India

IN · IND · Asia-Pacific · Last verified 2 Sep 2026

14 regulators · 26 instruments · 36 enforcement actions · 9 upcoming deadlines

India — hero image

Direction 2022

CERT-In Directions on Cyber Incident Reporting, April 2022

Issued by Indian Computer Emergency Response Team

Effective: 27 Jun 2022

Plain-English summary

The CERT-In Directions on Cyber Incident Reporting, 2022, continue to be valid and constitute the main statutory requirement for prompt cyber threat mitigation in India. According to the regulation, all individuals or organizations owning or controlling any computer resource must notify specific cyber threats within the very short period of 6 hours from their first identification. As for the reporting period, the regulatory framework mandates several operational requirements that are necessary to prevent any cyber threat – clock synchronization of all systems with NTP and national servers, maintaining system logs for 180 days, and storing all data for 5 years in case of cloud computing and virtual private network service providers. Violation of such directions constitutes a crime under section 70B(7) of the IT Act.

Who it applies to

Banking · Payments & Fintech · Crypto / VDA · Telecom & Tech

Topics

Cybersecurity & IT Risk

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates