CERT-In Directions of 28 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The CERT-In Directions of 28 April 2022 (No. 20(3)/2022-CERT-In) are directions under sub-section (6) of section 70B of the Information Technology Act, 2000. Directions (i) to (iv) deal with time synchronisation, reporting of cyber incidents within 6 hours, a Point of Contact and action on CERT-In's orders, and the maintenance of logs for a rolling period of 180 days within the Indian jurisdiction. This article explains the Directions as issued on 28 April 2022. Later clarifications and amendments should be checked.
Under direction (ii), a service provider, intermediary, data centre, body corporate or Government organisation shall mandatorily report cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing them or being brought to notice. Direction (iv) requires all ICT system logs to be enabled and maintained securely for a rolling period of 180 days within the Indian jurisdiction. Direction (i) requires clock synchronisation to the NTP servers of NIC or NPL. The Directions "become effective after 60 days from the date on which it is issued". Failure may invite punitive action under section 70B(7).
Background: section 70B and the Directions
Section 70B(6) lets the Indian Computer Emergency Response Team call for information and give direction to service providers, intermediaries, data centres, body corporate and any other person to carry out the functions in section 70B(4). Our article on section 70B explains the section. The recitals of the Directions mention the Information Technology (The Indian Computer Emergency Response Team and Manner of performing functions and duties) Rules, 2013, which they say were notified "in exercise of the powers conferred by clause (zf) of sub-section (2) of section 87". The copy of section 87(2) used in this series prints clause (z) and then clause (za), and no clause (zf); we flag the mismatch and do not correct any text. CERT-In also published FAQs in May 2022. The Directions are the text explained here; the second part of the Directions is covered in our article on customer records and KYC retention.
Direction (i): time synchronisation
Direction (i) says all service providers, intermediaries, data centres, body corporate and Government organisations "shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers, for synchronisation of all their ICT systems clocks". Entities having ICT infrastructure spanning multiple geographies "may also use accurate and standard time source other than NPL and NIC, however it is to be ensured that their time source shall not deviate from NPL and NIC."
| Element | What the words say |
|---|---|
| Who | Service providers, intermediaries, data centres, body corporate and Government organisations |
| What | Connect to the NTP Server of NIC or NPL, or to NTP servers traceable to them, for synchronisation of all ICT systems clocks |
| Multi-geography entities | May use another accurate and standard time source, provided it does not deviate from NPL and NIC |
Direction (ii): reporting within 6 hours
Direction (ii) says any service provider, intermediary, data centre, body corporate and Government organisation "shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents". The Directions print the reporting channels: email (incident@cert-in.org.in), phone (1800-11-4949) and fax (1800-11-6969), as printed in the Directions; they add that the details regarding methods and formats of reporting are also published on the CERT-In website and "will be updated from time to time".
The 6 hours run from "noticing" or "being brought to notice". The Directions do not define "noticing". If you operate an online business, a hosting service or an IT team, a legal due diligence review of how an incident is escalated within your organisation, and who records the time of noticing, is a sensible control before an incident occurs.
Annexure I: types of cyber security incidents
Annexure I, headed "Types of cyber security incidents mandatorily to be reported", cites Rule 12(1)(a) of the 2013 Rules and lists, as printed:
| No. | Incident type |
|---|---|
| i | Targeted scanning/probing of critical networks/systems |
| ii | Compromise of critical systems/information |
| iii | Unauthorised access of IT systems/data |
| iv | Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc. |
| v | Malicious code attacks such as spreading of virus/worm/Trojan/Bots/Spyware/Ransomware/Cryptominers |
| vi | Attack on servers such as Database, Mail and DNS and network devices such as Routers |
| vii | Identity Theft, spoofing and phishing attacks |
| viii | Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks |
| ix | Attacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks |
| x | Attacks on Application such as E-Governance, E-Commerce etc. |
| xi | Data Breach |
| xii | Data Leak |
| xiii | Attacks on Internet of Things (IoT) devices and associated systems, networks, software, servers |
| xiv | Attacks or incident affecting Digital Payment systems |
| xv | Attacks through Malicious mobile Apps |
| xvi | Fake mobile Apps |
| xvii | Unauthorised access to social media accounts |
| xviii | Attacks or malicious/suspicious activities affecting Cloud computing systems/servers/software/applications |
| xix | Attacks or malicious/suspicious activities affecting systems/servers/networks/software/applications related to Big Data, Block chain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones |
| xx | Attacks or malicious/suspicious activities affecting systems/servers/software/applications related to Artificial Intelligence and Machine Learning |
The Annexure repeats the reporting channels. For a data-protection view of breach intimation, which is a different law with different tests, see our posts on data breach notification under the Digital Personal Data Protection Act, 2023 and on rule 7(2) of the Digital Personal Data Protection Rules, 2025.
Direction (iii): action, information and the Point of Contact
Direction (iii) says that when required by order or direction of CERT-In, for the purposes of cyber incident response, protective and preventive actions related to cyber incidents, the service provider, intermediary, data centre or body corporate "is mandated to take action or provide information or any such assistance to CERT-In". The order may include the format of the information (up to and including near real-time) and a specified timeframe, "which should be adhered to and compliance provided to CERT-In, else it would be treated as non-compliance of this direction".
The entities "shall designate a Point of Contact to interface with CERT-In". The information about the Point of Contact is to be sent to CERT-In in the format at Annexure II and updated from time to time, and all communications from CERT-In shall be sent to that Point of Contact.
| Annexure II field | |
|---|---|
| Name; Designation; Organisation Name; Office Address; Email ID; Mobile No.; Office Phone; Office Fax | Sent to CERT-In via email (info@cert-in.org.in), as printed in the Directions |
Direction (iv): logs for a rolling period of 180 days
Direction (iv) says all service providers, intermediaries, data centres, body corporate and Government organisations "shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction. These should be provided to CERT-In along with reporting of any incident or when ordered / directed by CERT-In."
| Element | What the words say |
|---|---|
| Duty | Enable logs of all ICT systems and maintain them securely |
| Period | A rolling period of 180 days |
| Place | Within the Indian jurisdiction |
| Handover | To CERT-In along with reporting of any incident or when ordered or directed by CERT-In |
The Directions do not list which fields a log must contain, and this article adds none.
Consequence and effect
The closing paragraphs say that the meaning of terms such as "cyber incident", "cyber security incident" and "computer resource" may be ascribed as defined in the Act or the 2013 Rules, and that failure to furnish the information or non-compliance with the directions "may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable". Section 70B(7), as printed in the consolidated copy, prints imprisonment for a term which may extend to one year or fine which may extend to one lakh rupees or both; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the words "one lakh" are replaced by "one crore". Commencement of that Act is by notification and no date is in the sources used; check whether the amendment has been brought into force.
| Provision | As printed in the consolidated copy | As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023 |
|---|---|---|
| Section 70B(7) fine | "one lakh rupees" | "one crore rupees" |
| Section 70B(7) imprisonment | "one year" | unchanged |
The Directions state: "This direction will become effective after 60 days from the date on which it is issued." This article gives no calendar date for the effective date and says nothing about any extension. Check later clarifications and amendments.
A worked example
Pankaj Hosting Private Limited, an invented hosting company, notices on a Monday afternoon an unauthorised access to a customer-facing system. Direction (ii) makes the 6 hours run from noticing; the company's on-call manager records the time, notifies the Point of Contact named under direction (iii), and reports to CERT-In through one of the printed channels. Under direction (iv), the company's logs for the preceding period are kept securely within India so they can be provided to CERT-In along with the report. The company's written incident log, with times, is its record that it acted within 6 hours.
Need help with CERT-In compliance?
If your business is a service provider, intermediary, data centre or body corporate and wants an incident escalation process, a Point of Contact and a log retention plan, our team can help. Begin with a legal due diligence review.
Key takeaways
- Directions (i) to (iv) cover NTP synchronisation, reporting of Annexure I incidents within 6 hours, action and a Point of Contact, and logs kept for a rolling period of 180 days within the Indian jurisdiction.
- Annexure I lists twenty types of incident; Annexure II is the Point of Contact format.
- Section 70B(7) is cited for non-compliance; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the fine figure changes from "one lakh" to "one crore"; check whether it is in force.
- The Directions "become effective after 60 days from the date on which it is issued"; later clarifications and amendments should be checked.
Read next
- Section 70B of the Information Technology Act, 2000: Indian Computer Emergency Response Team
- CERT-In Directions of 28 April 2022: customer records and KYC retention
- Data Breach Notification: obligation under DPDP
- Section 66F of the Information Technology Act, 2000: punishment for cyber terrorism
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
