Ask any Indian CISO what keeps them awake in April and the answer is usually the same: the 6-hour rule. That rule was not created by a new statute. It was issued by a directive of the Indian Computer Emergency Response Team, dated the 28th of April, 2022, under Section 70B(6) of the Information Technology Act, 2000. Before you can operate the rule, you have to see where the power to make it came from.
The statute in one paragraph
Section 70B was inserted into the IT Act in 2008. The Central Government constitutes CERT-In as the national agency for cyber incident response [L1-C1]. CERT-In has six statutory functions: it collects and analyses information on cyber incidents, issues forecasts and alerts, takes emergency measures, coordinates incident response, issues guidelines and advisories, and performs such other cyber-security functions as may be prescribed [L1-C2]. To do those things, sub-section (6) gives CERT-In the power to "call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person" [L1-C3]. Sub-section (7) attaches teeth: non-compliance is punishable with imprisonment up to one year and a fine [L1-C4].
What actually happened in April 2022
CERT-In exercised the sub-section (6) power on the 28th of April, 2022. The instrument was numbered No. 20(3)/2022-CERT-In. It carried a long title: "Directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet" [L1-C5]. The Directions were to become effective 60 days from the date of issue, that is the 27th of June, 2022.
Six substantive Directions were issued. Direction (i) required NTP time synchronisation to NIC or NPL. Direction (ii) imposed the 6-hour incident reporting rule. Direction (iii) gave CERT-In the right to demand information and required every entity to designate a Point of Contact. Direction (iv) imposed a 180-day log retention obligation within Indian jurisdiction. Direction (v) required a five-year customer-record regime for Data Centre, VPS, Cloud and VPN Service providers. Direction (vi) imposed a five-year KYC and transaction record obligation on virtual asset service providers. Each of these is covered in its own module later in the course.
The fine ceiling changed in 2023
When the Directions were first issued, non-compliance under Section 70B(7) attracted imprisonment up to one year and a fine which could extend to one lakh rupees. The Jan Vishwas (Amendment of Provisions) Act, 2023 (Act No. 18 of 2023) substituted the words "one crore rupees" for "one lakh rupees" in Section 70B(7) [L1-C6]. In other words, the maximum fine went up a hundredfold. The imprisonment ceiling is unchanged. This is the reason a course on the 2022 Directions is worth taking in 2026 and not in 2022. The obligations are the same. The consequences of ignoring them are not.
Note on gazette verification. Sources are unanimous that the Jan Vishwas Act 2023 was enacted and its schedules staged into commencement. Practitioners advising a client on maximum exposure should still confirm the specific commencement date for the IT Act entry against the e-gazette on the day of the advice. This is on the course's manual-verification checklist.
Nothing has superseded the 2022 Directions
Between the 28th of April, 2022 and August 2026, one extension order was issued (the 27 June 2022 extension for MSMEs and specific sub-clauses of Direction (v)) but no superseding Direction has replaced the substantive obligations. The DPDP Act 2023 and DPDP Rules 2025 created a parallel breach notification regime aimed at personal data, but they did not modify the CERT-In clock [L1-C7]. Practitioners should re-check the CERT-In "Directions70B" index page on the day they publish any advice to confirm no new instrument has been issued in the interim. This is also on the manual-verification checklist.
Why this matters
Most public commentary treats the 6-hour rule as if it were a standalone rule of the road. It is not. It is a specific direction issued under the statutory authority of Section 70B(6). If you understand the source, you can predict how the regime will evolve. When Parliament raises the Section 70B(7) fine, every existing Direction becomes correspondingly more expensive to ignore. When CERT-In issues a new Direction under sub-section (6), it will attach to the same penalty ceiling automatically.
That is what changed in 2023. Nothing about the six Directions changed. The cost of ignoring them changed. This is the pattern to watch.