Live Founding Cohort open, limited seats remaining Back to main site →

Section 70B, and why the Directions exist

Every cyber incident notification duty in India today runs back to a single provision: Section 70B of the Information Technology Act, 2000. This lesson explains where the statutory authority comes from, how it was used to issue the 28 April 2022 Directions, and why the penalty ceiling was quietly raised a hundred-fold in 2023.

Free preview 12 min read Verified
Legal basis
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016

Ask any Indian CISO what keeps them awake in April and the answer is usually the same: the 6-hour rule. That rule was not created by a new statute. It was issued by a directive of the Indian Computer Emergency Response Team, dated the 28th of April, 2022, under Section 70B(6) of the Information Technology Act, 2000. Before you can operate the rule, you have to see where the power to make it came from.

The statute in one paragraph

Section 70B was inserted into the IT Act in 2008. The Central Government constitutes CERT-In as the national agency for cyber incident response [L1-C1]. CERT-In has six statutory functions: it collects and analyses information on cyber incidents, issues forecasts and alerts, takes emergency measures, coordinates incident response, issues guidelines and advisories, and performs such other cyber-security functions as may be prescribed [L1-C2]. To do those things, sub-section (6) gives CERT-In the power to "call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person" [L1-C3]. Sub-section (7) attaches teeth: non-compliance is punishable with imprisonment up to one year and a fine [L1-C4].

What actually happened in April 2022

CERT-In exercised the sub-section (6) power on the 28th of April, 2022. The instrument was numbered No. 20(3)/2022-CERT-In. It carried a long title: "Directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet" [L1-C5]. The Directions were to become effective 60 days from the date of issue, that is the 27th of June, 2022.

Six substantive Directions were issued. Direction (i) required NTP time synchronisation to NIC or NPL. Direction (ii) imposed the 6-hour incident reporting rule. Direction (iii) gave CERT-In the right to demand information and required every entity to designate a Point of Contact. Direction (iv) imposed a 180-day log retention obligation within Indian jurisdiction. Direction (v) required a five-year customer-record regime for Data Centre, VPS, Cloud and VPN Service providers. Direction (vi) imposed a five-year KYC and transaction record obligation on virtual asset service providers. Each of these is covered in its own module later in the course.

The fine ceiling changed in 2023

When the Directions were first issued, non-compliance under Section 70B(7) attracted imprisonment up to one year and a fine which could extend to one lakh rupees. The Jan Vishwas (Amendment of Provisions) Act, 2023 (Act No. 18 of 2023) substituted the words "one crore rupees" for "one lakh rupees" in Section 70B(7) [L1-C6]. In other words, the maximum fine went up a hundredfold. The imprisonment ceiling is unchanged. This is the reason a course on the 2022 Directions is worth taking in 2026 and not in 2022. The obligations are the same. The consequences of ignoring them are not.

Note on gazette verification. Sources are unanimous that the Jan Vishwas Act 2023 was enacted and its schedules staged into commencement. Practitioners advising a client on maximum exposure should still confirm the specific commencement date for the IT Act entry against the e-gazette on the day of the advice. This is on the course's manual-verification checklist.

Nothing has superseded the 2022 Directions

Between the 28th of April, 2022 and August 2026, one extension order was issued (the 27 June 2022 extension for MSMEs and specific sub-clauses of Direction (v)) but no superseding Direction has replaced the substantive obligations. The DPDP Act 2023 and DPDP Rules 2025 created a parallel breach notification regime aimed at personal data, but they did not modify the CERT-In clock [L1-C7]. Practitioners should re-check the CERT-In "Directions70B" index page on the day they publish any advice to confirm no new instrument has been issued in the interim. This is also on the manual-verification checklist.

Why this matters

Most public commentary treats the 6-hour rule as if it were a standalone rule of the road. It is not. It is a specific direction issued under the statutory authority of Section 70B(6). If you understand the source, you can predict how the regime will evolve. When Parliament raises the Section 70B(7) fine, every existing Direction becomes correspondingly more expensive to ignore. When CERT-In issues a new Direction under sub-section (6), it will attach to the same penalty ceiling automatically.

That is what changed in 2023. Nothing about the six Directions changed. The cost of ignoring them changed. This is the pattern to watch.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (18 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
IT Act 2000, Section 70B(1) (Constitution of CERT-In) L1-C1
Central Government constitutes the Indian Computer Emergency Response Team as the national agency for cyber security incident response.
IT Act 2000, Section 70B(4) (Functions of CERT-In) L1-C2
CERT-In collects and analyses cyber incident data, issues forecasts and alerts, coordinates response, issues guidelines and advisories, and performs other prescribed cyber-security functions.
IT Act 2000, Section 70B(6) (Power to call for information and give directions) L1-C3
CERT-In may call for information and give directions to service providers, intermediaries, data centres, body corporates and any other person to carry out its functions. This is the authority under which the 28 April 2022 Directions were issued.
IT Act 2000, Section 70B(7) (Penalty for non-compliance) L1-C4
Any service provider, intermediary, data centre, body corporate or person who fails to provide information called for or to comply with the direction issued under sub-section (6) is punishable with imprisonment up to one year and/or fine. The fine ceiling was raised from one lakh rupees to one crore rupees by the Jan Vishwas (Amendment of Provisions) Act, 2023.
CERT-In Directions 2022, Preamble (Instrument, authority, coverage) L1-C5
Directions No. 20(3)/2022-CERT-In dated 28 April 2022. Issued under Section 70B(6) of the IT Act 2000. Titled: Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet. Effective 60 days from issue, i.e. 27 June 2022.
Jan Vishwas Act 2023, Schedule item on IT Act 70B(7) (Fine ceiling under Sec. 70B(7) raised from one lakh to one crore rupees) L1-C6
The Jan Vishwas (Amendment of Provisions) Act, 2023 (No. 18 of 2023) amended the penalty ceiling in Section 70B(7) of the IT Act 2000. The maximum fine for non-compliance with a CERT-In direction was raised from one lakh rupees to one crore rupees. Imprisonment ceiling remains one year. Practitioners should confirm the exact commencement date against the gazette on release day.
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L1-C7
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Law Itself
Module 2: The 6-Hour Rule
  • Direction (ii) and when the clock actually starts
  • Annexure I: the twenty incident types you must report
  • Reporting channels, the incident form, and what to include
  • Building an internal 6-hour SLA
Module 3: Log Retention, 180 Days, in India
  • Direction (iv) and what counts as an ICT log
  • FAQ Q35: offshore storage and the producible-on-demand carve-out
  • FAQ Q38: only Deputy Secretary may requisition, and when to say no
Module 4: VPN, VPS, Cloud, VDR and Crypto KYC
  • Direction (v) and the seven KYC fields
  • FAQ Q34: enterprise VPNs are NOT covered
  • Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation
Module 5: NTP Time-Sync
  • Why time-sync is the foundation of every incident report
  • Configuring NTP against NIC and NPL
Module 6: Incident Response Playbook
  • The detect, triage, report, contain, review cycle
  • Coordinating with CERT-In after the initial report
  • Empanelled auditors and independent VAPT
Module 7: DPDP + CERT-In Together
  • DPDP Rule 7 alongside the CERT-In 6-hour clock
  • The parallel clocks runbook: seven destinations, one incident
  • Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI
Module 8: Final Exam and Certificate