The CERT-In Directions: 6-Hour Breach Reporting and 180-Day Log Retention Explained
All Insights Security

The CERT-In Directions: 6-Hour Breach Reporting and 180-Day Log Retention Explained

CoSol Team 2 April 2026 7 min read

CERT-In’s 2022 cyber security directions impose some of the tightest incident-reporting timelines in the world. Here is what the six-hour rule and the log-retention mandate actually require.

In April 2022, CERT-In issued directions under Section 70B(6) of the IT Act, 2000, setting mandatory practices for incident reporting, log retention, and record-keeping.

They apply broadly — service providers, intermediaries, data centres, body corporates, and government bodies in India — and are among the most prescriptive incident-response rules anywhere.

6 hrs
to report an incident
180 days
rolling log retention
India
jurisdiction for logs

The six-hour reporting rule

Entities must report specified incidents to CERT-In within six hours of noticing them or being made aware. The clock runs from awareness, not from confirmed impact — far tighter than the 72-hour windows common elsewhere.

Six hours is an organisational commitment, not a legal footnote — your escalation path must file a report the same working hours a reportable event is found.

CERT-In obligations
1
Detect
Incident identified
2
Report ≤ 6 hrs
To CERT-In
3
Retain 180 days
Logs, secured
From detection to filing: the six-hour window runs from awareness, not investigation.
  • The clock starts on notice — not when investigation concludes.
  • Reportable types include scanning, unauthorised access, intrusions, and data breaches.
  • File by email, phone, or the CERT-In portal in the specified format.

The fix is organisational: an on-call path, a pre-drafted template, and clear authority to file without a long sign-off chain. Many teams rehearse this with tabletop exercises.

The 180-day log retention mandate

Entities must enable and securely maintain ICT system logs, retained for a rolling 180 days within Indian jurisdiction, and produce them to CERT-In when directed.

That implies you know which systems generate security-relevant logs, that they are captured, and that they are stored durably and searchably for six months.

Rows of servers in a data centre
Centralised, indexed log storage makes the 180-day mandate practical and India-resident.
  • Retain system logs for a rolling 180 days, maintained within India.
  • Keep logs tamper-evident and access-controlled for investigation integrity.
  • Favour centralised, indexed storage so logs are produced quickly on direction.

Clock sync and record-keeping

Synchronise ICT clocks to NIC or National Physical Laboratory NTP servers, or servers traceable to them. Consistent timestamps are essential to correlate events during forensics.

Data centres, VPS, cloud, and VPN providers must also keep customer registration records, and certain crypto entities have KYC and transaction-record duties.

What compliance looks like

This is about wiring detection, logging, and response together — not one tool. A SIEM gives retention and search, a managed SOC gives awareness for the six-hour clock, and runbooks give the authority to report.

Takeaway: confirm logs are centralised, retained 180 days within India, and time-synchronised — then rehearse your reporting path so a real incident is not your first attempt.

Run your operations with CoSol

Compliance, networking and security — managed 24×7, delivered in India.