Skip to content

India CERT-In Cyber Security Directions

In force India · In force Jun 27, 2022 · no upcoming deadlines

Deadlines

DateWhat happens
Sep 25, 20224 years agoExtended date for MSMEs and subscriber validation
Jun 27, 20224 years agoCERT-In Directions take effecttentative

Summaries for reference, not legal advice. Check the official text.

What it does

Requires service providers, intermediaries, data centres, body corporates and government bodies to report listed cyber incidents to CERT-In within 6 hours of noticing them. Entities must sync clocks to Indian NTP servers, keep ICT logs for a rolling 180 days within India, and name a point of contact. Data centre, VPS, cloud and VPN providers must keep validated subscriber details for 5 years.

Who it applies to
Service providers, intermediaries, data centres, body corporates and government organisations in India, with extra record duties for data centres, VPS, cloud and VPN providers, virtual asset providers and exchanges.
Penalties
Non-compliance can lead to punitive action under section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to INR 1 lakh, or both.
Enforced by
Indian Computer Emergency Response Team (CERT-In), MeitY
Official name
Directions under section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet
Citation
CERT-In Directions No. 20(3)/2022-CERT-In, 28 Apr 2022
Topics
cybersecurity, breach-notification, data-residency
Verified 2026-09-25 cert-in.org.in cert-in.org.in cert-in.org.in
Research notes

The Directions say they take effect 60 days after issue, and the 27 June 2022 extension notice repeats this without naming a day, so the main effective date is marked tentative. Penalty figures come from section 70B(7) of the IT Act, which the Directions cite.

Related

Questions about India CERT-In Cyber Security Directions
What are the India CERT-In Cyber Security Directions compliance deadlines?
Jun 27, 2022: CERT-In Directions take effect (tentative). Sep 25, 2022: Extended date for MSMEs and subscriber validation.
When does India CERT-In Cyber Security Directions take effect?
India CERT-In Cyber Security Directions took effect on Jun 27, 2022.
Who does India CERT-In Cyber Security Directions apply to?
Service providers, intermediaries, data centres, body corporates and government organisations in India, with extra record duties for data centres, VPS, cloud and VPN providers, virtual asset providers and exchanges.
What are the penalties under India CERT-In Cyber Security Directions?
Non-compliance can lead to punitive action under section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to INR 1 lakh, or both.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.