{"id":971,"date":"2026-08-23T21:20:03","date_gmt":"2026-08-23T21:20:03","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=971"},"modified":"2026-08-23T21:20:03","modified_gmt":"2026-08-23T21:20:03","slug":"cert-in-incident-reporting","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/guides\/cert-in-incident-reporting\/","title":{"rendered":"CERT-In 6-Hour Reporting: The Rule Indian Startups Keep Missing"},"content":{"rendered":"\n<style>\n.og{\n  --navy:#1c267a; --navy-2:#2e3a9e; --navy-3:#141c5c;\n  --indigo:#4657e5; --peri:#97a2ff;\n  --ink:#060818; --ink-2:#373a51; --ink-3:#6b6d80;\n  --page:#f3f4fc; --bg-2:#e6e8f7; --paper:#ffffff; --line:#d9dcf1;\n  --t1:#eaecfd; --t2:#e6e8f7; --t3:#f3f4fc; --t4:#dddff4; --t5:#f0f1fb;\n  font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif;\n  font-size:17px; line-height:1.75; color:var(--ink); max-width:820px; margin:0 auto;\n}\n.og p{margin:0 0 20px}\n.og a{color:var(--navy-2); text-decoration:underline; text-underline-offset:2px}\n.og .dek{font-size:19px; line-height:1.6; margin:0 0 18px}\n.og .pills{display:flex; flex-wrap:wrap; gap:8px; margin:0 0 28px; padding:0; list-style:none}\n.og .pills li{font-size:12.5px; font-weight:600; letter-spacing:.02em; padding:5px 13px;\n  border-radius:999px; background:var(--t1); color:var(--navy)}\n.og .shortans{border-radius:14px; padding:26px 30px; margin:0 0 26px;\n  background:linear-gradient(135deg,#eaecfd 0%,#e6e8f7 100%)}\n.og .shortans h4{margin:0 0 10px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase;\n  font-weight:700; color:var(--navy)}\n.og .shortans p{margin:0; font-size:18px; line-height:1.65; font-weight:500}\n.og h2{font-size:27px; line-height:1.3; font-weight:700; color:var(--navy);\n  margin:54px 0 14px; padding-bottom:10px; letter-spacing:-.015em; position:relative}\n.og h2::after{content:\"\"; position:absolute; left:0; bottom:0; width:56px; height:3px; border-radius:2px}\n.og h2.s1::after{background:var(--navy)}\n.og h2.s2::after{background:var(--navy-2)}\n.og h2.s3::after{background:var(--indigo)}\n.og h2.s4::after{background:var(--peri)}\n.og h2.s5::after{background:var(--navy-3)}\n.og h2 + .sub{color:var(--ink-2); font-size:16px; margin:0 0 22px}\n.og h3{font-size:19px; font-weight:650; color:var(--navy-2); margin:32px 0 10px}\n.og .toc{border:1px solid var(--line); border-radius:14px; padding:22px 26px; margin:0 0 44px; background:var(--page)}\n.og .toc h4{margin:0 0 12px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase; font-weight:700; color:var(--navy)}\n.og .toc ol{margin:0; padding:0; list-style:none; counter-reset:t}\n.og .toc li{counter-increment:t; padding:9px 0 9px 34px; border-bottom:1px solid var(--line);\n  font-size:16px; line-height:1.5; position:relative}\n.og .toc li:last-child{border-bottom:none; padding-bottom:0}\n.og .toc li::before{content:counter(t,decimal-leading-zero); position:absolute; left:0; top:11px;\n  font-size:12px; font-weight:700; color:var(--indigo)}\n.og .toc a{color:var(--navy); font-weight:600; text-decoration:none}\n.og .toc a:hover{text-decoration:underline}\n.og .scroll{overflow-x:auto; -webkit-overflow-scrolling:touch; margin:26px 0 30px;\n  border:1px solid var(--line); border-radius:14px; background:var(--paper)}\n.og .scroll svg{display:block; min-width:660px; width:100%; height:auto}\n.og .cap{font-size:13.5px; color:var(--ink-2); text-align:center; margin:-18px 0 30px}\n.og .trio{display:grid; grid-template-columns:repeat(3,1fr); gap:12px; margin:26px 0 30px}\n.og .duo{display:grid; grid-template-columns:repeat(2,1fr); gap:12px; margin:26px 0 30px}\n.og .cd{border-radius:12px; padding:20px 22px}\n.og .cd.a{background:var(--t1)} .og .cd.b{background:var(--t2)} .og .cd.c{background:var(--t3)}\n.og .cd.d{background:var(--t4)} .og .cd.e{background:var(--t5)}\n.og .cd .code{display:block; font-size:11.5px; font-weight:700; letter-spacing:.07em;\n  text-transform:uppercase; color:var(--indigo); margin-bottom:7px}\n.og .cd h5{margin:0 0 7px; font-size:16.5px; font-weight:650; color:var(--navy); line-height:1.35}\n.og .cd p{margin:0; font-size:15px; line-height:1.6}\n.og .note{border:1px solid var(--navy); border-radius:12px; padding:20px 24px; margin:28px 0; background:var(--paper)}\n.og .note p{margin:0; font-size:16.5px; line-height:1.65}\n.og .note strong{color:var(--navy)}\n.og table{width:100%; border-collapse:separate; border-spacing:0; margin:26px 0 32px; font-size:15.5px;\n  border:1px solid var(--line); border-radius:12px; overflow:hidden}\n.og th{background:var(--navy); color:#fff; text-align:left; padding:14px 16px; font-weight:700;\n  font-size:13px; line-height:1.4; letter-spacing:.055em; text-transform:uppercase}\n.og td{border:0; border-top:1px solid var(--line); padding:13px 16px; vertical-align:top; line-height:1.6}\n.og tbody tr:first-child td{border-top:0}\n.og tbody tr:nth-child(even){background:var(--t3)}\n.og tbody td:first-child{font-weight:600; color:var(--navy)}\n.og tbody tr:nth-child(even){background:var(--page)}\n.og .steps{margin:26px 0 30px; padding:0; list-style:none; counter-reset:s}\n.og .steps li{counter-increment:s; position:relative; padding:14px 18px 14px 56px; margin-bottom:8px;\n  border-radius:11px; background:var(--page); font-size:16px; line-height:1.55}\n.og .steps li::before{content:counter(s); position:absolute; left:16px; top:14px; width:26px; height:26px;\n  border-radius:50%; background:var(--navy); color:#fff; font-size:13px; font-weight:700;\n  display:flex; align-items:center; justify-content:center}\n.og .steps span{display:block; font-size:14px; color:var(--ink-2); margin-top:3px}\n.og details{border:1px solid var(--line); border-radius:11px; padding:15px 20px; margin-bottom:9px; background:var(--paper)}\n.og details[open]{border-color:var(--peri)}\n.og summary{font-weight:650; color:var(--navy); cursor:pointer; font-size:16.5px; line-height:1.5}\n.og details p{margin:12px 0 0; font-size:16px; line-height:1.7}\n.og .cta{border-radius:16px; padding:38px 34px; margin:52px 0 30px; text-align:center;\n  background:linear-gradient(135deg,#141c5c 0%,#4657e5 100%)}\n.og .cta h3{color:#fff; margin:0 0 10px; font-size:25px; line-height:1.3}\n.og .cta p{color:#d5d8f5; margin:0 0 24px; font-size:16.5px; line-height:1.6}\n.og .cta .btns{display:flex; gap:12px; justify-content:center; flex-wrap:wrap}\n.og .cta a{display:inline-block; padding:14px 30px; border-radius:9px; font-weight:650; font-size:16px; text-decoration:none}\n.og .cta a.p{background:#ffffff}\n.og .cta a.p span{color:#1c267a !important}\n.og .cta a.s{border:1px solid rgba(255,255,255,.6)}\n.og .cta a.s span{color:#ffffff !important}\n.og .foot{border-top:1px solid var(--line); padding-top:20px; margin-top:42px; font-size:14.5px;\n  color:var(--ink-2); line-height:1.7}\n@media(max-width:680px){\n  .og{font-size:16px}\n  .og h2{font-size:22px} .og .dek{font-size:17px} .og .shortans p{font-size:16.5px}\n  .og .trio,.og .duo{grid-template-columns:1fr}\n  .og .shortans{padding:20px 22px} .og .toc{padding:18px 20px} .og .cta{padding:28px 20px}\n  .og table{font-size:14px} .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">Six hours from the moment you notice, not from the moment you understand. Twenty reportable categories, criminal liability attached, and a separate clock running for every other regulator you answer to.<\/p>\n\n<ul class=\"pills\"><li>India<\/li><li>CERT-In<\/li><li>Incident response<\/li><li>Regulatory<\/li><\/ul>\n\n<div class=\"shortans\">\n  <h4>The short answer<\/h4>\n  <p>CERT-In Directions dated 28 April 2022, effective 27 June 2022, require organisations in India to report any of twenty specified cyber security incident categories within six hours of noticing them. Non-compliance is an offence under Section 70B(7) of the IT Act carrying up to one year of imprisonment, a fine up to one lakh rupees, or both. Logs must be retained in India for 180 days.<\/p>\n<\/div>\n\n<p>Most incident response processes take six hours just to confirm something real has happened. That is the problem this rule creates, and the reason preparation matters more here than in almost any other regime.<\/p>\n\n<div class=\"toc\">\n  <h4>On this page<\/h4>\n  <ol>\n    <li><a href=\"#clock\">When the clock starts<\/a><\/li>\n    <li><a href=\"#what\">What counts as reportable<\/a><\/li>\n    <li><a href=\"#file\">What you file in six hours<\/a><\/li>\n    <li><a href=\"#other\">The two obligations that come with it<\/a><\/li>\n    <li><a href=\"#parallel\">The other clocks running<\/a><\/li>\n    <li><a href=\"#ready\">Getting ready before you need it<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<div class=\"note\">\n  <p><strong>This is not legal advice.<\/strong> CERT-In obligations are statutory and their application depends on your entity type, sector and the specific facts of an incident. Confirm your position with qualified Indian counsel before relying on any summary, including this one.<\/p>\n<\/div>\n\n<h2 class=\"s1\" id=\"clock\">When the clock starts<\/h2>\n\n<p>Six hours from noticing the incident or being brought to notice about it. Not six hours from confirming it, not from completing triage, and not from the point somebody senior agrees it is serious.<\/p>\n\n<p>That distinction is where most organisations get caught. A mature response process typically spends the first few hours establishing whether an alert is real, looping in stakeholders and drafting an internal situation report. By the time that finishes, the regulatory deadline can already have passed.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 244\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"CERT-In six hour reporting window compared against GDPR and DPDP seventy two hour windows\">\n<text x=\"16\" y=\"28\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Reporting windows compared<\/text>\n<text x=\"16\" y=\"71\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#373a51\">CERT-In<\/text>\n<rect x=\"168\" y=\"54\" width=\"48\" height=\"24\" rx=\"4\" fill=\"#1c267a\"\/>\n<text x=\"228\" y=\"71\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#1c267a\">6 hours<\/text>\n<text x=\"16\" y=\"123\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#373a51\">GDPR<\/text>\n<rect x=\"168\" y=\"106\" width=\"580\" height=\"24\" rx=\"4\" fill=\"#97a2ff\"\/>\n<text x=\"182\" y=\"123\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">72 hours<\/text>\n<text x=\"16\" y=\"175\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#373a51\">DPDP Board report<\/text>\n<rect x=\"168\" y=\"158\" width=\"580\" height=\"24\" rx=\"4\" fill=\"#97a2ff\"\/>\n<text x=\"182\" y=\"175\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">72 hours<\/text>\n<text x=\"16\" y=\"232\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" fill=\"#373a51\">CERT-In closes before most teams finish internal triage.<\/text>\n<\/svg>\n<\/div>\n\n<h2 class=\"s2\" id=\"what\">What counts as reportable<\/h2>\n\n<p>The 2013 CERT-In Rules listed ten mandatorily reportable incident types. The 2022 Directions expanded that to twenty, and the expansion is where teams get exposed, because several of the added categories are events people would not instinctively treat as a breach.<\/p>\n\n<div class=\"trio\">\n  <div class=\"cd a\"><h5>Obvious ones<\/h5>\n    <p>Targeted scanning of critical systems, compromise of critical systems, unauthorised access to data, website defacement, malware and ransomware.<\/p><\/div>\n  <div class=\"cd b\"><h5>Less obvious ones<\/h5>\n    <p>Attacks on servers and network devices, identity theft and phishing, denial of service, attacks on applications and databases, data breach and data leak.<\/p><\/div>\n  <div class=\"cd d\"><h5>Easily missed<\/h5>\n    <p>Incidents affecting IoT devices, cloud systems, big data platforms, blockchain and virtual assets, robotics and drones, and systems related to digital payments.<\/p><\/div>\n<\/div>\n\n<div class=\"note\">\n  <p><strong>Under-reporting is a violation, not a judgment call.<\/strong> Deciding an incident was too minor to report is itself a compliance risk. Train the team to recognise all twenty categories rather than the handful that feel serious.<\/p>\n<\/div>\n\n<h2 class=\"s3\" id=\"file\">What you file in six hours<\/h2>\n\n<p>The six-hour report is an initial notification, not an investigation. You are not expected to produce root cause, complete impact assessment or attribution in that window, and attempting to will make you late.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 200\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Timeline of the first six hours from noticing an incident to filing the initial CERT-In intimation\">\n<text x=\"16\" y=\"28\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">The first six hours<\/text>\n<rect x=\"16\" y=\"48\" width=\"142\" height=\"118\" rx=\"12\" fill=\"#1c267a\"\/>\n<text x=\"87\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#ffffff\">0:00<\/text>\n<text x=\"87\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Noticed<\/text>\n<text x=\"87\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#ffffff\">alert, report or<\/text>\n<text x=\"87\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#ffffff\">third-party notice<\/text>\n<path d=\"M159 107 L167 107\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<rect x=\"168\" y=\"48\" width=\"142\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"238\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">0:30<\/text>\n<text x=\"238\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#1c267a\">Confirm and log<\/text>\n<text x=\"238\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">record the detection<\/text>\n<text x=\"238\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">timestamp precisely<\/text>\n<path d=\"M310 107 L318 107\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<rect x=\"319\" y=\"48\" width=\"142\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"390\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">2:00<\/text>\n<text x=\"390\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#1c267a\">Contain<\/text>\n<text x=\"390\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">and start the<\/text>\n<text x=\"390\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">evidence trail<\/text>\n<path d=\"M462 107 L470 107\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<rect x=\"471\" y=\"48\" width=\"142\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"542\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">4:00<\/text>\n<text x=\"542\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#1c267a\">Draft the notice<\/text>\n<text x=\"542\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">six fields, marked<\/text>\n<text x=\"542\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#373a51\">preliminary<\/text>\n<path d=\"M613 107 L621 107\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<rect x=\"622\" y=\"48\" width=\"142\" height=\"118\" rx=\"12\" fill=\"#1c267a\"\/>\n<text x=\"693\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#ffffff\">6:00<\/text>\n<text x=\"693\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Filed<\/text>\n<text x=\"693\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#ffffff\">initial intimation<\/text>\n<text x=\"693\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"11.5\" fill=\"#ffffff\">to CERT-In<\/text>\n<text x=\"16\" y=\"190\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" fill=\"#373a51\">You are not expected to have root cause. You are expected to have filed.<\/text>\n<\/svg>\n<\/div>\n\n<table>\n  <thead><tr><th>Field<\/th><th>What to put<\/th><\/tr><\/thead>\n  <tbody>\n    <tr><td>Incident category<\/td><td>Which of the reportable types this falls under<\/td><\/tr>\n    <tr><td>Detection timestamp<\/td><td>When it was noticed, synchronised to the designated time source<\/td><\/tr>\n    <tr><td>Affected systems<\/td><td>Named systems and their function, as currently understood<\/td><\/tr>\n    <tr><td>Estimated scope<\/td><td>A best current estimate, marked as preliminary<\/td><\/tr>\n    <tr><td>Point of contact<\/td><td>A named person who can be reached, not a shared inbox<\/td><\/tr>\n    <tr><td>Initial containment<\/td><td>What you have already done to limit the incident<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Reports go to CERT-In by the channels published in the Directions. Have the submission route tested and the contact details current before an incident, not during one.<\/p>\n\n<h2 class=\"s4\" id=\"other\">The two obligations that come with it<\/h2>\n\n<p>Reporting is the visible requirement. Two others in the same Directions are discovered by many organisations only during an inspection.<\/p>\n\n<div class=\"duo\">\n  <div class=\"cd c\"><h5>180 days of logs, held in India<\/h5>\n    <p>Logs of all ICT systems must be enabled, maintained securely and retained for a rolling 180 days within Indian jurisdiction. If your logging stack ships everything to a region outside India by default, that is a configuration problem worth finding now.<\/p><\/div>\n  <div class=\"cd e\"><h5>Synchronised time<\/h5>\n    <p>ICT systems must be synchronised to the designated network time source. This sounds administrative until you need to correlate events across systems during an investigation and the timestamps do not line up.<\/p><\/div>\n<\/div>\n\n<h2 class=\"s5\" id=\"parallel\">The other clocks running<\/h2>\n\n<p>CERT-In is one obligation triggered by an incident, not the only one. Depending on what you do and who your customers are, the same event can start several timers at once.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"One incident triggering parallel reporting obligations to CERT-In, the DPDP Board, data principals and sector regulators\">\n<rect x=\"290\" y=\"14\" width=\"200\" height=\"50\" rx=\"12\" fill=\"#1c267a\"\/>\n<text x=\"390\" y=\"45\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#ffffff\">One incident detected<\/text>\n<path d=\"M390 64 L390 86\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M104 86 L676 86\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M104 86 L104 106\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M295 86 L295 106\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M485 86 L485 106\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M676 86 L676 106\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<rect x=\"16\" y=\"106\" width=\"176\" height=\"106\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"104\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">CERT-In<\/text>\n<text x=\"104\" y=\"166\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"18\" font-weight=\"700\" fill=\"#1c267a\">6 hrs<\/text>\n<text x=\"104\" y=\"192\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">from noticing<\/text>\n<rect x=\"206\" y=\"106\" width=\"176\" height=\"106\" rx=\"12\" fill=\"#eaecfd\"\/>\n<text x=\"295\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">DPDP Board<\/text>\n<text x=\"295\" y=\"166\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"18\" font-weight=\"700\" fill=\"#1c267a\">72 hrs<\/text>\n<text x=\"295\" y=\"192\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">detailed report<\/text>\n<rect x=\"397\" y=\"106\" width=\"176\" height=\"106\" rx=\"12\" fill=\"#dddff4\"\/>\n<text x=\"485\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Data principals<\/text>\n<text x=\"485\" y=\"166\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"18\" font-weight=\"700\" fill=\"#1c267a\">without delay<\/text>\n<text x=\"485\" y=\"192\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">affected individuals<\/text>\n<rect x=\"588\" y=\"106\" width=\"176\" height=\"106\" rx=\"12\" fill=\"#f0f1fb\"\/>\n<text x=\"676\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Sector regulator<\/text>\n<text x=\"676\" y=\"166\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"18\" font-weight=\"700\" fill=\"#1c267a\">varies<\/text>\n<text x=\"676\" y=\"192\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">RBI, SEBI, IRDAI<\/text>\n<text x=\"16\" y=\"238\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" fill=\"#373a51\">Same trigger, different recipients, different deadlines. Applicability depends on sector and data.<\/text>\n<\/svg>\n<\/div>\n\n<h2 class=\"s1\" id=\"ready\">Getting ready before you need it<\/h2>\n\n<ol class=\"steps\">\n  <li>Name the person who can file at 3am<span>And a backup, with the CERT-In submission route tested<\/span><\/li>\n  <li>Write the six-hour report as a template now<span>Six fields, pre-filled where possible, blanks for the rest<\/span><\/li>\n  <li>Check where your logs physically live<span>180 days, in India, is a hosting question before it is a policy one<\/span><\/li>\n  <li>Synchronise every system to the designated time source<span>Including anything running outside your main cloud account<\/span><\/li>\n  <li>Train on all twenty categories, not the obvious five<span>The gap is usually cloud, payments and IoT incidents<\/span><\/li>\n  <li>Map every clock the same incident starts<span>One intake, fanning out to each regulator that applies to you<\/span><\/li>\n<\/ol>\n\n<h2 class=\"s2\">Where Osto helps<\/h2>\n\n<p>Detection speed is what makes a six-hour window survivable. Osto correlates events across web protection, cloud posture, endpoint and code security in one platform, so an incident surfaces as a single picture rather than four separate alerts somebody has to assemble.<\/p>\n\n<p>Log retention and time synchronisation are configuration questions we cover during assessment, and both are common findings in Indian environments built on default cloud settings.<\/p>\n\n<div class=\"cta\">\n  <h3>Check your six-hour readiness<\/h3>\n  <p>A free assessment reviews detection coverage, log retention location and time synchronisation against the CERT-In Directions.<\/p>\n  <div class=\"btns\">\n    <a class=\"p\" href=\"https:\/\/www.osto.one\/contact\"><span>Get a free security assessment<\/span><\/a>\n    <a class=\"s\" href=\"https:\/\/www.osto.one\/book-demo\"><span>Book a platform walkthrough<\/span><\/a>\n  <\/div>\n<\/div>\n\n<h2 class=\"s3\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the CERT-In 6-hour rule?<\/summary>\n  <p>Under Directions issued on 28 April 2022 and effective from 27 June 2022, any service provider, intermediary, data centre, body corporate or government organisation in India must report specified cyber security incidents to CERT-In within six hours of noticing the incident or being made aware of it. The Directions were issued under Section 70B(6) of the Information Technology Act, 2000.<\/p>\n<\/details>\n<details>\n  <summary>What is the penalty for not reporting to CERT-In?<\/summary>\n  <p>Failure to comply with a CERT-In direction is an offence under Section 70B(7) of the IT Act, carrying imprisonment of up to one year, a fine of up to one lakh rupees, or both. Section 70B(8) provides that no court takes cognisance unless a complaint is made by a CERT-In officer. Proposed amendments have sought to raise the financial penalty substantially.<\/p>\n<\/details>\n<details>\n  <summary>How many types of incidents must be reported to CERT-In?<\/summary>\n  <p>The 2022 Directions expanded the list of mandatorily reportable incident categories from the original ten under the 2013 CERT-In Rules to twenty. Under-reporting is treated as seriously as not reporting, so teams need to recognise all twenty categories rather than only the obvious breach scenarios.<\/p>\n<\/details>\n<details>\n  <summary>Does the 6-hour clock start at detection or at confirmation?<\/summary>\n  <p>At the point the incident is noticed or brought to your attention, not when investigation concludes. This is the most commonly misunderstood part of the rule. You are not expected to have root cause, full impact assessment or attribution within six hours.<\/p>\n<\/details>\n<details>\n  <summary>How does CERT-In compare to GDPR and DPDP timelines?<\/summary>\n  <p>CERT-In is considerably tighter. GDPR allows 72 hours to notify a supervisory authority, and the DPDP framework works to a comparable window for the detailed Board report. CERT-In requires six hours, which is among the shortest statutory incident reporting windows anywhere.<\/p>\n<\/details>\n<details>\n  <summary>What are the log retention requirements under CERT-In?<\/summary>\n  <p>The Directions require organisations to enable logs of all ICT systems and maintain them securely for a rolling period of 180 days within Indian jurisdiction. Systems must also be synchronised to a designated network time source, so timestamps across systems are consistent during an investigation.<\/p>\n<\/details>\n<details>\n  <summary>Do CERT-In and DPDP obligations run at the same time?<\/summary>\n  <p>Yes. They are separate obligations with separate clocks and separate recipients, both triggered by the same event. Sector regulators may add further reporting duties. Building one intake process that fans out to every applicable regulator is more reliable than treating each as a distinct workflow.<\/p>\n<\/details>\n\n<div class=\"foot\">\n  <p><strong>Related reading:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act explained<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-readiness-checklist\/\">SOC 2 readiness checklist<\/a><\/p>\n  <p><strong>Accuracy and legal note:<\/strong> This guide summarises the CERT-In Directions No. 20(3)\/2022 dated 28 April 2022, effective 27 June 2022, issued under Section 70B(6) of the Information Technology Act, 2000, and related provisions, current to August 2026. It is general information and not legal advice. Applicability, incident classification and penalties depend on entity type, sector and specific facts. Proposed legislative amendments may alter penalty levels. Consult qualified Indian counsel on your obligations.<\/p>\n<\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What is the CERT-In 6-hour rule?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Under Directions issued on 28 April 2022 and effective from 27 June 2022, any service provider, intermediary, data centre, body corporate or government organisation in India must report specified cyber security incidents to CERT-In within six hours of noticing the incident or being made aware of it. The Directions were issued under Section 70B(6) of the Information Technology Act, 2000.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What is the penalty for not reporting to CERT-In?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Failure to comply with a CERT-In direction is an offence under Section 70B(7) of the IT Act, carrying imprisonment of up to one year, a fine of up to one lakh rupees, or both. Section 70B(8) provides that no court takes cognisance unless a complaint is made by a CERT-In officer. Proposed amendments have sought to raise the financial penalty substantially.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How many types of incidents must be reported to CERT-In?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"The 2022 Directions expanded the list of mandatorily reportable incident categories from the original ten under the 2013 CERT-In Rules to twenty. Under-reporting is treated as seriously as not reporting, so teams need to recognise all twenty categories rather than only the obvious breach scenarios.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Does the 6-hour clock start at detection or at confirmation?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"At the point the incident is noticed or brought to your attention, not when investigation concludes. This is the most commonly misunderstood part of the rule. You are not expected to have root cause, full impact assessment or attribution within six hours.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How does CERT-In compare to GDPR and DPDP timelines?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"CERT-In is considerably tighter. GDPR allows 72 hours to notify a supervisory authority, and the DPDP framework works to a comparable window for the detailed Board report. CERT-In requires six hours, which is among the shortest statutory incident reporting windows anywhere.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What are the log retention requirements under CERT-In?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"The Directions require organisations to enable logs of all ICT systems and maintain them securely for a rolling period of 180 days within Indian jurisdiction. Systems must also be synchronised to a designated network time source, so timestamps across systems are consistent during an investigation.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Do CERT-In and DPDP obligations run at the same time?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Yes. They are separate obligations with separate clocks and separate recipients, both triggered by the same event. Sector regulators may add further reporting duties. Building one intake process that fans out to every applicable regulator is more reliable than treating each as a distinct workflow.\"\n   }\n  }\n ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>Six hours from the moment you notice, not from the moment you understand. Twenty reportable categories, criminal liability attached, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":972,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[211],"tags":[430,432,429,431],"class_list":["post-971","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guides","tag-cert-in-compliance","tag-cert-in-directions-2022","tag-cert-in-incident-reporting","tag-cyber-incident-reporting-india"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=971"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/971\/revisions"}],"predecessor-version":[{"id":973,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/971\/revisions\/973"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/972"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}