Insights/Regulatory Newsroom
CERT-In Incident Reporting: When, How, and What Happens If You Don’t
Published
Reading time2 minutes
FromTriad ICS Research

Six hours is not long. Here is what CERT-In’s directions require and how to be ready before you need to be.
In April 2022, CERT-In issued directions under Section 70B(6) of the Information Technology Act, 2000 that changed incident reporting in India. The headline requirement is short: report specified cyber incidents to CERT-In within six hours of noticing them or being told about them. Meeting it is harder than it sounds.
Who has to report
The directions apply broadly: service providers, intermediaries, data centres, body corporates and government organisations. In practice, if you run IT systems in India for a business, you should assume they apply to you.
What has to be reported
The directions list the incident types in an annexure. They include, among others:
- Targeted scanning or probing of critical networks and systems
- Compromise of critical systems or information
- Unauthorised access to IT systems or data
- Website defacement, or intrusion into a website to inject malicious code
- Malicious code attacks, including ransomware
- Attacks on servers, databases, email and DNS
- Identity theft, spoofing and phishing attacks
- Denial-of-service and distributed denial-of-service attacks
- Data breaches and data leaks
- Attacks on cloud systems, IoT devices and digital payment systems
How to report
Reports go to CERT-In by email to incident@cert-in.org.in, or through the formats and channels published on the CERT-In website. The first report can be a preliminary one; you are not expected to have completed your investigation in six hours. You are expected to have noticed, assessed and told them.
The obligations around reporting
The same directions carry supporting requirements that make reporting possible:
- Designate a point of contact to interface with CERT-In.
- Keep logs of your ICT systems for a rolling 180 days, within Indian jurisdiction, and provide them when asked.
- Synchronise system clocks with the NTP servers of the National Informatics Centre or the National Physical Laboratory, or with servers traceable to them.
What happens if you don’t
Non-compliance can be dealt with under Section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to ₹1 lakh, or both. The larger cost is usually practical: an incident discovered late, logs that no longer exist, and a regulator who hears about it from someone else.
Getting ready
- Decide in advance who has authority to file the report.
- Keep a prepared template with your organisation’s details filled in.
- Check that your logs are really retained for 180 days, and that timestamps agree across systems.
- Run a tabletop exercise: start a clock and see how long it takes your team to reach the point of reporting.
This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.