Skip to content
CERT-In · India · 2022

CERT-In Directions 2022

Compliance checklist for CERT-In Directions under Section 70B of the IT Act 2000 (effective 28 June 2022). Mandatory for all organisations operating in India. Covers 24 controls across the six obligation areas the Directions actually specify (incident reporting, log retention, NTP sync, VPN/cloud/data-centre records, crypto/virtual-asset KYC, governance) — not a general IT Act compliance review.

Reporting

6 hours

Max time to report incidents

Log Retention

180 days

All ICT system logs

VPN Records

5 years

Subscriber data retention

Penalty

₹1 lakh

Per violation + imprisonment

0%0/24 controls implemented
Incident Reporting Obligations: 0/5
Log Retention Requirements: 0/5
NTP Synchronisation: 0/3
VPN, Cloud & Data Centre Obligations: 0/4
Cryptography & Virtual Asset Obligations: 0/2
Governance & Coordination: 0/5

Frequently Asked Questions

What is the CERT-In incident reporting timeline?

Directions issued under Section 70B of the IT Act 2000 (effective 28 June 2022) require reporting specified categories of cyber incidents to CERT-In within 6 hours of noticing them.

How long must logs be retained under CERT-In Directions?

ICT system logs must be securely maintained for a rolling period of 180 days within Indian jurisdiction.

Who must comply with CERT-In Directions?

Service providers, intermediaries, data centres, body corporates and government organisations operating in India.

Do VPN providers have specific obligations under CERT-In?

Yes — VPN and cloud service providers must retain customer registration and usage records (name, IP addresses assigned, purpose, validity period, etc.) for at least 5 years after account cancellation.