The 6-hour clock most teams find out about too late.
CERT-In's April 2022 orders are binding. They apply to firms of every size. Their deadline is very short. They sit alongside DPDP rather than inside it — a single incident can start both clocks at once.
Much of this site covers advice. The AI Guidelines carry no penalties. Most DPDP duties start only on 13 May 2027. The CERT-In directions are the opposite case. They were issued under Section 70B(6) of the IT Act, they took effect in 2022, and non-compliance is an offence under Section 70B(7) today.
What the directions require
Six duties, in the order they tend to matter operationally.
- Direction (ii)
Report cyber incidents within 6 hours
Reportable incidents must be notified to CERT-In within six hours of noticing them or being told about them. You can report by email to incident@cert-in.org.in, by phone on 1800-11-4949, or by fax on 1800-11-6969.
- Direction (iv)
Keep ICT system logs for 180 days, inside India
Turn on logs. Keep them safe for 180 days, inside India. They must be produced to CERT-In when ordered in connection with an incident. Keeping logs only abroad is not enough.
- Direction (i)
Synchronise system clocks
Set your system clocks by the time servers of NIC or NPL, or servers linked to them. Firms with systems in many countries may use other exact time sources. Their time must match those servers.
- Direction (v)
Registration duties for cloud, VPS and VPN providers
Data centres, virtual private server providers, cloud service providers and VPN service providers must keep customer records. These include validated names, the period of hire, IP addresses, the email and IP used to sign up, the purpose of hiring, and the ownership pattern.
- Direction (vi)
KYC records for virtual asset service providers
Crypto exchanges and wallet firms must keep all customer ID (KYC) records and financial transaction records for five years.
- Direction (iii)
Name a point of contact
Entities must designate a point of contact to interface with CERT-In and keep those details current. CERT-In writes to that contact. If it is out of date, you may miss an urgent message.
opened CERT-In Directions; penalty from IT Act Section 70B(7), India Code copy
Two clocks, one incident
Reporting a cyber attack and reporting a data leak are two separate duties. You report cyber attacks to CERT-In under the IT Act. You report data leaks to the people hit and to the Data Protection Board (Section 8(6), Rule 7).
A ransomware event at an Indian startup can trigger both. The CERT-In clock is running today. The DPDP clock becomes enforceable on 13 May 2027. An incident-response runbook that only accounts for one of them will miss the other.
In plain English: build your response plan around the six-hour clock. It is law today, and it is the shorter one.
Related
Frequently asked questions
DPDP readiness checklist
Incident response is one line item. Check what else you need in place before the May 2027 deadline.
Run it nowEducational only — not legal advice. Read the Directions and Section 70B yourself before you rely on this page.