Live Founding Cohort open, limited seats remaining Back to main site →

The six Directions in one map

A one-page mental model of everything the 28 April 2022 Directions require. Read this once, and every later module will slot into a place you already recognise.

Free preview 10 min read Verified
Legal basis
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016

The 28 April 2022 Directions are six paragraphs long. Practitioners who read them once often stop reading and forget the order. That is a mistake. The order of the Directions is a logical build. Direction (i) is a technical prerequisite that makes everything else evidentially useful. Direction (ii) is the notification duty on which everything hangs. Directions (iii) and (iv) tell CERT-In how it can call for information. Directions (v) and (vi) impose bulk KYC and record retention on specific service providers. Put in that order, the Directions read as one coherent regime.

Direction (i): time synchronisation

Every in-scope entity must synchronise all ICT system clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to those. Entities that operate across multiple geographies may use other accurate standard time sources provided the time does not deviate from NIC and NPL [L2-C1].

The point is not the NTP servers themselves. The point is that when CERT-In asks you what happened at 03:11 IST on the 17th of a month, and you produce logs from three systems that disagree with each other by 40 seconds, you cannot tell a straight story. Direction (i) is the foundation stone. Every log you retain for the next 180 days is only as useful as your clock.

Direction (ii): the 6-hour rule

Any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report the cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing them or being brought to notice about them [L2-C2]. The reporting channels are email ([email protected]), phone (1800-11-4949) and fax (1800-11-6969). Module 2 goes through this in full.

Direction (iii): information on demand plus Point of Contact

When CERT-In requires an entity to provide information, take an action, or extend assistance, the entity must do so in the format and timeframe specified, up to and including near real-time [L2-C3]. Every entity must designate a Point of Contact and submit the PoC in the format at Annexure II to [email protected]. Note the different email address: incident reports go to incident@, the PoC submission goes to info@. The PoC email must be kept current. It is the address CERT-In writes to when it needs you.

Direction (iv): 180 days of logs, within Indian jurisdiction

Entities must enable logs of all ICT systems and maintain them securely for a rolling 180 days, within Indian jurisdiction, and produce them to CERT-In on an incident report or on directions [L2-C4]. The FAQ softens the location language: logs may be stored offshore if the entity can produce them to CERT-In in a reasonable time. Module 3 is dedicated to this Direction.

Direction (v): five-year KYC on DC, VPS, Cloud and VPN service providers

Data Centres, Virtual Private Server providers, Cloud Service providers and VPN Service providers must register seven categories of information about each customer and retain them for five years or longer after cancellation [L2-C5]. The FAQ carves out enterprise or corporate VPNs. Direction (v) applies only to VPN Service providers offering Internet proxy-like services to general subscribers. Module 4 covers Direction (v) end to end.

Direction (vi): virtual asset service providers

Virtual asset service providers, exchange providers and custodian wallet providers must retain all KYC information and financial transaction records for five years, sufficient to reconstruct individual transactions along with the identities of parties, IP addresses, timestamps, transaction IDs, public keys and addresses, nature and date of transaction, and amount transferred [L2-C6]. This is the crypto-industry-specific Direction. Module 4 handles it alongside Direction (v).

What is not in the Directions

Nothing in the six Directions defines penalties, prescribes a specific incident report form (the form lives on the CERT-In website, at certinirform.pdf, referenced by Direction (ii)), or grants an exemption for encrypted or anonymised data. Penalties come from Section 70B(7) of the IT Act. The exemptions and clarifications come from the May 2022 FAQ, which is covered in the next lesson. This separation matters: it is the FAQ that says enterprise VPNs are outside Direction (v), and it is the FAQ that says partial reports at the 6-hour mark are acceptable. Practitioners who read the Directions but not the FAQ end up scaring their board unnecessarily.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (18 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
CERT-In Directions 2022, Direction (i) (NTP time synchronisation) L2-C1
All in-scope entities must synchronise their ICT system clocks to the NIC or NPL Network Time Protocol servers, or to NTP servers traceable to these. Entities operating across multiple geographies may use other accurate standard time sources provided the time does not deviate from NIC and NPL.
CERT-In Directions 2022, Direction (ii) (CERT-In 6-hour cyber incident reporting (parallel to CSCRF)) L2-C2
CERT-In Directions of 28 April 2022, Direction (ii): any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing. Runs in parallel with SEBI CSCRF 6-hour clock. Filing to one regulator does not satisfy the obligation to the other.
CERT-In Directions 2022, Direction (iii) (Information on demand and Point of Contact) L2-C3
When CERT-In requires information, or orders an entity to take an action or extend assistance, the entity must comply in the specified format and timeframe. Every entity must designate a Point of Contact to interface with CERT-In and submit the PoC in the format at Annexure II to [email protected].
CERT-In Directions 2022, Direction (iv) (180-day log retention within Indian jurisdiction) L2-C4
All in-scope entities must enable logs of all ICT systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. Logs must be provided to CERT-In along with any incident report or on direction. FAQ Q35 clarifies that offshore storage is acceptable if logs can be produced to CERT-In in a reasonable time.
CERT-In Directions 2022, Direction (v) (Five-year KYC for Data Centre, VPS, Cloud and VPN service providers) L2-C5
Data Centres, Virtual Private Server providers, Cloud Service providers and VPN Service providers must register and retain seven categories of customer information for a period of 5 years or longer, after cancellation or withdrawal of registration by the customer.
CERT-In Directions 2022, Direction (vi) (Five-year KYC and transaction records for virtual asset service providers) L2-C6
Virtual Asset Service Providers, virtual asset exchange providers and custodian wallet providers must retain all information obtained during KYC and records of financial transactions for 5 years so as to reconstruct individual transactions along with the relevant elements: identities of parties, IP addresses, timestamps, transaction IDs, public keys / addresses, nature and date of transaction, and amount transferred.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Law Itself
Module 2: The 6-Hour Rule
  • Direction (ii) and when the clock actually starts
  • Annexure I: the twenty incident types you must report
  • Reporting channels, the incident form, and what to include
  • Building an internal 6-hour SLA
Module 3: Log Retention, 180 Days, in India
  • Direction (iv) and what counts as an ICT log
  • FAQ Q35: offshore storage and the producible-on-demand carve-out
  • FAQ Q38: only Deputy Secretary may requisition, and when to say no
Module 4: VPN, VPS, Cloud, VDR and Crypto KYC
  • Direction (v) and the seven KYC fields
  • FAQ Q34: enterprise VPNs are NOT covered
  • Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation
Module 5: NTP Time-Sync
  • Why time-sync is the foundation of every incident report
  • Configuring NTP against NIC and NPL
Module 6: Incident Response Playbook
  • The detect, triage, report, contain, review cycle
  • Coordinating with CERT-In after the initial report
  • Empanelled auditors and independent VAPT
Module 7: DPDP + CERT-In Together
  • DPDP Rule 7 alongside the CERT-In 6-hour clock
  • The parallel clocks runbook: seven destinations, one incident
  • Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI
Module 8: Final Exam and Certificate