India CERT-In Cyber Security Directions
In force India · In force Jun 27, 2022 · no upcoming deadlines
Deadlines
| Date | What happens | When |
|---|---|---|
| Sep 25, 20224 years ago | Extended date for MSMEs and subscriber validation | 4 years ago |
| Jun 27, 20224 years ago | CERT-In Directions take effecttentative | 4.2 years ago |
Summaries for reference, not legal advice. Check the official text.
What it does
Requires service providers, intermediaries, data centres, body corporates and government bodies to report listed cyber incidents to CERT-In within 6 hours of noticing them. Entities must sync clocks to Indian NTP servers, keep ICT logs for a rolling 180 days within India, and name a point of contact. Data centre, VPS, cloud and VPN providers must keep validated subscriber details for 5 years.
- Who it applies to
- Service providers, intermediaries, data centres, body corporates and government organisations in India, with extra record duties for data centres, VPS, cloud and VPN providers, virtual asset providers and exchanges.
- Penalties
- Non-compliance can lead to punitive action under section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to INR 1 lakh, or both.
- Enforced by
- Indian Computer Emergency Response Team (CERT-In), MeitY
- Official name
- Directions under section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet
- Citation
- CERT-In Directions No. 20(3)/2022-CERT-In, 28 Apr 2022
- Topics
- cybersecurity, breach-notification, data-residency
Research notes
The Directions say they take effect 60 days after issue, and the 27 June 2022 extension notice repeats this without naming a day, so the main effective date is marked tentative. Penalty figures come from section 70B(7) of the IT Act, which the Directions cite.
Related
Questions about India CERT-In Cyber Security Directions
- What are the India CERT-In Cyber Security Directions compliance deadlines?
- Jun 27, 2022: CERT-In Directions take effect (tentative). Sep 25, 2022: Extended date for MSMEs and subscriber validation.
- When does India CERT-In Cyber Security Directions take effect?
- India CERT-In Cyber Security Directions took effect on Jun 27, 2022.
- Who does India CERT-In Cyber Security Directions apply to?
- Service providers, intermediaries, data centres, body corporates and government organisations in India, with extra record duties for data centres, VPS, cloud and VPN providers, virtual asset providers and exchanges.
- What are the penalties under India CERT-In Cyber Security Directions?
- Non-compliance can lead to punitive action under section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to INR 1 lakh, or both.