CERT-In Security Audit & Cyber Security Directions Compliance
CERT-In’s Directions under Section 70B(6) of the IT Act carry criminal liability for non-compliance, not just a fine. Vyapari Solutions builds the logging, reporting and audit evidence that stands up to a government submission.
4.9/5 average client rating · 1200+ engagements delivered
What the CERT-In Directions require
The Indian Computer Emergency Response Team is the national nodal agency for cyber incidents. Its 2022 Directions moved incident reporting from good practice to a legal obligation with a very short clock, and added retention, synchronisation and KYC duties that touch infrastructure design.
A CERT-In security audit report — produced against the Directions and, where required, by an empanelled auditor — is routinely demanded for government tenders, banking approvals, payment aggregator authorisation, listing requirements and application go-live sign-offs.
- Report any of the 20+ listed incident types to CERT-In within 6 hours of noticing them
- Maintain ICT logs for 180 days within India and produce them on demand
- Synchronise all system clocks to NIC/NPL NTP servers or a traceable equivalent
- Designate a point of contact and keep the details current with CERT-In
- VPN, cloud and data centre providers: retain subscriber KYC and allocation records for five years
- Virtual asset service providers: maintain KYC and transaction records for five years
Key facts
| Legal basis | Section 70B(6), Information Technology Act 2000; CERT-In Directions of 28 April 2022 |
|---|---|
| Incident reporting | Within 6 hours of noticing or being notified of a reportable cyber incident |
| Log retention | ICT system logs maintained securely for a rolling 180 days, within Indian jurisdiction |
| Time sync | All ICT systems synchronised to NIC or NPL NTP servers |
| Applies to | Service providers, intermediaries, data centres, body corporate, VPN and cloud providers, VASPs |
What a CERT-In engagement covers
We combine technical audit with the operational readiness that the six-hour clock actually demands.
Directions gap assessment
Clause-by-clause assessment of reporting, retention, NTP, KYC and point-of-contact obligations.
Application & infrastructure audit
Full VAPT of in-scope applications and infrastructure with reporting in the format expected for submissions.
Log architecture
Design and validation of centralised, tamper-evident logging with 180-day retention inside Indian jurisdiction.
Incident response readiness
Detection, triage, severity classification and a pre-approved CERT-In reporting pack that can be filed within six hours.
Tabletop exercise
A simulated incident that tests whether your team can genuinely meet the six-hour clock, end to end.
Audit report & closure
Findings remediated and retested, with the audit report and compliance certificate your filing requires.
Who must comply
The Directions apply broadly to any service provider, intermediary, data centre, body corporate or government organisation operating ICT infrastructure in India — and to entities offering services to Indian users from outside India.
- Banks, NBFCs, insurers and payment system operators filing system audit reports
- Government departments, PSUs and their application vendors before go-live
- Data centres, cloud service providers, VPS and VPN providers
- Intermediaries and platforms under the IT Rules
- Virtual asset service providers, exchanges and custodian wallet providers
Legal exposure closed
Non-compliance with the Directions can attract penal consequences under Section 70B(7). We close the obligations that carry real liability first.
Six hours becomes achievable
Pre-drafted templates, defined severity criteria and a named on-call owner turn a panic into a procedure.
Submission-ready reporting
Reports formatted the way regulators, banks and tender authorities expect to receive them.
Logging that survives scrutiny
Tamper-evident, time-synchronised, India-resident log architecture that can actually answer a forensic request.
How the engagement runs
Applicability mapping
We establish which categories you fall into and therefore which Directions and retention duties apply.
Technical audit
VAPT across in-scope applications, APIs and infrastructure, plus configuration and log architecture review.
Operational readiness
Incident classification matrix, six-hour reporting workflow, escalation tree and CERT-In point of contact registration.
Remediation & retest
Findings closed with your teams and independently retested to a clean state.
Report & ongoing support
Audit report issued, plus retainer support for actual incident reporting when something happens.
What you receive
- CERT-In Directions applicability and gap assessment report
- Security audit report in submission-ready format with remediation evidence
- Log retention and NTP synchronisation architecture note
- Incident classification matrix and 6-hour reporting SOP with templates
- Tabletop exercise report and improvement actions
- Point-of-contact registration support and compliance calendar
- Post-remediation retest report and audit closure certificate
CERT-In — frequently asked questions
The Directions list over twenty incident types including targeted scanning, unauthorised access, website defacement, malware and ransomware, identity theft, data breach or leak, attacks on servers and network devices, IoT and critical systems, and incidents affecting digital payment systems. The clock starts when you notice the incident or are notified of it.
The Directions require logs to be maintained within Indian jurisdiction. In practice that means your primary log store must be in an Indian region; replication elsewhere is possible but the authoritative, producible copy needs to be resident in India for the full 180 days.
For many government tenders, banking submissions and regulatory filings, yes — the recipient specifically asks for a report from a CERT-In empanelled organisation. Vyapari Solutions delivers audits using empanelled methodology and coordinates empanelled sign-off where your submission requires it.
They overlap heavily. RBI cyber security framework, SEBI CSCRF and IRDAI guidelines all reference incident reporting, log retention and VAPT. We run one technical audit and map the output to each regulator’s reporting format rather than repeating the work.
Yes. The Directions expressly extend to entities providing services to users in India, and require a point of contact for CERT-In communications. Many overseas SaaS providers meet this through an Indian entity or a designated representative.
Yes. Retainer clients get an on-call escalation line: we help classify the incident, draft the CERT-In submission, and support forensic preservation so the six-hour deadline is met without compromising the investigation.
Still not sure what applies to you?
Ask an assessor directly — we answer scoping questions before anyone talks about a fee.
Get a realistic timeline and a fixed fee
A 30-minute call is usually enough to scope CERT-In accurately. You will leave with a timeline, an evidence checklist and a number — whether or not you engage us.