Don’t do SECURITY. Do business SECURELY.

India’s CERT-In issues cyber security directions

India’s CERT-In issues directions requiring cyber incidents to be reported within six hours and logs to be kept for 180 days.

India’s Computer Emergency Response Team (CERT-In) has issued Directions under section 70B(6) of the Information Technology Act 2000, setting new cyber security obligations for service providers, intermediaries, data centres and other organisations.

Key points

  • Specified cyber incidents must be reported to CERT-In within six hours of being noticed.
  • ICT system logs must be kept securely for 180 days, within India.
  • Clocks must be synchronised with Indian government NTP servers.
  • VPN, cloud and data centre providers must keep subscriber records for five years.
  • The Directions take effect 60 days after issue.

The Directions apply to organisations with systems or customers in India, alongside existing interception and decryption powers under section 69. UK organisations with Indian operations or suppliers should update incident response and logging arrangements.

Source: CERT-In Directions under section 70B(6), 28 April 2022 (CERT-In)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights