In April 2022, CERT-In issued directions under Section 70B(6) of the IT Act, 2000, setting mandatory practices for incident reporting, log retention, and record-keeping.
They apply broadly — service providers, intermediaries, data centres, body corporates, and government bodies in India — and are among the most prescriptive incident-response rules anywhere.
The six-hour reporting rule
Entities must report specified incidents to CERT-In within six hours of noticing them or being made aware. The clock runs from awareness, not from confirmed impact — far tighter than the 72-hour windows common elsewhere.
Six hours is an organisational commitment, not a legal footnote — your escalation path must file a report the same working hours a reportable event is found.
- The clock starts on notice — not when investigation concludes.
- Reportable types include scanning, unauthorised access, intrusions, and data breaches.
- File by email, phone, or the CERT-In portal in the specified format.
The fix is organisational: an on-call path, a pre-drafted template, and clear authority to file without a long sign-off chain. Many teams rehearse this with tabletop exercises.
The 180-day log retention mandate
Entities must enable and securely maintain ICT system logs, retained for a rolling 180 days within Indian jurisdiction, and produce them to CERT-In when directed.
That implies you know which systems generate security-relevant logs, that they are captured, and that they are stored durably and searchably for six months.
- Retain system logs for a rolling 180 days, maintained within India.
- Keep logs tamper-evident and access-controlled for investigation integrity.
- Favour centralised, indexed storage so logs are produced quickly on direction.
Clock sync and record-keeping
Synchronise ICT clocks to NIC or National Physical Laboratory NTP servers, or servers traceable to them. Consistent timestamps are essential to correlate events during forensics.
Data centres, VPS, cloud, and VPN providers must also keep customer registration records, and certain crypto entities have KYC and transaction-record duties.
What compliance looks like
This is about wiring detection, logging, and response together — not one tool. A SIEM gives retention and search, a managed SOC gives awareness for the six-hour clock, and runbooks give the authority to report.
Takeaway: confirm logs are centralised, retained 180 days within India, and time-synchronised — then rehearse your reporting path so a real incident is not your first attempt.