← Back to all briefings
Cybersecurity 5 min read Published Updated Credibility 40/100

Cybersecurity Briefing — India CERT-In 6-Hour Cyber Incident Reporting Directive

India’s CERT-In issued directions on 28 April 2022 mandating that a wide range of service providers and enterprises report specified cyber incidents within six hours and retain detailed logs for 180 days.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

On 28 April 2022 India’s Computer Emergency Response Team (CERT-In) invoked its Section 70B authority to order service providers, data centers, VPN companies, cloud providers, and enterprises to report defined security incidents within six hours of noticing them. The directive also requires organizations to synchronize system clocks with NTP servers, retain ICT system logs for 180 days within India, maintain subscriber/customer KYC information, and share it on request.

The rules became enforceable after 60 days, with compliance deadlines extended for some providers. Security and privacy teams operating in India must update incident playbooks, log retention, and customer verification processes to align with the accelerated reporting timeline and data localization expectations.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Incident Reporting
  • India
  • Regulation
  • Logging
Back to curated briefings