CERT-In Directions Practitioner Certification
The 6-hour rule, decoded. Every Indian company is subject to it.
A citation-anchored, exam-backed practitioner course on the CERT-In Directions of 28 April 2022 issued under Section 70B(6) of the IT Act 2000. Covers the 6-hour incident reporting clock, the 180-day log retention rule, KYC obligations on Data Centre, VPS, Cloud and VPN service providers, virtual asset service provider record-keeping, NTP time synchronisation, the incident response playbook, and the parallel-clocks runbook when the same incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications. Written from the primary law and government sources, updated through August 2026.
Who this is for. CISOs, DPOs and heads of information security; IT and security compliance leads in mid-to-large tech firms; BFSI cyber and IT risk teams facing RBI, SEBI or IRDAI oversight; MSSP consultants and CERT-In empanelled auditors and their teams; founders and CTOs of Indian SaaS, e-commerce, fintech and healthtech companies; and in-house counsel responsible for cyber incident readiness. The programme assumes you have to actually file to CERT-In, not merely brief someone who does.
What you will learn. You will read and apply the six CERT-In Directions of 28 April 2022 as they stand today, build a working 6-hour detect-to-report SLA with a template incident report, and design a 180-day log retention regime that survives a CERT-In requisition. You will distinguish enterprise VPN carve-outs from service-provider KYC obligations, reconcile CERT-In log-location language with FAQ Q35 offshore-storage guidance, and operate the parallel clocks when an incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications together. You will also structure vendor and cloud contracts so the reporting duty is not accidentally outsourced, and prepare an incident response runbook that a Deputy Secretary at CERT-In can act on. For BFSI teams whose obligations extend beyond CERT-In, the dcomply Academy RBI Cybersecurity Framework Practitioner course maps the same incident against the RBI DAKSH clock.
Legal basis. Anchored to CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, the extension dated 27 June 2022 and May 2022 FAQ, Section 70B of the IT Act 2000 (as amended by the Jan Vishwas Act 2023), the DPDP Act 2023 and DPDP Rules 2025 (notified 13 November 2025), the RBI Master Direction on IT Governance (November 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 and the Aadhaar Data Security Regulations 2016.
How the course is graded and the certificate. Self-paced. A final exam checks working knowledge across the full syllabus; the pass mark is applied uniformly and the certificate issued on pass is verifiable via a public URL. Retakes are unlimited.
What you will learn
- Read and apply the six CERT-In Directions of 28 April 2022 as they stand today
- Build a working 6-hour detect-to-report SLA and template incident report
- Design a 180-day log retention regime that survives a CERT-In requisition
- Distinguish enterprise VPN carve-outs from service-provider KYC obligations
- Reconcile CERT-In log-location language with FAQ Q35 offshore-storage guidance
- Operate the parallel clocks when an incident triggers CERT-In, DPDP, RBI, SEBI, IRDAI, DoT and UIDAI notifications together
- Structure vendor and cloud contracts so the reporting duty is not accidentally outsourced
- Prepare an incident response runbook that a Deputy Secretary at CERT-In can act on
Prerequisites
- Basic familiarity with how an organisation collects, stores and processes digital information
- No prior legal background required. Practitioners in security, IT, DPO, MSSP and consulting roles are the natural audience
Who this is for
- CISOs, DPOs and heads of information security
- IT and security compliance leads in mid to large tech firms
- BFSI cyber and IT risk teams facing RBI, SEBI or IRDAI oversight
- MSSP consultants and CERT-In-empanelled auditors and their teams
- Founders and CTOs of Indian SaaS, e-commerce, fintech and healthtech companies
- In-house counsel responsible for cyber incident readiness
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 22 lessons. Click any module to expand.
The statutory authority, the six Directions, the FAQ that clarifies scope, and how the CERT-In regime sits beside DPDP breach reporting. This module is available as a free preview so buyers can validate the depth before purchasing.
- 1. Section 70B, and why the Directions exist 12 min
- 2. The six Directions in one map 10 min
- 3. Who is in scope 9 min
- 4. Timeline and amendments through August 2026 8 min
The most-feared clause of the Directions read carefully. The twenty reportable incident types in Annexure I, when the clock starts, what happens if you cannot get complete information in 6 hours, and how to run a detect-to-report SLA that does not burn out your on-call team.
- 1. Direction (ii) and when the clock actually starts 10 min
- 2. Annexure I: the twenty incident types you must report 12 min
- 3. Reporting channels, the incident form, and what to include 9 min
- 4. Building an internal 6-hour SLA 10 min
What counts as an ICT log. Where logs may live. Who can legally requisition them.
How to reconcile the "within Indian jurisdiction" language with the FAQ softening on offshore storage. Practical retention hygiene and handoff to law enforcement.
- 1. Direction (iv) and what counts as an ICT log 10 min
- 2. FAQ Q35: offshore storage and the producible-on-demand carve-out 8 min
- 3. FAQ Q38: only Deputy Secretary may requisition, and when to say no 7 min
The seven KYC fields, the 5-year retention, the VASP transaction record obligation, and the FAQ Q34 clarification that enterprise VPNs are NOT covered. Also, how KYC obligations collide with DPDP data-minimisation and how to reconcile them.
- 1. Direction (v) and the seven KYC fields 10 min
- 2. FAQ Q34: enterprise VPNs are NOT covered 8 min
- 3. Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation 9 min
Why the Central Government demanded time-sync to NIC and NPL, the technical setup for Indian and multi-geography stacks, and why accurate time is the foundation of every credible incident report and forensic log correlation.
- 1. Why time-sync is the foundation of every incident report 7 min
- 2. Configuring NTP against NIC and NPL 8 min
A working runbook. Detection, triage, the 6-hour clock, coordination with CERT-In, containment, post-incident review, and the interlock with legal, communications and the Board. Anchored to real incidents such as AIIMS, ICMR, Angel One and Star Health.
- 1. The detect, triage, report, contain, review cycle 10 min
- 2. Coordinating with CERT-In after the initial report 8 min
- 3. Empanelled auditors and independent VAPT 7 min
A single incident, seven possible destinations. How to design a runbook that fires all outbound notifications at the right destination at the right time without missing any. Includes a worked example for a listed BFSI entity with personal data compromise.
- 1. DPDP Rule 7 alongside the CERT-In 6-hour clock 10 min
- 2. The parallel clocks runbook: seven destinations, one incident 11 min
- 3. Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI 9 min
Final certification exam covering all seven modules. Every question is anchored to a specific Direction, FAQ answer, rule, or gazette notification cited in the course. Randomised order, shuffled options, explanations shown after each question.
Lessons coming soon.
Litigation angle on this? Our sister academy covers it.
VakeelSaathi Academy is our sister site for practice training aimed at corporate advocates and litigators. Separate login. Same group. You will sign in there with a fresh account.
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme. Every claim is anchored to a primary source (statute, direction, FAQ, gazette notification, or sectoral regulator circular) cited in the lesson. The course is not legal advice. It does not create a lawyer-client relationship.
For specific compliance decisions, consult a qualified information technology and data protection lawyer. Where a fact was unverifiable at the time of writing, the lesson flags it explicitly.
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016