Free 30-minute scoping call, no obligation

Vyapari Solutions
Get a free quote

+91 78380 40655 · vyaparisolutions01@gmail.com

CERT-In Directions · 70B

CERT-In Security Audit & Cyber Security Directions Compliance

CERT-In’s Directions under Section 70B(6) of the IT Act carry criminal liability for non-compliance, not just a fine. Vyapari Solutions builds the logging, reporting and audit evidence that stands up to a government submission.

4.9/5 average client rating · 1200+ engagements delivered

1200+Audits delivered
96%Pass first time
8–14 wksTypical timeline
Fixed feeQuoted up front
Overview

What the CERT-In Directions require

The Indian Computer Emergency Response Team is the national nodal agency for cyber incidents. Its 2022 Directions moved incident reporting from good practice to a legal obligation with a very short clock, and added retention, synchronisation and KYC duties that touch infrastructure design.

A CERT-In security audit report — produced against the Directions and, where required, by an empanelled auditor — is routinely demanded for government tenders, banking approvals, payment aggregator authorisation, listing requirements and application go-live sign-offs.

  • Report any of the 20+ listed incident types to CERT-In within 6 hours of noticing them
  • Maintain ICT logs for 180 days within India and produce them on demand
  • Synchronise all system clocks to NIC/NPL NTP servers or a traceable equivalent
  • Designate a point of contact and keep the details current with CERT-In
  • VPN, cloud and data centre providers: retain subscriber KYC and allocation records for five years
  • Virtual asset service providers: maintain KYC and transaction records for five years

Key facts

Key facts
Legal basisSection 70B(6), Information Technology Act 2000; CERT-In Directions of 28 April 2022
Incident reportingWithin 6 hours of noticing or being notified of a reportable cyber incident
Log retentionICT system logs maintained securely for a rolling 180 days, within Indian jurisdiction
Time syncAll ICT systems synchronised to NIC or NPL NTP servers
Applies toService providers, intermediaries, data centres, body corporate, VPN and cloud providers, VASPs
Request a fixed-fee quote
Scope of work

What a CERT-In engagement covers

We combine technical audit with the operational readiness that the six-hour clock actually demands.

Directions gap assessment

Clause-by-clause assessment of reporting, retention, NTP, KYC and point-of-contact obligations.

Application & infrastructure audit

Full VAPT of in-scope applications and infrastructure with reporting in the format expected for submissions.

Log architecture

Design and validation of centralised, tamper-evident logging with 180-day retention inside Indian jurisdiction.

Incident response readiness

Detection, triage, severity classification and a pre-approved CERT-In reporting pack that can be filed within six hours.

Tabletop exercise

A simulated incident that tests whether your team can genuinely meet the six-hour clock, end to end.

Audit report & closure

Findings remediated and retested, with the audit report and compliance certificate your filing requires.

Applicability

Who must comply

The Directions apply broadly to any service provider, intermediary, data centre, body corporate or government organisation operating ICT infrastructure in India — and to entities offering services to Indian users from outside India.

  • Banks, NBFCs, insurers and payment system operators filing system audit reports
  • Government departments, PSUs and their application vendors before go-live
  • Data centres, cloud service providers, VPS and VPN providers
  • Intermediaries and platforms under the IT Rules
  • Virtual asset service providers, exchanges and custodian wallet providers

Legal exposure closed

Non-compliance with the Directions can attract penal consequences under Section 70B(7). We close the obligations that carry real liability first.

Six hours becomes achievable

Pre-drafted templates, defined severity criteria and a named on-call owner turn a panic into a procedure.

Submission-ready reporting

Reports formatted the way regulators, banks and tender authorities expect to receive them.

Logging that survives scrutiny

Tamper-evident, time-synchronised, India-resident log architecture that can actually answer a forensic request.

Our approach

How the engagement runs

  • Applicability mapping

    We establish which categories you fall into and therefore which Directions and retention duties apply.

  • Technical audit

    VAPT across in-scope applications, APIs and infrastructure, plus configuration and log architecture review.

  • Operational readiness

    Incident classification matrix, six-hour reporting workflow, escalation tree and CERT-In point of contact registration.

  • Remediation & retest

    Findings closed with your teams and independently retested to a clean state.

  • Report & ongoing support

    Audit report issued, plus retainer support for actual incident reporting when something happens.

Deliverables

What you receive

  • CERT-In Directions applicability and gap assessment report
  • Security audit report in submission-ready format with remediation evidence
  • Log retention and NTP synchronisation architecture note
  • Incident classification matrix and 6-hour reporting SOP with templates
  • Tabletop exercise report and improvement actions
  • Point-of-contact registration support and compliance calendar
  • Post-remediation retest report and audit closure certificate
Questions

CERT-In — frequently asked questions

The Directions list over twenty incident types including targeted scanning, unauthorised access, website defacement, malware and ransomware, identity theft, data breach or leak, attacks on servers and network devices, IoT and critical systems, and incidents affecting digital payment systems. The clock starts when you notice the incident or are notified of it.

The Directions require logs to be maintained within Indian jurisdiction. In practice that means your primary log store must be in an Indian region; replication elsewhere is possible but the authoritative, producible copy needs to be resident in India for the full 180 days.

For many government tenders, banking submissions and regulatory filings, yes — the recipient specifically asks for a report from a CERT-In empanelled organisation. Vyapari Solutions delivers audits using empanelled methodology and coordinates empanelled sign-off where your submission requires it.

They overlap heavily. RBI cyber security framework, SEBI CSCRF and IRDAI guidelines all reference incident reporting, log retention and VAPT. We run one technical audit and map the output to each regulator’s reporting format rather than repeating the work.

Yes. The Directions expressly extend to entities providing services to users in India, and require a point of contact for CERT-In communications. Many overseas SaaS providers meet this through an Indian entity or a designated representative.

Yes. Retainer clients get an on-call escalation line: we help classify the incident, draft the CERT-In submission, and support forensic preservation so the six-hour deadline is met without compromising the investigation.

Still not sure what applies to you?

Ask an assessor directly — we answer scoping questions before anyone talks about a fee.

Talk to an assessor

Get a realistic timeline and a fixed fee

A 30-minute call is usually enough to scope CERT-In accurately. You will leave with a timeline, an evidence checklist and a number — whether or not you engage us.

Reply within one business day NDA before any detail is shared No obligation, no proposal theatre