Live Founding Cohort open, limited seats remaining Back to main site →
Cybersecurity

CERT-In Directions Practitioner Certification

The 6-hour rule, decoded. Every Indian company is subject to it.

₹4,999 Intermediate 4.4 hours 8 modules Founding Cohort: 836 seats left
Founding Cohort, DPDP Class of 2026. The first 1,000 learners to pass the final exam receive a permanent "Founding #N" badge on their certificate. 836 seats remaining.
8
Modules
22
Lessons
40
Exam questions
75%
Pass mark

A citation-anchored, exam-backed practitioner course on the CERT-In Directions of 28 April 2022 issued under Section 70B(6) of the IT Act 2000. Covers the 6-hour incident reporting clock, the 180-day log retention rule, KYC obligations on Data Centre, VPS, Cloud and VPN service providers, virtual asset service provider record-keeping, NTP time synchronisation, the incident response playbook, and the parallel-clocks runbook when the same incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications. Written from the primary law and government sources, updated through August 2026.

Who this is for. CISOs, DPOs and heads of information security; IT and security compliance leads in mid-to-large tech firms; BFSI cyber and IT risk teams facing RBI, SEBI or IRDAI oversight; MSSP consultants and CERT-In empanelled auditors and their teams; founders and CTOs of Indian SaaS, e-commerce, fintech and healthtech companies; and in-house counsel responsible for cyber incident readiness. The programme assumes you have to actually file to CERT-In, not merely brief someone who does.

What you will learn. You will read and apply the six CERT-In Directions of 28 April 2022 as they stand today, build a working 6-hour detect-to-report SLA with a template incident report, and design a 180-day log retention regime that survives a CERT-In requisition. You will distinguish enterprise VPN carve-outs from service-provider KYC obligations, reconcile CERT-In log-location language with FAQ Q35 offshore-storage guidance, and operate the parallel clocks when an incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications together. You will also structure vendor and cloud contracts so the reporting duty is not accidentally outsourced, and prepare an incident response runbook that a Deputy Secretary at CERT-In can act on. For BFSI teams whose obligations extend beyond CERT-In, the dcomply Academy RBI Cybersecurity Framework Practitioner course maps the same incident against the RBI DAKSH clock.

Legal basis. Anchored to CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, the extension dated 27 June 2022 and May 2022 FAQ, Section 70B of the IT Act 2000 (as amended by the Jan Vishwas Act 2023), the DPDP Act 2023 and DPDP Rules 2025 (notified 13 November 2025), the RBI Master Direction on IT Governance (November 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 and the Aadhaar Data Security Regulations 2016.

How the course is graded and the certificate. Self-paced. A final exam checks working knowledge across the full syllabus; the pass mark is applied uniformly and the certificate issued on pass is verifiable via a public URL. Retakes are unlimited.

What you will learn
  • Read and apply the six CERT-In Directions of 28 April 2022 as they stand today
  • Build a working 6-hour detect-to-report SLA and template incident report
  • Design a 180-day log retention regime that survives a CERT-In requisition
  • Distinguish enterprise VPN carve-outs from service-provider KYC obligations
  • Reconcile CERT-In log-location language with FAQ Q35 offshore-storage guidance
  • Operate the parallel clocks when an incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications together
  • Structure vendor and cloud contracts so the reporting duty is not accidentally outsourced
  • Prepare an incident response runbook that a Deputy Secretary at CERT-In can act on
Prerequisites
  • Basic familiarity with how an organisation collects, stores and processes digital information
  • No prior legal background required. Practitioners in security, IT, DPO, MSSP and consulting roles are the natural audience
Who this is for
  • CISOs, DPOs and heads of information security
  • IT and security compliance leads in mid to large tech firms
  • BFSI cyber and IT risk teams facing RBI, SEBI or IRDAI oversight
  • MSSP consultants and CERT-In-empanelled auditors and their teams
  • Founders and CTOs of Indian SaaS, e-commerce, fintech and healthtech companies
  • In-house counsel responsible for cyber incident readiness
About the author
AJ
Advocate Joginder Poswal
Course Author. Advocate; author of "DPDP Compliance for Indian Businesses".

Advocate Joginder Poswal is the founder of Poswal Law Office and the author of "DPDP Compliance for Indian Businesses: A Practical Guide for SMEs, Startups, and Founders". His 18 years of IT operations experience before legal practice give this course a perspective most cybersecurity compliance material lacks: it explains not only what the law says, but what it means for how your logs, incident response and vendor contracts have to be structured. This paid course is based on the CERT-In Directions of 28 April 2022, the May 2022 FAQ, the 27 June 2022 extension, the Jan Vishwas Act 2023 fine hike, the DPDP Act 2023 and DPDP Rules 2025, and the parallel sectoral frameworks of RBI, SEBI, IRDAI, DoT and UIDAI. It is intended as practitioner training and does not constitute legal advice or solicitation.

No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 75%.
Curriculum

Syllabus

8 modules, 22 lessons. Click any module to expand.

The statutory authority, the six Directions, the FAQ that clarifies scope, and how the CERT-In regime sits beside DPDP breach reporting. This module is available as a free preview so buyers can validate the depth before purchasing.

  1. 1. Section 70B, and why the Directions exist 12 min
  2. 2. The six Directions in one map 10 min
  3. 3. Who is in scope 9 min
  4. 4. Timeline and amendments through August 2026 8 min

The most-feared clause of the Directions read carefully. The twenty reportable incident types in Annexure I, when the clock starts, what happens if you cannot get complete information in 6 hours, and how to run a detect-to-report SLA that does not burn out your on-call team.

  1. 1. Direction (ii) and when the clock actually starts 10 min
  2. 2. Annexure I: the twenty incident types you must report 12 min
  3. 3. Reporting channels, the incident form, and what to include 9 min
  4. 4. Building an internal 6-hour SLA 10 min

What counts as an ICT log. Where logs may live. Who can legally requisition them.

How to reconcile the "within Indian jurisdiction" language with the FAQ softening on offshore storage. Practical retention hygiene and handoff to law enforcement.

  1. 1. Direction (iv) and what counts as an ICT log 10 min
  2. 2. FAQ Q35: offshore storage and the producible-on-demand carve-out 8 min
  3. 3. FAQ Q38: only Deputy Secretary may requisition, and when to say no 7 min

The seven KYC fields, the 5-year retention, the VASP transaction record obligation, and the FAQ Q34 clarification that enterprise VPNs are NOT covered. Also, how KYC obligations collide with DPDP data-minimisation and how to reconcile them.

  1. 1. Direction (v) and the seven KYC fields 10 min
  2. 2. FAQ Q34: enterprise VPNs are NOT covered 8 min
  3. 3. Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation 9 min

Why the Central Government demanded time-sync to NIC and NPL, the technical setup for Indian and multi-geography stacks, and why accurate time is the foundation of every credible incident report and forensic log correlation.

  1. 1. Why time-sync is the foundation of every incident report 7 min
  2. 2. Configuring NTP against NIC and NPL 8 min

A working runbook. Detection, triage, the 6-hour clock, coordination with CERT-In, containment, post-incident review, and the interlock with legal, communications and the Board. Anchored to real incidents such as AIIMS, ICMR, Angel One and Star Health.

  1. 1. The detect, triage, report, contain, review cycle 10 min
  2. 2. Coordinating with CERT-In after the initial report 8 min
  3. 3. Empanelled auditors and independent VAPT 7 min

A single incident, seven possible destinations. How to design a runbook that fires all outbound notifications at the right destination at the right time without missing any. Includes a worked example for a listed BFSI entity with personal data compromise.

  1. 1. DPDP Rule 7 alongside the CERT-In 6-hour clock 10 min
  2. 2. The parallel clocks runbook: seven destinations, one incident 11 min
  3. 3. Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI 9 min

Final certification exam covering all seven modules. Every question is anchored to a specific Direction, FAQ answer, rule, or gazette notification cited in the course. Randomised order, shuffled options, explanations shown after each question.

Lessons coming soon.

Sister Academy · VakeelSaathi Academy

Litigation angle on this? Our sister academy covers it.

VakeelSaathi Academy is our sister site for practice training aimed at corporate advocates and litigators. Separate login. Same group. You will sign in there with a fresh account.

Frequently Asked

Everything a buyer usually asks

Who is this course for?
CISOs, DPOs and heads of information security Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 8 modules covering 22 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 75% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹4,999 founding-cohort price (list price ₹14,999) One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme. Every claim is anchored to a primary source (statute, direction, FAQ, gazette notification, or sectoral regulator circular) cited in the lesson. The course is not legal advice. It does not create a lawyer-client relationship.

For specific compliance decisions, consult a qualified information technology and data protection lawyer. Where a fact was unverifiable at the time of writing, the lesson flags it explicitly.