Scroll to top

CERT-In Compliance

  • Home
  • CERT-In Compliance

"6 hours to report. 180 days in India. Criminal liability for non-compliance."

CERT-In Compliance Incident Reporting

The 6-hour CERT-In reporting window starts at first detection β€” not when you finish your incident assessment. Automated detection and pre-approved templates are essential.

CERT-In Directive 2022 β€” Automated Compliance Before the 6-Hour Clock Starts

The CERT-In directive (April 2022) requires: reporting 20 categories of cyber incidents within 6 hours of detection; maintaining ICT system logs for 180 days within Indian jurisdiction; synchronizing all system clocks with NTP servers traceable to India's NPL; and maintaining verifiable user identities across all ICT systems. Non-compliance is a criminal offence under Section 70B(7) of the IT Act 2000 β€” punishable by up to one year imprisonment. VinfraSec implements all four requirements as automated, IaC-enforced controls.

Key Capabilities

20-Category Incident Detection & CERT-In Reporting

SIEM-based automated detection for all 20 CERT-In incident categories β€” ransomware, data breaches, unauthorized access, DoS, SCADA attacks, and more β€” with pre-approved reporting templates ready before an incident occurs.

180-Day Log Retention in India (Immutable WORM)

Centralized log aggregation with Azure Log Analytics (Central India / South India) or AWS CloudWatch + S3 Object Lock (Mumbai). Immutable retention enforced by IaC policy β€” logs cannot be deleted or modified before the 180-day period expires.

NTP Synchronization with NIC Servers

All servers, VMs, containers, network devices, and workstations synchronized with NIC's NTP servers (time.nic.in) via Terraform and Ansible. Drift alerts notify when any device falls out of sync β€” protecting log correlation integrity.

ICT Audit Trail Engineering

Complete audit logging for all privileged actions, authentication events, API calls, and data access β€” timestamped, tamper-evident, and searchable. Evidence packages ready for CERT-In in hours, not days.

Verifiable System Identity

Every user, system, and service has a traceable identity β€” IAM roles, managed identities, certificate-based authentication. No anonymous accounts. VPN users are logged with their real identity even through NAT.

6-Hour Data Response Capability

Pre-authorized CERT-In data response procedures with designated responders, evidence collection runbooks, and escalation protocols β€” so your organization can respond to CERT-In data requests within the required 6-hour window.

Why the 6-Hour Clock Cannot Be Managed Manually

The 6-hour CERT-In reporting window starts at the moment of first detection β€” not when you finish your incident assessment. VinfraSec implements SIEM-based automated detection with pre-approved reporting templates, so the 6-hour clock is met even at 3am during a ransomware incident.

Non-compliance is a criminal offence under Section 70B(7) of the IT Act 2000 β€” with imprisonment up to one year for responsible officers. The more significant business risk is reputational damage and prolonged regulatory scrutiny from a CERT-In investigation.

Book Free CERT-In Gap Assessment

Ready to Automate Your CERT-In Compliance?

We'll assess your incident reporting capability, log retention architecture, NTP configuration, and ICT audit trail against CERT-In directive requirements and deliver a prioritized gap report β€” at no charge.