Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

CERT-In Directions of 28 April 2022: cyber incident reporting and log retention

Under direction (ii), a service provider, intermediary, data centre, body corporate or Government organisation shall mandatorily report cyber incidents listed in Annexure I to...

Published
Updated
Reading time
10 min
Views
9
Questions
7 answered
  • Expert Reviewed
  • High Complexity
  • In-Depth Guide
Topic
Cyber & Data Protection
Published
October 2, 2026
Last updated
Oct 10, 2026
Reading time
10 min
0:00
Last updated: October 2026Verified against: Government sources

The CERT-In Directions of 28 April 2022 (No. 20(3)/2022-CERT-In) are directions under sub-section (6) of section 70B of the Information Technology Act, 2000. Directions (i) to (iv) deal with time synchronisation, reporting of cyber incidents within 6 hours, a Point of Contact and action on CERT-In's orders, and the maintenance of logs for a rolling period of 180 days within the Indian jurisdiction. This article explains the Directions as issued on 28 April 2022. Later clarifications and amendments should be checked.

Background: section 70B and the Directions

Section 70B(6) lets the Indian Computer Emergency Response Team call for information and give direction to service providers, intermediaries, data centres, body corporate and any other person to carry out the functions in section 70B(4). Our article on section 70B explains the section. The recitals of the Directions mention the Information Technology (The Indian Computer Emergency Response Team and Manner of performing functions and duties) Rules, 2013, which they say were notified "in exercise of the powers conferred by clause (zf) of sub-section (2) of section 87". The copy of section 87(2) used in this series prints clause (z) and then clause (za), and no clause (zf); we flag the mismatch and do not correct any text. CERT-In also published FAQs in May 2022. The Directions are the text explained here; the second part of the Directions is covered in our article on customer records and KYC retention.

Direction (i): time synchronisation

Direction (i) says all service providers, intermediaries, data centres, body corporate and Government organisations "shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers, for synchronisation of all their ICT systems clocks". Entities having ICT infrastructure spanning multiple geographies "may also use accurate and standard time source other than NPL and NIC, however it is to be ensured that their time source shall not deviate from NPL and NIC."

ElementWhat the words say
WhoService providers, intermediaries, data centres, body corporate and Government organisations
WhatConnect to the NTP Server of NIC or NPL, or to NTP servers traceable to them, for synchronisation of all ICT systems clocks
Multi-geography entitiesMay use another accurate and standard time source, provided it does not deviate from NPL and NIC

Direction (ii): reporting within 6 hours

Direction (ii) says any service provider, intermediary, data centre, body corporate and Government organisation "shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents". The Directions print the reporting channels: email (incident@cert-in.org.in), phone (1800-11-4949) and fax (1800-11-6969), as printed in the Directions; they add that the details regarding methods and formats of reporting are also published on the CERT-In website and "will be updated from time to time".

The 6 hours run from "noticing" or "being brought to notice". The Directions do not define "noticing". If you operate an online business, a hosting service or an IT team, a legal due diligence review of how an incident is escalated within your organisation, and who records the time of noticing, is a sensible control before an incident occurs.

Annexure I: types of cyber security incidents

Annexure I, headed "Types of cyber security incidents mandatorily to be reported", cites Rule 12(1)(a) of the 2013 Rules and lists, as printed:

No.Incident type
iTargeted scanning/probing of critical networks/systems
iiCompromise of critical systems/information
iiiUnauthorised access of IT systems/data
ivDefacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc.
vMalicious code attacks such as spreading of virus/worm/Trojan/Bots/Spyware/Ransomware/Cryptominers
viAttack on servers such as Database, Mail and DNS and network devices such as Routers
viiIdentity Theft, spoofing and phishing attacks
viiiDenial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
ixAttacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks
xAttacks on Application such as E-Governance, E-Commerce etc.
xiData Breach
xiiData Leak
xiiiAttacks on Internet of Things (IoT) devices and associated systems, networks, software, servers
xivAttacks or incident affecting Digital Payment systems
xvAttacks through Malicious mobile Apps
xviFake mobile Apps
xviiUnauthorised access to social media accounts
xviiiAttacks or malicious/suspicious activities affecting Cloud computing systems/servers/software/applications
xixAttacks or malicious/suspicious activities affecting systems/servers/networks/software/applications related to Big Data, Block chain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones
xxAttacks or malicious/suspicious activities affecting systems/servers/software/applications related to Artificial Intelligence and Machine Learning

The Annexure repeats the reporting channels. For a data-protection view of breach intimation, which is a different law with different tests, see our posts on data breach notification under the Digital Personal Data Protection Act, 2023 and on rule 7(2) of the Digital Personal Data Protection Rules, 2025.

Direction (iii): action, information and the Point of Contact

Direction (iii) says that when required by order or direction of CERT-In, for the purposes of cyber incident response, protective and preventive actions related to cyber incidents, the service provider, intermediary, data centre or body corporate "is mandated to take action or provide information or any such assistance to CERT-In". The order may include the format of the information (up to and including near real-time) and a specified timeframe, "which should be adhered to and compliance provided to CERT-In, else it would be treated as non-compliance of this direction".

The entities "shall designate a Point of Contact to interface with CERT-In". The information about the Point of Contact is to be sent to CERT-In in the format at Annexure II and updated from time to time, and all communications from CERT-In shall be sent to that Point of Contact.

Annexure II field
Name; Designation; Organisation Name; Office Address; Email ID; Mobile No.; Office Phone; Office FaxSent to CERT-In via email (info@cert-in.org.in), as printed in the Directions

Direction (iv): logs for a rolling period of 180 days

Direction (iv) says all service providers, intermediaries, data centres, body corporate and Government organisations "shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction. These should be provided to CERT-In along with reporting of any incident or when ordered / directed by CERT-In."

ElementWhat the words say
DutyEnable logs of all ICT systems and maintain them securely
PeriodA rolling period of 180 days
PlaceWithin the Indian jurisdiction
HandoverTo CERT-In along with reporting of any incident or when ordered or directed by CERT-In

The Directions do not list which fields a log must contain, and this article adds none.

Consequence and effect

The closing paragraphs say that the meaning of terms such as "cyber incident", "cyber security incident" and "computer resource" may be ascribed as defined in the Act or the 2013 Rules, and that failure to furnish the information or non-compliance with the directions "may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable". Section 70B(7), as printed in the consolidated copy, prints imprisonment for a term which may extend to one year or fine which may extend to one lakh rupees or both; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the words "one lakh" are replaced by "one crore". Commencement of that Act is by notification and no date is in the sources used; check whether the amendment has been brought into force.

ProvisionAs printed in the consolidated copyAs amended by the Jan Vishwas (Amendment of Provisions) Act, 2023
Section 70B(7) fine"one lakh rupees""one crore rupees"
Section 70B(7) imprisonment"one year"unchanged

The Directions state: "This direction will become effective after 60 days from the date on which it is issued." This article gives no calendar date for the effective date and says nothing about any extension. Check later clarifications and amendments.

A worked example

Pankaj Hosting Private Limited, an invented hosting company, notices on a Monday afternoon an unauthorised access to a customer-facing system. Direction (ii) makes the 6 hours run from noticing; the company's on-call manager records the time, notifies the Point of Contact named under direction (iii), and reports to CERT-In through one of the printed channels. Under direction (iv), the company's logs for the preceding period are kept securely within India so they can be provided to CERT-In along with the report. The company's written incident log, with times, is its record that it acted within 6 hours.

Need help with CERT-In compliance?

If your business is a service provider, intermediary, data centre or body corporate and wants an incident escalation process, a Point of Contact and a log retention plan, our team can help. Begin with a legal due diligence review.

Key takeaways

  • Directions (i) to (iv) cover NTP synchronisation, reporting of Annexure I incidents within 6 hours, action and a Point of Contact, and logs kept for a rolling period of 180 days within the Indian jurisdiction.
  • Annexure I lists twenty types of incident; Annexure II is the Point of Contact format.
  • Section 70B(7) is cited for non-compliance; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the fine figure changes from "one lakh" to "one crore"; check whether it is in force.
  • The Directions "become effective after 60 days from the date on which it is issued"; later clarifications and amendments should be checked.

Read next

Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About CERT-In Directions of 28

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is the reporting period under the Directions?

Within 6 hours of noticing the incident or being brought to notice about it, for incidents in Annexure I.

How long must logs be kept?

For a rolling period of 180 days, maintained within the Indian jurisdiction.

Know which registrations your business actually needs — both too few and too many cost money.

— TaxClue Compliance Desk

CERT-In Directions of 28: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 7 questions readers ask most on this topic.

Within 6 hours of noticing the incident or being brought to notice about it, for incidents in Annexure I.

For a rolling period of 180 days, maintained within the Indian jurisdiction.

Service providers, intermediaries, data centres, body corporate and Government organisations.

The Directions print email (incident@cert-in.org.in), phone (1800-11-4949) and fax (1800-11-6969), and say the methods and formats are also published on the CERT-In website and will be updated from time to time.

A person designated to interface with CERT-In, whose details are sent in the Annexure II format.

The Directions say it "may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable".

No. Later clarifications and amendments should be checked.