CERT-In Directions 2022
Compliance checklist for CERT-In Directions under Section 70B of the IT Act 2000 (effective 28 June 2022). Mandatory for all organisations operating in India. Covers 24 controls across the six obligation areas the Directions actually specify (incident reporting, log retention, NTP sync, VPN/cloud/data-centre records, crypto/virtual-asset KYC, governance) — not a general IT Act compliance review.
Reporting
6 hours
Max time to report incidents
Log Retention
180 days
All ICT system logs
VPN Records
5 years
Subscriber data retention
Penalty
₹1 lakh
Per violation + imprisonment
Related Compliance Frameworks
International ISMS standard — 93 controls across 4 themes. Widely recognised globally.
6-function framework (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) for any organisation size.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
Trust Service Criteria audit covering Security, Availability, Confidentiality, Integrity and Privacy.
Reserve Bank of India Master Directions covering cyber risk, SOC requirements and incident reporting.
Administrative, physical and technical safeguards for electronic Protected Health Information (ePHI).
Frequently Asked Questions
What is the CERT-In incident reporting timeline?
Directions issued under Section 70B of the IT Act 2000 (effective 28 June 2022) require reporting specified categories of cyber incidents to CERT-In within 6 hours of noticing them.
How long must logs be retained under CERT-In Directions?
ICT system logs must be securely maintained for a rolling period of 180 days within Indian jurisdiction.
Who must comply with CERT-In Directions?
Service providers, intermediaries, data centres, body corporates and government organisations operating in India.
Do VPN providers have specific obligations under CERT-In?
Yes — VPN and cloud service providers must retain customer registration and usage records (name, IP addresses assigned, purpose, validity period, etc.) for at least 5 years after account cancellation.