We are always ready to protect your data

CERT-In Directions (2022)
Compliance Audit

Compliance support aligned to CERT-In incident reporting and log retention mandates. Ensure your organization meets the stringent 6-hour reporting timelines and national cybersecurity guidelines.

6-Hour Readiness Log Retention Trusted Experts Forensic Ready
Service Overview
100%Legal Alignment
180Days Log Validation
48hrReport Delivery
0Penalties
  • 6-hour reporting readiness
  • Log management validation
  • Forensic readiness advisory
  • Incident documentation framework
  • CERT-In empanelled standards
Overview

What are the CERT-In Directions (2022)?

The Indian Computer Emergency Response Team (CERT-In) issued new directions in 2022 under Section 70B of the IT Act, 2000. These directives mandate stringent cybersecurity guidelines for service providers, intermediaries, body corporates, and government organizations, including the mandatory reporting of severe cyber incidents within 6 hours and maintaining secure IT logs for a rolling period of 180 days.

Our compliance support services help your organization align with these critical national mandates. We validate your log management architecture, assess your forensic readiness, and establish a robust, legally defensible incident documentation framework to ensure full regulatory compliance and prevent legal penalties.

Coverage Areas:

  • 6-hour reporting readiness workflows
  • Log management validation (180 days)
  • Forensic readiness advisory
  • Incident documentation framework
  • NTP Server synchronization assessment
Service At a Glance
Service TypeRegulatory Compliance
Focus AreaIncident Reporting & Logs
OutcomeNational Cyber Alignment
StandardCERT-In Directions 2022
ReportingGap & Validation Report
DeliverableAudit-Ready Status
EngagementNDA Protected
Our Methodology

Approach to CERT-In Compliance

Readiness Assessment
Log Management
Incident Reporting
Forensic Advisory
Governance & Policies
🔍

Gap & Readiness Assessment

We systematically evaluate your organization's current IT and security posture against the specific directives outlined in the CERT-In 2022 mandate.

This discovery phase identifies critical areas of vulnerability, specifically focusing on your current capability to detect, analyze, and report cyber incidents within the legally required timeframes.

Mandate Review Infrastructure Audit Current-State Analysis Gap Identification
💾

Log Management & NTP Validation

CERT-In mandates the secure retention of ICT system logs for a rolling period of 180 days. We validate your log storage architecture to ensure logs are collected, securely stored within Indian jurisdiction, and readily available.

Additionally, we assess your systems' Network Time Protocol (NTP) synchronization to ensure all clocks are synced with the servers of the National Informatics Centre (NIC) or National Physical Laboratory (NPL).

180-Day Log Retention NTP Server Sync Storage Architecture Jurisdiction Compliance
⏱️

6-Hour Incident Reporting Framework

The core of the 2022 directives is the requirement to report specific severe cyber incidents to CERT-In within 6 hours. We help design and implement the workflows needed to meet this strict SLA.

This includes streamlining internal communication, automating alert escalations, and establishing clear protocols for the Point of Contact (PoC) responsible for liaising with CERT-In.

6-Hour SLA Workflows Alert Automation Internal Escalation CERT-In PoC Setup
🔬

Forensic Readiness Advisory

In the event of an incident, logs must be preserved as evidence. We provide forensic readiness advisory to ensure your logs are tamper-proof and cryptographically secure.

We establish procedures for evidence preservation and chain of custody, ensuring that your data can be used effectively for internal investigations, regulatory reviews, or law enforcement inquiries.

Tamper-Proof Logs Evidence Preservation Chain of Custody Forensic Preparedness
📝

Governance & Incident Documentation

We help update your organizational IT policies and Incident Response (IR) plans to explicitly reflect the CERT-In mandates. This ensures compliance is baked into your everyday governance.

We develop a comprehensive incident documentation framework, providing standardized templates for reporting incidents accurately and thoroughly as required by national authorities.

IR Policy Updates Documentation Templates Governance Alignment Continuous Compliance
Compliance Domains

Key CERT-In Mandates

The critical requirements enforced by the 2022 directions that organizations must fulfill.

Rapid Response

6-Hour Incident
Reporting

Organizations must report specified cyber incidents (like data breaches, ransomware, or critical system compromise) to CERT-In within 6 hours of noticing them. We design the internal automation, escalation matrices, and communication channels necessary to meet this aggressive deadline without fail.

  • Automated alert triage
  • Designated Point of Contact (PoC)
  • Incident severity classification
  • Pre-approved reporting templates
Data Retention

Log Management &
Time Sync

The directive mandates maintaining secure, rolling logs of all ICT systems for 180 days within Indian jurisdiction. We validate your log storage architecture and ensure your system clocks are strictly synchronized with the Network Time Protocol (NTP) servers of NIC or NPL for accurate time-stamping.

  • 180-day rolling log retention
  • NTP Server synchronization
  • Centralized SIEM integration
  • Data localization checks
Investigation Preparedness

Forensic Readiness & Documentation Framework

To assist in post-incident analysis and regulatory scrutiny, organizations must be forensically ready. We advise on establishing tamper-proof log storage, secure evidence preservation, and a structured documentation framework that ensures all actions taken during an incident are legally defensible and compliant.

  • Cryptographically secured logs
  • Chain of custody procedures
  • Detailed incident playbooks
  • Law enforcement readiness
Why It Matters

Outcomes of CERT-In Compliance

Regulatory Compliance

Avoid punitive actions, legal liabilities, and penalties under Section 70B of the IT Act by fully adhering to the mandated guidelines.

National Security Alignment

Contribute to India's national cybersecurity posture by ensuring your infrastructure can rapidly report and share vital threat intelligence.

Rapid Incident Response

Streamline your internal Incident Response (IR) processes, enabling your security teams to react to severe threats within hours, not days.

Forensic Preparedness

Maintain secure, irrefutable logs and evidence trails, ensuring you are fully prepared for post-incident investigations or regulatory audits.

Common Questions

Frequently Asked Questions

What are the CERT-In Directions 2022?
Issued under Section 70B of the IT Act, these directions mandate new cybersecurity guidelines aimed at strengthening India's cybersecurity posture. They require specific incident reporting timelines, strict log retention policies, and accurate time synchronization across IT infrastructure.
Who must comply with these directions?
The mandates apply broadly to service providers, intermediaries, data centers, body corporates, and government organizations operating within India. If you handle digital infrastructure or user data, these rules likely apply to your operations.
What is the 6-hour reporting rule?
Organizations are legally required to report a specific list of severe cyber incidents (like data breaches, ransomware attacks, or critical infrastructure compromises) to CERT-In within 6 hours of noticing such incidents or being brought to notice about them.
What are the log retention requirements?
Organizations must maintain secure logs of all their ICT (Information and Communication Technology) systems for a rolling period of 180 days. Furthermore, these logs must be stored within Indian jurisdiction to facilitate investigations if needed.
Why is NTP synchronization important?
CERT-In requires that all system clocks connect and sync with the Network Time Protocol (NTP) servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL). This ensures uniform timestamps across all systems, which is critical for accurate forensic analysis during a cyber incident.

All Your Cyber Security Needs
Under One Roof

Or call us: 93156 97737