Home » AI & Digital Tools » CERT-In 6-Hour Cyber Incident Rule: Who Must Report?

CERT-In 6-Hour Cyber Incident Rule: Who Must Report?

Indian technology team managing a timed cyber-incident response beside protected server systems

Published:

· Updated:

CERT-In 6-Hour Cyber Incident Rule: Who Must Report?

Short answer: CERT-In’s cyber-security directions require specified cyber incidents to be reported within six hours of noticing the incident or being brought to notice about it. The direction applies to service providers, intermediaries, data centres, body corporates and government organisations. It is not a blanket rule requiring every individual internet user to file a CERT-In report within six hours whenever a suspicious message or ordinary account problem appears.

Author: Ajit Naskar · Draft date: 22 September 2026 · Updated: 22 September 2026 · Last verified: 22 September 2026

Compliance disclaimer: This explainer is general information, not legal advice or an incident-specific compliance opinion. Organisations should assess the current CERT-In directions, annexed incident categories, sectoral rules, contracts and facts with qualified security and legal personnel.

Table of contents

  • What the six-hour rule says
  • Who must report
  • Which incidents are covered
  • When the clock begins
  • What to send and how
  • Logs, response plan and FAQs

What changed under the CERT-In directions

On 28 April 2022, the Indian Computer Emergency Response Team issued directions under section 70B(6) of the Information Technology Act, 2000. They address information-security practices, prevention, response and reporting for a safe and trusted internet. Among the most discussed provisions is the requirement to report specified cyber incidents to CERT-In within six hours.

CERT-In later published frequently asked questions to explain the directions and issued a June 2022 extension for certain implementation timelines involving micro, small and medium enterprises and specified service providers. The official directions page continues to list the directions, FAQs and extension. Organisations should use that page, not an undated compliance blog, as the starting point.

Fact check: does every Indian have to report within six hours?

No. The six-hour direction is framed for service providers, intermediaries, data centres, body corporates and government organisations in relation to specified cyber incidents. An individual consumer who receives a phishing message, loses money or sees an unfamiliar login may need to contact a bank, platform, the National Cyber Crime Reporting Portal or police quickly, but that is not the same as saying every citizen is personally subject to the organisational CERT-In reporting direction.

This distinction is important. Overbroad claims can cause panic, while an organisation that assumes the rule is only for large technology companies can miss a real obligation. “Body corporate” can cover many companies and incorporated entities beyond the cyber-security industry. A small organisation should not assume size alone creates an exemption.

Who is covered by the CERT-In cyber incident reporting rule?

  • Service providers.
  • Intermediaries.
  • Data centres.
  • Body corporates.
  • Government organisations.

Other directions impose additional record or subscriber-information duties on particular providers, including data centres, virtual private server providers, cloud service providers, virtual private network service providers and virtual-asset businesses. Do not merge every duty into the six-hour rule; identify which clause applies to the entity and service.

A vendor contract does not automatically transfer the statutory responsibility. If a managed service provider detects an incident affecting a customer, the parties need a clear notification path so the responsible organisation can assess and report promptly. CERT-In’s FAQ states that the statutory reporting obligation overrides a contractual confidentiality clause.

Which incidents are reportable?

The directions refer to cyber incidents listed in the annexure. Organisations should review the current official list rather than rely on a shortened checklist. Categories include targeted scanning or probing of critical networks and systems; compromise of critical systems or information; unauthorised access to IT systems or data; malicious-code attacks; identity theft, spoofing and phishing; data breach or data leak; attacks on internet-of-things systems; attacks or incidents affecting digital payment systems; and other listed security events.

Not every failed login or blocked spam email necessarily becomes a reportable incident. The analysis should consider the official category, affected assets, evidence and whether an incident occurred. Conversely, waiting for perfect forensic certainty can defeat the purpose of timely reporting. CERT-In’s FAQ allows an entity to provide information available at the time and submit additional information later.

When does the six-hour clock start?

The FAQ says the cyber incident needs to be reported within six hours of noticing it or being brought to notice about it. This makes internal escalation crucial. If a help-desk analyst, vendor or branch office sees credible evidence but the information sits in a queue, the organisation may lose valuable time before the security team begins its assessment.

“Notice” should be handled through a documented incident process. Staff need a route to flag suspected breaches, and the response team needs authority to classify, contain and report. An alert that is clearly a false positive is different from a confirmed compromise, but teams should record why an alert was closed.

What information should an initial CERT-In report contain?

Use the reporting form and channels provided on CERT-In’s official site. An initial report should give the organisation’s identity and contact, incident date and detection time, affected systems or services, category, known indicators, impact, containment steps and available logs. State what is confirmed, what is suspected and what remains under investigation.

Do not delay solely because every field is incomplete. CERT-In’s FAQ explains that whatever information is available may be provided within six hours, followed by additional information in a reasonable time. Preserve accuracy: do not present an estimate as a confirmed count or hide material uncertainty.

Six-hour incident response workflow

  1. Validate the alert. Confirm the source, affected asset and whether evidence indicates a cyber incident.
  2. Activate the response team. Notify security, technology, legal, privacy, leadership and communications roles appropriate to the incident.
  3. Protect evidence. Preserve relevant logs, disk or cloud evidence and timestamps before routine rotation destroys them.
  4. Contain safely. Isolate affected accounts, endpoints or services without erasing evidence.
  5. Classify against the official annexure. Document the category and reasoning.
  6. Prepare the initial report. Send confirmed facts and clearly labelled preliminary information through CERT-In’s official channel.
  7. Continue investigation. Determine scope, root cause, affected data and recovery actions.
  8. Submit follow-up information. Update CERT-In and other authorities or affected parties where legally required.
  9. Record decisions. Keep a chronology of detection, escalation, containment, reporting and restoration.

What does not change because of the CERT-In report?

Reporting does not replace containment, customer protection, law-enforcement contact, sector-regulator reporting, contractual notices or privacy obligations that may apply. A report is not proof that the organisation caused the incident, and it does not make every technical detail public. It also does not permit a team to destroy evidence once a summary has been emailed.

The direction does not guarantee that a company can wait six hours before taking action. A compromised account may need immediate disabling; a payment incident may require immediate bank contact. Six hours is a reporting deadline for covered incidents, not a safe waiting period.

Log retention and clock synchronisation

The directions also require covered entities to enable logs of ICT systems and retain them securely for a rolling period of 180 days within Indian jurisdiction. They require connection to specified Network Time Protocol sources or other traceable, accurate time sources. These provisions help investigators correlate events across systems.

Log retention should be designed before an incident. Identify critical cloud, identity, endpoint, network, application and database logs; protect them from alteration; restrict access; monitor collection failures; and test retrieval. A policy saying “retain logs” is insufficient if storage overwrites them after seven days or timestamps use inconsistent time zones.

Example: ransomware at a small software company

At 10:00 a.m., a 70-person software company confirms that ransomware encrypted a production file server and that an attacker used a compromised administrator account. The incident-response lead records the detection time, isolates the server, preserves identity and network logs, checks the annexure and prepares an initial CERT-In report before 4:00 p.m. The report states the systems known to be affected, preliminary indicators, containment steps and the fact that data-exfiltration analysis is continuing. Follow-up information is sent when the investigation establishes the scope.

The company does not wait for a final forensic report, and it does not claim that no data left the network without evidence. It also evaluates contractual, sectoral, privacy and customer-notification duties separately.

Individuals: what should you do after a cyber incident?

If you are an individual victim, act through the channel that matches the harm. Contact the bank or payment provider immediately for unauthorised transactions, secure compromised accounts, preserve messages and transaction references, and use the National Cyber Crime Reporting Portal or helpline where appropriate. For a threatening video-call scam, our digital arrest scam fact check explains why callers cannot lawfully arrest someone through a video call.

Do not email sensitive identity files to addresses copied from an unknown blog. CERT-In’s official site publishes its incident-response contact information, but a consumer fraud complaint and an organisational statutory incident report are not interchangeable.

Small-business readiness checklist

  • Name an incident-response owner and alternate.
  • Keep the official CERT-In directions and incident annexure accessible.
  • Define what “noticed” means in the escalation workflow.
  • Require vendors to notify the organisation rapidly.
  • Maintain an initial-report template without real secrets.
  • Synchronise system clocks and test 180-day log retention.
  • Record regulator, law-enforcement, insurer and customer notice paths.
  • Run a timed tabletop exercise.

Cyber compliance is one piece of India’s digital-policy landscape. Our IndiaAI Mission explainer covers a separate government programme for compute, innovation, skills and safe AI; it should not be confused with CERT-In’s binding cyber-security directions.

Frequently asked questions

Is the deadline six hours from when the attack began?

The official FAQ frames it as six hours from noticing the incident or being brought to notice about it, not necessarily from the attacker’s first action.

Can we wait for the forensic report?

No, not if that would miss the reporting deadline. Provide available information and follow with additional findings.

Does a confidentiality agreement stop reporting?

CERT-In’s FAQ says the statutory reporting obligation overrides a contractual confidentiality clause.

Does every phishing email require a report?

Assess the event against the official reportable-incident categories and facts. An organisation should document its classification; an individual receiving spam is not automatically subject to the organisational direction.

Are MSMEs exempt?

Do not assume so. A 2022 order extended certain implementation timelines, but it did not create a permanent blanket exemption from cyber-incident reporting for every MSME.

Where is the official incident email?

CERT-In’s current guidance and advisories list incident-response contacts, including incident@cert-in.org.in. Verify the live official site before sending sensitive incident data.

Action checklist

  1. Open the current CERT-In directions and annexure.
  2. Identify whether the entity is covered.
  3. Record when the incident was noticed.
  4. Preserve evidence and contain immediate harm.
  5. Classify the incident using the official list.
  6. Report available facts within six hours when required.
  7. Send follow-ups as facts develop.
  8. Review logs, contracts and escalation gaps after recovery.

Conclusion

The CERT-In six hour cyber incident reporting rule is a targeted organisational duty, not a universal command for every internet user. Covered entities should build detection, escalation, evidence preservation and reporting into one tested workflow so an incomplete investigation does not become an excuse for late reporting.

Official sources: CERT-In directions under section 70B; Cyber Security Directions dated 28 April 2022; CERT-In frequently asked questions.

Verification metadata: _cm_verified_source_url: https://www.cert-in.org.in/Directions70B.jsp · _cm_source_authority: Indian Computer Emergency Response Team, MeitY · _cm_effective_date: 2022-06-27

Correction history: 22 September 2026 — first draft.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *