Law / India

CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation

Directions under section 70B(6) of the Information Technology Act 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 27 June 2022.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds a service provider, intermediary, data centre, body corporate, or Government organisation, the Information Technology Act's own general terms for essentially any commercial or professional actor operating a computer resource in India, not a licensed or sector-specific status; a company distributing software or operating a mobile app in India falls within this reach without needing a specific regulatory registration.
  • Connect all your ICT systems' clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to an NTP server traceable to one of them, and ensure any other time source you use does not deviate from NPL or NIC.
  • Report a listed cyber security incident, including a targeted attack, a data breach, a data leak, unauthorised access to your IT systems, or an attack through a malicious or fake mobile app, to CERT-In within six hours of noticing it or being notified of it, by email, phone, or fax; current reporting formats and channels are published on CERT-In's own website.
  • Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.
  • Designate a Point of Contact to interface with CERT-In, using the format CERT-In publishes, and keep that designation current.
  • If your own service is itself a data centre, a virtual private server provider, a cloud service provider, a virtual private network service, or a virtual asset (crypto) service provider, a narrower and heavier duty also applies: register and retain specified customer KYC information and financial-transaction records for five years. That narrower bound-party class is not one this profile's declared activities can identify on their own, so confirm applicability directly against the text if this describes your service.
  • Failing to furnish information CERT-In calls for, or to comply with a direction it issues, including these Directions, is punishable under section 70B(7) of the Information Technology Act with imprisonment for up to one year, a fine of up to one lakh rupees, or both.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Imprisonment for a term which may extend to one year, or a fine which may extend to one lakh rupees, or both, under Information Technology Act section 70B(7), for failing to provide information called for, or to comply with a direction issued, under section 70B(6), which includes these Directions.

Penalty structure

Section 70B(7)'s fine cap of one lakh rupees; the same provision separately authorises imprisonment for up to one year, either alone or in addition to the fine. The Directions themselves state only that non-compliance 'may invite punitive action under sub-section (7) of the section 70B', without restating the figures; the amounts are stated in section 70B(7) itself.

Rule
Fixed only
As of
12 September 2026
Currency
INR
Fixed cap
100,000

Who enforces it

Enforcement body

CERT-In (the Indian Computer Emergency Response Team), the national agency appointed under Information Technology Act section 70B(1), which issued these Directions under section 70B(6); non-compliance may be prosecuted as an offence under section 70B(7).

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any service provider, intermediary, data centre, body corporate, or Government organisation that operates a computer resource in India must synchronise all its ICT system clocks to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or an equivalent source that does not deviate from them. The same entities must enable logs of all their ICT systems and retain them securely within Indian jurisdiction on a rolling 180-day basis.

They must also designate a Point of Contact for CERT-In. They must mandatorily report a broad enumerated list of cyber security incidents to CERT-In within six hours of noticing the incident or being notified of it. That enumerated list includes a data breach, a data leak, and an attack through a malicious or fake mobile app.

Data centres, virtual private server providers, cloud service providers, virtual private network service providers, and virtual asset service providers face an additional duty to register and retain specified customer KYC and transaction records for five years.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official CERT-In directions text, Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology

Back to the example  ·  Lint your app