Live Founding Cohort open, limited seats remaining Back to main site →

Timeline and amendments through August 2026

A single reference timeline: what was issued, when it took effect, what changed since, and what to check on the day you give advice. Includes the DPDP overlay and the pending Delhi High Court challenge.

Free preview 8 min read Verified
Legal basis
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016

The regime has moved in five discrete steps. Anyone advising on it must know all five, and know what to re-check on the day of the advice.

Step 1. 28 April 2022. The Directions

CERT-In issued the six Directions under Section 70B(6). Effective 60 days from issue, i.e. the 27th of June, 2022. No superseding Direction has been issued since. Always re-check the CERT-In "Directions70B" index page on the day of publication of any advice.

Step 2. 18 May 2022. The FAQ

CERT-In published 44 Frequently Asked Questions on the Directions. The FAQ answers scope, applicability, extraterritorial reach, definition of cyber incident, log storage location, and the enterprise-VPN carve-out. Practitioners often forget how much of the working regime lives in this document. Twelve FAQ answers are drilled into throughout this course: Q3, Q7, Q10, Q13, Q22, Q24, Q25, Q26, Q30, Q34, Q35, Q37 and Q38.

Step 3. 27 June 2022. The extension for MSMEs and Direction (v)(a), (f)

Issued on the same day the Directions took effect for everyone else. It pushed the effective date to the 25th of September, 2022 for MSMEs and for the subscriber-name and address-validation obligations of Direction (v)(a) and (v)(f) for DC, VPS, Cloud and VPN Service providers [L4-C1]. All other obligations became effective on 27 June 2022 as issued.

Step 4. Jan Vishwas Act 2023. The fine hike

The Jan Vishwas (Amendment of Provisions) Act, 2023 amended Section 70B(7) of the IT Act to raise the fine ceiling for non-compliance from one lakh rupees to one crore rupees [L4-C2]. The imprisonment ceiling remains one year. This is the single most important change since the Directions were issued. It transforms the risk calculus for any non-compliant entity.

Step 5. 13 November 2025. DPDP Rules Rule 7. The parallel breach clock

The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 by Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E) on the 13th and 14th of November, 2025. Rule 7 introduces a two-stage breach notification duty to the Data Protection Board of India: "without delay" for the initial notice, and within 72 hours (extendable on written request) for the detailed report [L4-C3]. This is a separate clock, running to a separate destination, than the CERT-In 6-hour clock. It does not modify the Directions. Module 7 walks through how the two regimes run in parallel for a single incident, and how to reconcile them without missing either deadline.

What has not happened

Some things you might expect have not happened:

  • No superseding CERT-In Direction has replaced the 28 April 2022 instrument through August 2026.
  • The Digital India Act announced in March 2023 has not been introduced as a Bill through August 2026. The IT Act 2000 remains the parent statute.
  • No Supreme Court judgment interpreting Section 70B or the Directions has been located through August 2026.
  • No public prosecution or fine under Section 70B(7) has been reported. The regime has produced large de-facto compliance costs (VPN provider exits, integrated breach playbooks across four regulators) without any public monetary enforcement action. The Star Health disclosure of August 2024 is the strongest open test case for late reporting; no penalty had been imposed as of August 2026.

Live litigation to know about

The Delhi High Court is hearing SnTHostings v. Union of India, a constitutional challenge to Direction (v) filed in September 2022. CERT-In filed its counter-affidavit on the 8th of December, 2022. The petition remains pending through August 2026. If Direction (v) is struck down or read down, the VPN and cloud KYC regime changes substantially. This is worth watching before any long-lead product launch that depends on Direction (v) status.

The one-slide summary

The Directions of 28 April 2022, softened by the FAQ of May 2022, extended for MSMEs to 25 September 2022, have not been superseded. The Section 70B(7) fine ceiling was raised from one lakh to one crore rupees by Jan Vishwas Act 2023. A separate DPDP breach clock runs alongside them from 13 November 2025.

That is Module 1 in one paragraph. Modules 2 through 7 unpack the operational implications.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of CERT-In Directions Practitioner Certification?

  • All 7 paid modules (18 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
CERT-In Extension 2022, Extension Order (Partial extension for MSMEs and Direction (v)(a) & (v)(f)) L4-C1
Effective date pushed from 27 June 2022 to 25 September 2022 for MSMEs classified under MoMSME S.O. 1702(E) dated 1 June 2020, and for the subscriber-name and address-validation obligations under Direction (v)(a) and (v)(f) applicable to Data Centre, VPS, Cloud and VPN service providers. All other obligations became effective on 27 June 2022 as originally notified.
Jan Vishwas Act 2023, Schedule item on IT Act 70B(7) (Fine ceiling under Sec. 70B(7) raised from one lakh to one crore rupees) L4-C2
The Jan Vishwas (Amendment of Provisions) Act, 2023 (No. 18 of 2023) amended the penalty ceiling in Section 70B(7) of the IT Act 2000. The maximum fine for non-compliance with a CERT-In direction was raised from one lakh rupees to one crore rupees. Imprisonment ceiling remains one year. Practitioners should confirm the exact commencement date against the gazette on release day.
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L4-C3
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Law Itself
Module 2: The 6-Hour Rule
  • Direction (ii) and when the clock actually starts
  • Annexure I: the twenty incident types you must report
  • Reporting channels, the incident form, and what to include
  • Building an internal 6-hour SLA
Module 3: Log Retention, 180 Days, in India
  • Direction (iv) and what counts as an ICT log
  • FAQ Q35: offshore storage and the producible-on-demand carve-out
  • FAQ Q38: only Deputy Secretary may requisition, and when to say no
Module 4: VPN, VPS, Cloud, VDR and Crypto KYC
  • Direction (v) and the seven KYC fields
  • FAQ Q34: enterprise VPNs are NOT covered
  • Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation
Module 5: NTP Time-Sync
  • Why time-sync is the foundation of every incident report
  • Configuring NTP against NIC and NPL
Module 6: Incident Response Playbook
  • The detect, triage, report, contain, review cycle
  • Coordinating with CERT-In after the initial report
  • Empanelled auditors and independent VAPT
Module 7: DPDP + CERT-In Together
  • DPDP Rule 7 alongside the CERT-In 6-hour clock
  • The parallel clocks runbook: seven destinations, one incident
  • Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI
Module 8: Final Exam and Certificate