Compliance Guide

CERT-In 6-Hour Incident Reporting — How to Comply, Step by Step

CERT-In's Direction No. 20(3)/2022-CERT-In, in force since 28 June 2022, requires covered entities to report specified cyber incidents within 6 hours of becoming aware of them, keep ICT system clocks synchronised to Indian time servers, retain logs for a rolling 180 days within India, and respond to CERT-In information requests within 6 hours. It applies broadly — service providers, intermediaries, data centres and body corporates — and the penalty for most organisations isn't a fine so much as scrambling to build the reporting pipeline for the first time during an actual incident. Here is how to have it ready before that happens.

Steps

Frequently Asked Questions

What happens if we miss the 6-hour reporting window?

CERT-In's Direction gives it authority to call for information and take action against non-compliant entities; the practical risk for most Indian organisations is regulatory and reputational exposure alongside the fact that a delayed report usually means a delayed and less effective response to the incident itself. The 6-hour requirement exists because speed genuinely limits breach impact — treating it as a compliance checkbox rather than an operational capability misses the point.

Does this apply to small businesses, or only large enterprises?

The Direction's language covers "service providers, intermediaries, data centres, body corporates and Government organisations" broadly, without an explicit small-business carve-out — if you operate any of the systems in the reportable categories (a website, a mail server, a database of customer data), the obligation applies regardless of company size. In practice, enforcement focus and audit scrutiny concentrate on larger and regulated entities, but the underlying reporting obligation is not scoped to enterprise size.

What exactly counts as "becoming aware" of an incident?

CERT-In has not published a rigid technical definition, which is why organisations need to define it internally and document that definition — most compliance guidance treats it as the point a confirmed, credible indicator reaches someone with authority to act, not the first raw alert or rumour. Defining this clearly in advance is what prevents the 6-hour clock becoming a dispute during an actual incident.

Do we need a SIEM specifically, or can we comply without one?

The Direction does not name any specific product, but the 180-day retention and rapid-detection requirements are difficult to meet reliably at any real scale without centralised log management and correlation — which is functionally what a SIEM does. Very small environments with few systems can sometimes meet the letter of the requirement manually; anything beyond that scale typically needs the tooling to make the obligation practically achievable rather than theoretically true.

Talk to us about mapping CERT-In compliance to a SIEM deployment — WhatsApp +91 98119 98370 for a compliance + tooling assessment.