose also engages data-protection law, which has its own tests; see our introduction to the Digital Personal Data Protection Act, 2023.
Direction (vi): virtual asset service providers
Direction (vi) says the virtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by the Ministry of Finance from time to time) "shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of five years so as to ensure cyber security in the area of payments and financial markets for citizens while protecting their data, fundamental rights and economic freedom in view of the growth of virtual assets."
| Element | What the words say |
|---|---|
| Who | Virtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by the Ministry of Finance from time to time) |
| What | All information obtained as part of KYC, and records of financial transactions |
| Period | Five years |
| Stated purpose | To ensure cyber security in the area of payments and financial markets |
The second paragraph of the direction says that, for the purpose of KYC, the Reserve Bank of India (RBI) Directions 2016, the Securities and Exchange Board of India (SEBI) circular dated April 24, 2020 and the Department of Telecom (DoT) notice September 21, 2021 "mandated procedures as amended from time to time may be referred to as per Annexure III". The third paragraph says that with respect to transaction records, "accurate information shall be maintained in such a way that individual transaction can be reconstructed along with the relevant elements comprising of, but not limited to, information relating to the identification of the relevant parties including IP addresses along with timestamps and time zones, transaction ID, the public keys (or equivalent identifiers), addresses or accounts involved (or equivalent identifiers), the nature and date of the transaction, and the amount transferred."
For general background on KYC regimes under other laws, which this article does not read into the Directions, see our posts on KYC requirements under the PMLA and on crypto business registration.
Annexure III: KYC requirements
Annexure III says that for the purpose of KYC, any of the following Officially Valid Documents (OVD) as a measure of identification procedure prescribed by the Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016, the SEBI clarification on Know Your Client (KYC) process and use of technology for KYC (circular SEBI/HO/MIRSD/DOP/CIR/P/2020/73 dated April 24, 2020), or the Department of Telecom File No: 800-12/2021-AS.II dated September 21, 2021 on Self-KYC (S-KYC), "shall be used and maintained":
| Item | Document, as printed |
|---|---|
| a | The passport |
| b | The driving license |
| c | Proof of possession of Aadhaar number |
| d | The Voter's Identity Card issued by the Election Commission of India |
| e | Job card issued by NREGA duly signed by an officer of the State Government |
| f | Letter issued by the National Population Register containing details of name and address |
| g | Validated phone number |
| h | Trading account number and details, Bank account number and bank details |
For KYC for business entities (B2B), "documents mentioned in the Customer Due Diligence (CDD) process prescribed in Reserve Bank of India Master Direction - Know Your Customer (KYC) Direction, 2016 as updated from time to time shall be used and maintained". The RBI, SEBI and DoT instruments are cited as printed; this article does not describe their content, and later changes to them are not covered. Check the current instruments.
Consequence, meaning of terms and effect
The closing paragraphs say that the meaning of "cyber incident", "cyber security incident", "computer resource" and other terms may be ascribed as defined in the Information Technology Act, 2000 or in the 2013 Rules on the Indian Computer Emergency Response Team, and that failure to furnish the information or non-compliance with the directions "may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable". Section 70B(7), as printed in the consolidated copy, prints imprisonment for a term which may extend to one year or fine which may extend to one lakh rupees or both. As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, item (I), the words "one lakh" are replaced by "one crore", and the one year term is not changed. Commencement of that Act is by notification and no date is in the sources used; check whether the amendment has been brought into force.
| Provision | As printed in the consolidated copy | As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023 |
|---|---|---|
| Section 70B(7) fine | "one lakh rupees" | "one crore rupees" |
| Section 70B(7) imprisonment | "one year" | unchanged |
The Directions end: "This direction will become effective after 60 days from the date on which it is issued." This article gives no calendar date for the effective date and says nothing about any extension. Later clarifications and amendments should be checked.
A worked example
Nimbus Private Cloud Limited, an invented cloud provider, onboards a customer. Under direction (v), the provider registers the validated name of the customer, the period of hire, the IPs allotted, the email and IP address and time stamp used at on-boarding, the purpose for hiring, the validated address and contact numbers, and the ownership pattern. When the customer cancels, the provider keeps the information for 5 years or longer duration as mandated by the law, counted from the cancellation. A virtual asset exchange (invented) onboarding a user under direction (vi) keeps the KYC and transaction records for five years, so that each individual transaction can be reconstructed.
Need help with record-keeping under the Directions?
If you run a hosting, cloud, VPN or virtual asset business and need to map the records you hold against directions (v) and (vi), our team can help. Contact us for a legal due diligence review.
Key takeaways
- Direction (v): data centres, VPS, cloud and VPN service providers register seven items of information and keep them for 5 years or longer duration as mandated by the law after cancellation or withdrawal of the registration.
- Direction (vi): virtual asset service providers, exchange providers and custodian wallet providers keep KYC information and records of financial transactions for five years, with transactions capable of reconstruction.
- Annexure III lists documents for KYC, and for B2B cites the CDD documents in the RBI Master Direction as updated from time to time.
- Non-compliance may invite action under section 70B(7); as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the fine figure changes from "one lakh" to "one crore"; check whether it is in force.
- The Directions are effective after 60 days from the date on which they are issued; later clarifications and amendments should be checked.
Read next
- CERT-In Directions of 28 April 2022: cyber incident reporting and log retention
- Section 70B of the Information Technology Act, 2000: Indian Computer Emergency Response Team
- KYC Requirements Under PMLA: CDD and EDD
- Crypto Business Registration: licenses, process and cost
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
