The regime has moved in five discrete steps. Anyone advising on it must know all five, and know what to re-check on the day of the advice.
Step 1. 28 April 2022. The Directions
CERT-In issued the six Directions under Section 70B(6). Effective 60 days from issue, i.e. the 27th of June, 2022. No superseding Direction has been issued since. Always re-check the CERT-In "Directions70B" index page on the day of publication of any advice.
Step 2. 18 May 2022. The FAQ
CERT-In published 44 Frequently Asked Questions on the Directions. The FAQ answers scope, applicability, extraterritorial reach, definition of cyber incident, log storage location, and the enterprise-VPN carve-out. Practitioners often forget how much of the working regime lives in this document. Twelve FAQ answers are drilled into throughout this course: Q3, Q7, Q10, Q13, Q22, Q24, Q25, Q26, Q30, Q34, Q35, Q37 and Q38.
Step 3. 27 June 2022. The extension for MSMEs and Direction (v)(a), (f)
Issued on the same day the Directions took effect for everyone else. It pushed the effective date to the 25th of September, 2022 for MSMEs and for the subscriber-name and address-validation obligations of Direction (v)(a) and (v)(f) for DC, VPS, Cloud and VPN Service providers [L4-C1]. All other obligations became effective on 27 June 2022 as issued.
Step 4. Jan Vishwas Act 2023. The fine hike
The Jan Vishwas (Amendment of Provisions) Act, 2023 amended Section 70B(7) of the IT Act to raise the fine ceiling for non-compliance from one lakh rupees to one crore rupees [L4-C2]. The imprisonment ceiling remains one year. This is the single most important change since the Directions were issued. It transforms the risk calculus for any non-compliant entity.
Step 5. 13 November 2025. DPDP Rules Rule 7. The parallel breach clock
The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 by Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E) on the 13th and 14th of November, 2025. Rule 7 introduces a two-stage breach notification duty to the Data Protection Board of India: "without delay" for the initial notice, and within 72 hours (extendable on written request) for the detailed report [L4-C3]. This is a separate clock, running to a separate destination, than the CERT-In 6-hour clock. It does not modify the Directions. Module 7 walks through how the two regimes run in parallel for a single incident, and how to reconcile them without missing either deadline.
What has not happened
Some things you might expect have not happened:
- No superseding CERT-In Direction has replaced the 28 April 2022 instrument through August 2026.
- The Digital India Act announced in March 2023 has not been introduced as a Bill through August 2026. The IT Act 2000 remains the parent statute.
- No Supreme Court judgment interpreting Section 70B or the Directions has been located through August 2026.
- No public prosecution or fine under Section 70B(7) has been reported. The regime has produced large de-facto compliance costs (VPN provider exits, integrated breach playbooks across four regulators) without any public monetary enforcement action. The Star Health disclosure of August 2024 is the strongest open test case for late reporting; no penalty had been imposed as of August 2026.
Live litigation to know about
The Delhi High Court is hearing SnTHostings v. Union of India, a constitutional challenge to Direction (v) filed in September 2022. CERT-In filed its counter-affidavit on the 8th of December, 2022. The petition remains pending through August 2026. If Direction (v) is struck down or read down, the VPN and cloud KYC regime changes substantially. This is worth watching before any long-lead product launch that depends on Direction (v) status.
The one-slide summary
The Directions of 28 April 2022, softened by the FAQ of May 2022, extended for MSMEs to 25 September 2022, have not been superseded. The Section 70B(7) fine ceiling was raised from one lakh to one crore rupees by Jan Vishwas Act 2023. A separate DPDP breach clock runs alongside them from 13 November 2025.
That is Module 1 in one paragraph. Modules 2 through 7 unpack the operational implications.