LEGALWEBSITE.inEvery page. Every law. No surprises. All articles
Security 5 min readReviewed 5 September 2026

CERT-In Directions, 2022: six hours to report, 180 days of logs

The reporting, log-retention, clock-synchronisation and KYC directions issued under Section 70B(6) of the IT Act, and who they bind.

The direction

On 28 April 2022 the Indian Computer Emergency Response Team issued directions under Section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents. They apply to service providers, intermediaries, data centres, body corporates and government organisations. They came into effect sixty days after issue.

What they require

  • Report specified cyber incidents to CERT-In within six hours of noticing them or being brought to notice. The Annexure to the directions lists the reportable incident types, including targeted scanning of critical systems, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code attacks, identity theft, data breach, data leak and attacks on servers, IoT devices and cloud systems.
  • Connect and synchronise all ICT system clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or servers traceable to them.
  • Enable logs of all ICT systems, maintain them securely for a rolling period of 180 days, and maintain them within India.
  • Designate a point of contact to interface with CERT-In and keep those details current.
  • Data centres, virtual private server providers, cloud service providers and VPN service providers must register and retain subscriber and customer records for five years after cancellation or withdrawal of the registration.
  • Virtual asset service providers, exchange providers and custodian wallet providers must maintain KYC and transaction records for five years.

Consequence of non-compliance

Section 70B(7) of the IT Act provides that failure to provide the information called for, or to comply with a direction under Section 70B(6), is punishable with imprisonment up to one year or a fine up to one lakh rupees, or both.

What to have ready before an incident

  • The CERT-In incident reporting form filled to the point where only the incident facts are missing.
  • A named person and an alternate who can send it within six hours, at any hour.
  • Log retention configured to 180 days with storage located in India, verified rather than assumed.
  • NTP configuration pointing at NIC or NPL.
  • A parallel note of the DPDP breach-notification duty under Section 8(6), which is a separate obligation to a different body.

Sources

  • CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, issued under Section 70B(6) of the Information Technology Act, 2000
  • The Information Technology Act, 2000 — Section 70B(6) and 70B(7)

This note is general information about published law, not legal advice on your facts. For advice, speak to our team.

Check your own site against this

The audit reads your live pages and grades them provision by provision.

Run a free audit

Read next