The Indian Computer Emergency Response Team (CERT-In) issued directions in April 2022 under the Information Technology Act, 2000 that materially changed incident-handling obligations for a wide range of organisations operating in India — not only “critical infrastructure,” but service providers, intermediaries, data centres, body corporates and government organisations more broadly.
The headline requirement: a 6-hour reporting window. Specified categories of cybersecurity incidents — including data breaches, ransomware, DNS server compromise, and unauthorised access to IT systems — must be reported to CERT-In within 6 hours of being noticed or brought to notice. This is a materially shorter window than most organisations’ existing incident response runbooks assumed, and it means detection-to-decision time, not just technical response, has to be built into the process.
Log retention. Organisations are required to maintain logs of their ICT systems for a rolling 180 days, and — critically — those logs must be maintained within Indian jurisdiction. For organisations using cloud logging or SIEM platforms hosted outside India, this has direct architectural implications, not just a policy update.
Time synchronisation. Systems must synchronise their clocks to the Network Time Protocol (NTP) servers of the National Informatics Centre (NIC) or National Physical Laboratory (NPL), or to NTP servers traceable to these. This sounds minor but matters enormously for incident forensics and log correlation — timestamp drift across systems is one of the most common practical obstacles to reconstructing an incident timeline.
KYC and record-keeping for specific service categories. Data centres, virtual private server (VPS) providers, cloud service providers, and virtual private network (VPN) service providers have additional obligations to maintain accurate customer information (name, validated address, contact number, purpose of use, and validity period) for a defined retention period after account closure.
A designated Point of Contact. Organisations are required to designate a Point of Contact to interface with CERT-In for the purposes of these directions.
Where organisations most commonly fall short, based on the pattern of readiness gaps we see in assessments: incident classification and escalation criteria that were never updated to match the 6-hour clock; log retention architecture built around a 30- or 90-day default rather than 180 days; and logging infrastructure that sits outside India by default because that’s where the rest of the cloud estate lives. None of these are difficult to fix individually — but each requires a deliberate architectural or process decision, not just an updated policy document.