The 28 April 2022 Directions are six paragraphs long. Practitioners who read them once often stop reading and forget the order. That is a mistake. The order of the Directions is a logical build. Direction (i) is a technical prerequisite that makes everything else evidentially useful. Direction (ii) is the notification duty on which everything hangs. Directions (iii) and (iv) tell CERT-In how it can call for information. Directions (v) and (vi) impose bulk KYC and record retention on specific service providers. Put in that order, the Directions read as one coherent regime.
Direction (i): time synchronisation
Every in-scope entity must synchronise all ICT system clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to those. Entities that operate across multiple geographies may use other accurate standard time sources provided the time does not deviate from NIC and NPL [L2-C1].
The point is not the NTP servers themselves. The point is that when CERT-In asks you what happened at 03:11 IST on the 17th of a month, and you produce logs from three systems that disagree with each other by 40 seconds, you cannot tell a straight story. Direction (i) is the foundation stone. Every log you retain for the next 180 days is only as useful as your clock.
Direction (ii): the 6-hour rule
Any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report the cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing them or being brought to notice about them [L2-C2]. The reporting channels are email ([email protected]), phone (1800-11-4949) and fax (1800-11-6969). Module 2 goes through this in full.
Direction (iii): information on demand plus Point of Contact
When CERT-In requires an entity to provide information, take an action, or extend assistance, the entity must do so in the format and timeframe specified, up to and including near real-time [L2-C3]. Every entity must designate a Point of Contact and submit the PoC in the format at Annexure II to [email protected]. Note the different email address: incident reports go to incident@, the PoC submission goes to info@. The PoC email must be kept current. It is the address CERT-In writes to when it needs you.
Direction (iv): 180 days of logs, within Indian jurisdiction
Entities must enable logs of all ICT systems and maintain them securely for a rolling 180 days, within Indian jurisdiction, and produce them to CERT-In on an incident report or on directions [L2-C4]. The FAQ softens the location language: logs may be stored offshore if the entity can produce them to CERT-In in a reasonable time. Module 3 is dedicated to this Direction.
Direction (v): five-year KYC on DC, VPS, Cloud and VPN service providers
Data Centres, Virtual Private Server providers, Cloud Service providers and VPN Service providers must register seven categories of information about each customer and retain them for five years or longer after cancellation [L2-C5]. The FAQ carves out enterprise or corporate VPNs. Direction (v) applies only to VPN Service providers offering Internet proxy-like services to general subscribers. Module 4 covers Direction (v) end to end.
Direction (vi): virtual asset service providers
Virtual asset service providers, exchange providers and custodian wallet providers must retain all KYC information and financial transaction records for five years, sufficient to reconstruct individual transactions along with the identities of parties, IP addresses, timestamps, transaction IDs, public keys and addresses, nature and date of transaction, and amount transferred [L2-C6]. This is the crypto-industry-specific Direction. Module 4 handles it alongside Direction (v).
What is not in the Directions
Nothing in the six Directions defines penalties, prescribes a specific incident report form (the form lives on the CERT-In website, at certinirform.pdf, referenced by Direction (ii)), or grants an exemption for encrypted or anonymised data. Penalties come from Section 70B(7) of the IT Act. The exemptions and clarifications come from the May 2022 FAQ, which is covered in the next lesson. This separation matters: it is the FAQ that says enterprise VPNs are outside Direction (v), and it is the FAQ that says partial reports at the 6-hour mark are acceptable. Practitioners who read the Directions but not the FAQ end up scaring their board unnecessarily.