Section 70B explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 70B of the Information Technology Act, 2000 provides for an agency of the Government called the Indian Computer Emergency Response Team, lists its functions in the area of cyber security, and lets it call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Sub-section (7) prints a consequence for failing to comply, which is amended by an item of the Jan Vishwas (Amendment of Provisions) Act, 2023. This article explains the section as per the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008), then as amended; later amendments and the current position should be checked.
The Central Government appoints, by notification, an agency called the Indian Computer Emergency Response Team. It serves as the national agency for incident response and, under sub-section (6), may call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Failure to comply is, as printed, punishable with imprisonment up to one year, or fine up to one lakh rupees, or both. As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the words "one lakh" become "one crore".
Sub-sections (1) to (3): the agency and its staff
Sub-section (1) says the Central Government "shall, by notification in the Official Gazette, appoint an agency of the Government to be called the Indian Computer Emergency Response Team". Sub-section (2) says the Central Government shall provide the agency with "a Director-General and such other officers and employees as may be prescribed". Sub-section (3) says the salary and allowances and terms and conditions of the Director-General and other officers and employees "shall be such as may be prescribed". The Act prints no number of posts and no salary; those details are left to rules.
Sub-section (4): functions
The Indian Computer Emergency Response Team "shall serve as the national agency for performing the following functions in the area of cyber security":
| Clause | Function |
|---|---|
| (a) | collection, analysis and dissemination of information on cyber incidents |
| (b) | forecast and alerts of cyber security incidents |
| (c) | emergency measures for handling cyber security incidents |
| (d) | co-ordination of cyber incidents response activities |
| (e) | issue guidelines, advisories, vulnerability notes and white-papers relating to information security practices, procedures, prevention, response and reporting of cyber incidents |
| (f) | such other functions relating to cyber security as may be prescribed |
Sub-section (5) says the manner of performing functions and duties of the agency "shall be such as may be prescribed". The Act names no rule in this section, so none is described here.
Sub-section (6): calling for information and giving directions
Sub-section (6) reads: "For carrying out the provisions of sub-section (4), the agency referred to in sub-section (1) may call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person."
The power is tied to the functions in sub-section (4), and it reaches five named groups and "any other person". The Act does not define "service providers", "data centres" or "body corporate" in this section. "Intermediary" is defined in section 2(1)(w); our article on section 2 of the IT Act sets out that definition.
CERT-In issued directions of 28 April 2022 under sub-section (6) of section 70B. Our articles on cyber incident reporting and log retention under the CERT-In Directions and on customer records and KYC retention under the CERT-In Directions explain them as issued on 28 April 2022; later clarifications and amendments should be checked.
If your business hosts data, provides a platform or runs IT systems, a legal due diligence review of how you would receive, assess and answer a CERT-In direction is a useful preparation.
Sub-section (7): the consequence, as printed and as amended
As printed in the consolidated copy: "Any service provider, intermediaries, data centres, body corporate or person who fails to provide the information called for or comply with the direction under sub -section (6), shall be punishable with imprisonment for a term which may extend to one year or with fine which may extend to one lakh rupees or with both."
Item (I) in the Jan Vishwas (Amendment of Provisions) Act, 2023, Schedule item 32, reads: "In section 70B, in sub-section (7), for the words 'one lakh', the words 'one crore' shall be substituted." The one year term is not changed.
| Provision | As printed in the consolidated copy | As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023 |
|---|---|---|
| Section 70B(7), imprisonment | "a term which may extend to one year" | unchanged: one year |
| Section 70B(7), fine | "fine which may extend to one lakh rupees" | "fine which may extend to one crore rupees" |
| Combination | "or with both" | unchanged: "or with both" |
The copy also prints "sub -section (6)" with a stray space, which we leave as printed. Commencement of the Jan Vishwas (Amendment of Provisions) Act, 2023 is by notification of the Central Government, and different dates may be appointed for amendments relating to different enactments; no date is in the sources used for this article. Check whether the amendment to section 70B(7) has been brought into force.
Sub-section (8): who may complain
Sub-section (8) says: "No Court shall take cognizance of any offence under this section, except on a complaint made by an officer authorized in this behalf by the agency referred to in sub-section (1)." The offence in sub-section (7) is therefore taken up only on a complaint by an officer authorised by the agency. Sections 77A, 77B and 78 also apply across the offences of the Act as printed: section 77B prints "the offence punishable with imprisonment of three years and above shall be cognizable and the offence punishable with imprisonment of three years shall be bailable", which we quote and do not apply further. The Act refers to the Code of Criminal Procedure, 1973; check the current procedural law for the corresponding provisions.
A worked example
Nirmal Data Centres Private Limited, an invented operator, receives a written direction from the Indian Computer Emergency Response Team calling for specified information about a cyber security incident. The company's questions are whether it is within the groups named in sub-section (6), whether the direction relates to the functions in sub-section (4), and what the direction asks and by when. If the company fails to provide the information or comply, sub-section (7) states a consequence, and sub-section (8) says that a court takes cognizance only on a complaint by an authorised officer of the agency. The company should keep a written record of the direction, its reply and the dates.
Need help with CERT-In obligations?
If your organisation is a service provider, intermediary, data centre or body corporate and wants to understand its position under section 70B and the Directions issued under it, our team can help. Begin with a legal due diligence review.
Key takeaways
- Section 70B provides for the Indian Computer Emergency Response Team, appointed by notification, as the national agency for incident response.
- Sub-section (4) lists its functions; sub-section (6) lets it call for information and give direction to service providers, intermediaries, data centres, body corporate and any other person.
- As printed, sub-section (7) is imprisonment up to one year, or fine up to one lakh rupees, or both; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the fine becomes "one crore".
- Cognizance is only on a complaint by an officer authorised by the agency.
- Check whether the amendment has been brought into force; no date is in the sources.
Read next
- CERT-In Directions of 28 April 2022: cyber incident reporting and log retention
- CERT-In Directions of 28 April 2022: customer records and KYC retention for data centres, VPN and virtual asset providers
- Sections 70 and 70A of the Information Technology Act, 2000: protected system and national nodal agency
- Cyber Law: Information Technology Act 2000, offences, penalties and adjudication
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
