CERT-In Directions 2022:
What every Indian business must do
The CERT-In Directions 2022 bind service providers, intermediaries, data centres, body corporates and Government organisations — no size threshold, no sector carve-out, so in practice every company operating in India. Here is what they require and where most businesses fall short.
Last updated: July 2026
Who does this apply to?
Every entity that owns, operates, or uses computer resources in India. That includes businesses of every size, enterprises, government bodies, NGOs, and individuals conducting business online. If your servers are in India, your users are in India, or your business is registered in India — these directions apply to you.
There is no minimum revenue, employee count, or data volume that exempts you. This is the most commonly misunderstood aspect of the Directions — many founders assume they are too small to be in scope. They are not.
The four core obligations
1. Incident reporting — 6-hour rule
Report any cyber incident to CERT-In within 6 hours of noticing it — or of being brought to notice of it. The clock starts when you become aware of the incident — not when it is confirmed, not when you have completed your investigation, and not when you decide it is serious enough. Detection starts the clock.
Reports are submitted at cert-in.org.in or by email to incident@cert-in.org.in. The report must include: nature of the incident, systems affected, time of detection, impact assessment, and steps taken or planned.
This requires a documented incident response procedure before an incident happens — not improvised in the middle of one.
2. 180-day log retention
All ICT system logs must be retained for a minimum of 180 days and stored in India. This covers application logs, server logs, access logs, network logs, and any other system event data.
AWS CloudWatch defaults to 90 days. GCP Cloud Logging defaults to 30 days (_Default bucket) or 400 days (_Required bucket for audit logs only). Neither default is compliant without explicit configuration.
Fix: Set CloudWatch log group retention to 180+ days. Set GCP log bucket retention to 180+ days. Ensure the log storage bucket is in ap-south-1 or asia-south1.
3. NTP synchronisation
All servers and systems must be synchronised to Indian NTP servers: samay1.nic.in, samay2.nic.in, or time.nptel.ac.in.
This matters for incident correlation. When logs from different systems have accurate, consistent timestamps, investigators can reconstruct what happened and when. Inaccurate timestamps can make an incident investigation impossible.
4. Designate a Point of Contact with CERT-In
Designate a Point of Contact to interface with CERT-In and file it in the Annexure II format, keeping it updated. All CERT-In communications go to that contact, and an order from CERT-In must be answered in the format and timeframe specified — up to near real-time — or it is treated as non-compliance.
Note: CERT-In localises logs, not primary systems. Nothing in the Direction requires your servers or databases to be in India. Where you do want India-resident infrastructure — or where a sector rule such as RBI payment-system data applies — AWS ap-south-1 and GCP asia-south1 are the usual choices.
What incidents must be reported?
CERT-In specifies 20 categories of reportable incidents. This is a broader list than most people expect — it goes well beyond data breaches:
Where most businesses fall short
No incident response procedure
When an incident happens, there is no defined owner, no escalation path, and no way to meet the 6-hour clock. By the time someone decides what to do, the deadline has passed.
Logs stored outside India
Many businesses use GCP or AWS and default to us-east-1 or europe-west1. The Direction requires ICT logs to be maintained within Indian jurisdiction, so a default region puts you outside the log-retention requirement.
No log retention policy configured
Default CloudWatch or GCP Logging retention is 30–90 days. CERT-In requires 180 days minimum. This is a configuration change that takes 10 minutes — but most businesses have never made it.
NTP not configured to Indian servers
Servers synced to pool.ntp.org or AWS/GCP internal NTP are non-compliant. CERT-In requires samay1.nic.in, samay2.nic.in, or time.nptel.ac.in.
No designated CERT-In reporting contact
CERT-In requires a designated point of contact. If no one is named, no one owns the 6-hour obligation — and it falls through the gap.
What happens if you don't comply?
Non-compliance with CERT-In Directions can result in imprisonment of up to one year and/or a fine under the IT Act 2000. More practically: if you experience a breach and cannot demonstrate compliance — no incident report filed within 6 hours, no 180-day logs, no NTP config — the regulatory and legal exposure compounds significantly.
CERT-In enforcement is still maturing, but the risk of being caught unprepared during or after a breach is real. The Directions are not a box-ticking exercise — they exist because log retention and incident reporting are what make incident investigation and recovery possible.
Get compliant
Check your CERT-In posture for free
Run a free scan on security.kaitara.com/scan — we check your HTTPS, security headers, email security, and DPDP Act compliance signals in under 2 minutes. For CERT-In implementation (log retention, NTP, incident response SOP, Point of Contact) we offer fixed-fee engagements.
Further reading: CERT-In's 6-hour rule, explained