DPDP Rules status: compliance window active. Read the update

Skip to content
Platforms & Internet · CERT-In

The 6-hour clock most teams find out about too late.

CERT-In's April 2022 orders are binding. They apply to firms of every size. Their deadline is very short. They sit alongside DPDP rather than inside it — a single incident can start both clocks at once.

Educational only · not legal adviceLast updated: 5 October 2026Reviewed by Sandesh Kokate, Editor
These are directions, not guidelines

Much of this site covers advice. The AI Guidelines carry no penalties. Most DPDP duties start only on 13 May 2027. The CERT-In directions are the opposite case. They were issued under Section 70B(6) of the IT Act, they took effect in 2022, and non-compliance is an offence under Section 70B(7) today.

What the directions require

Six duties, in the order they tend to matter operationally.

  • Direction (ii)

    Report cyber incidents within 6 hours

    Reportable incidents must be notified to CERT-In within six hours of noticing them or being told about them. You can report by email to incident@cert-in.org.in, by phone on 1800-11-4949, or by fax on 1800-11-6969.

  • Direction (iv)

    Keep ICT system logs for 180 days, inside India

    Turn on logs. Keep them safe for 180 days, inside India. They must be produced to CERT-In when ordered in connection with an incident. Keeping logs only abroad is not enough.

  • Direction (i)

    Synchronise system clocks

    Set your system clocks by the time servers of NIC or NPL, or servers linked to them. Firms with systems in many countries may use other exact time sources. Their time must match those servers.

  • Direction (v)

    Registration duties for cloud, VPS and VPN providers

    Data centres, virtual private server providers, cloud service providers and VPN service providers must keep customer records. These include validated names, the period of hire, IP addresses, the email and IP used to sign up, the purpose of hiring, and the ownership pattern.

  • Direction (vi)

    KYC records for virtual asset service providers

    Crypto exchanges and wallet firms must keep all customer ID (KYC) records and financial transaction records for five years.

  • Direction (iii)

    Name a point of contact

    Entities must designate a point of contact to interface with CERT-In and keep those details current. CERT-In writes to that contact. If it is out of date, you may miss an urgent message.

Source
CERT-In — Directions under s.70B(6) of the IT Act, No. 20(3)/2022-CERT-In (28 April 2022)

opened CERT-In Directions; penalty from IT Act Section 70B(7), India Code copy

Two clocks, one incident

Reporting a cyber attack and reporting a data leak are two separate duties. You report cyber attacks to CERT-In under the IT Act. You report data leaks to the people hit and to the Data Protection Board (Section 8(6), Rule 7).

A ransomware event at an Indian startup can trigger both. The CERT-In clock is running today. The DPDP clock becomes enforceable on 13 May 2027. An incident-response runbook that only accounts for one of them will miss the other.

In plain English: build your response plan around the six-hour clock. It is law today, and it is the shorter one.

Related

Frequently asked questions

Quick self-check

DPDP readiness checklist

Incident response is one line item. Check what else you need in place before the May 2027 deadline.

Run it now
Last updated: 5 October 2026 · Reviewed by Sandesh Kokate, Editor

Educational only — not legal advice. Read the Directions and Section 70B yourself before you rely on this page.