Live Founding Cohort open, limited seats remaining Back to main site →

Who is in scope

The Directions apply to service providers, intermediaries, data centres, body corporates and Government organisations. That sounds narrow. In practice, almost every organisation operating in India is caught. This lesson tells you when you are in scope and, more usefully, when you are not.

Free preview 9 min read Verified
Legal basis
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016

The applicability text at the top of the Directions is short: "service providers, intermediaries, data centres, body corporate and Government organisations". Read casually, that reads like a list of technology companies. Read carefully, it catches almost every business in India.

What "body corporate" means here

The term takes its meaning from the explanation to Section 43A of the IT Act 2000. FAQ Q25 confirms this: body corporate means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities [L3-C1]. So the term does not just mean a listed company or a PLC. It catches a partnership firm running a chartered accountancy practice, a sole proprietor running an e-commerce store, and a two-founder LLP running a SaaS product.

The one clean exclusion from FAQ Q7 is the individual citizen. If you are simply an individual using digital services in India, the Directions do not impose reporting obligations on you. If you run any commercial activity through a business form, they do [L3-C2].

What "service provider" and "intermediary" cover

The FAQ lists cloud service providers, VPN service providers, virtual asset service providers, exchange providers, custodian wallet providers and virtual private server providers as explicitly in scope. "Intermediary" here takes its IT Act 2000 meaning: any person who on behalf of another person receives, stores or transmits an electronic record or provides any service with respect to it. That catches internet service providers, telecom service providers, search engines, online marketplaces, payment gateways, social media platforms and cyber cafes.

Intermediaries under the Intermediary Guidelines Rules, 2021 have a wider reporting duty. Under FAQ Q10, they are expected to report incidents based on nature, severity and impact, not only the twenty types listed in Annexure I [L3-C3].

Foreign entities and Indian users

FAQ Q26 addresses the extraterritorial reach. The Directions apply to any entity that operates in India, including foreign firms serving Indian users. A foreign SaaS company that has no physical office in India but has paying customers in India is expected to designate a Point of Contact and comply with the reporting duty [L3-C4].

This mirrors, on a smaller scale, the extraterritorial application of the DPDP Act. But note the difference: the DPDP Act reaches foreign processing "in connection with offering of goods or services to Data Principals within the territory of India". The CERT-In Directions do not use that precise phrasing. Instead, the FAQ treats "operating in India" as broad enough to catch any entity that provides service into India, whether the customers are consumers, businesses or Government.

The multi-party trap

FAQ Q13 is the sleeper. It says the reporting obligation is not transferable by contract. Every entity that notices an incident is independently obliged to report to CERT-In. So if a data centre and its tenant both notice the same DDoS attack, both must report. If a SaaS company and its cloud provider both notice the same data leak, both must report. A common contract clause that says "the cloud provider will report" does not discharge the SaaS company's own duty. The clause is not, on its own, illegal, but it does not protect the primary entity [L3-C5].

MSMEs got a one-time extension

The Directions were originally to become effective on the 27th of June, 2022. On the same day, CERT-In extended the effective date to the 25th of September, 2022 for two limited things: MSMEs classified under MoMSME S.O. 1702(E) of 1 June 2020, and the subscriber-name and address-validation obligations under Direction (v)(a) and (v)(f) applicable to DC, VPS, Cloud and VPN service providers [L3-C6]. All other obligations became effective on the 27th of June, 2022 as originally notified. Since the 25th of September, 2022, MSMEs are within the Directions on the same footing as any other body corporate.

A practical checklist

Run through these questions. If you answer yes to any of the first six, you are within the Directions:

  1. Do you operate any company, firm, LLP, sole proprietorship or association in India that carries out commercial or professional activity?
  2. Are you a Government organisation of any tier?
  3. Do you run a data centre or offer cloud, VPS or VPN Service to Indian subscribers?
  4. Do you operate a virtual asset exchange, VASP or custodian wallet for Indian users?
  5. Are you a telecommunications service provider, ISP or intermediary under the IT Rules 2021?
  6. Are you a foreign entity that provides any digital service to users in India?
  7. Are you an individual using digital services purely for personal purposes? If yes, only then are you outside the reporting duty.

Almost every organisation you can think of answers yes to at least one of the first six.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (18 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
CERT-In FAQ May 2022, Q25 ("Body corporate" definition per Section 43A) L3-C1
Body corporate here has the meaning given in the explanation to Section 43A of the IT Act 2000: any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. Sole proprietors are therefore in scope.
CERT-In FAQ May 2022, Q7 (Scope: who the Directions apply to) L3-C2
The Directions apply to service providers, intermediaries, data centres, body corporates and Government organisations. Cloud service providers, VPN service providers, virtual asset service providers, exchange providers, custodian wallet providers, and virtual private server providers are included by name. Individual citizens are not in scope for the reporting duty.
CERT-In FAQ May 2022, Q10 (Intermediaries under IT Rules 2021) L3-C3
Intermediaries under the IT Rules 2021 have a wider reporting duty. They are expected to report any incident based on nature, severity, and impact, and are not limited to the twenty categories in Annexure I.
CERT-In FAQ May 2022, Q26 (Extraterritorial reach on foreign firms) L3-C4
The Directions apply to any entity that operates in India, including foreign firms serving Indian users. Foreign entities without a physical India presence are still expected to designate a Point of Contact.
CERT-In FAQ May 2022, Q13 (Multi-party incident: reporting duty is not transferable) L3-C5
When an incident affects multiple entities, each entity that notices the incident is independently obliged to report to CERT-In. The obligation cannot be transferred, indemnified or contracted away. A common contract clause that says "our vendor will report" does not discharge the primary entity.
CERT-In Extension 2022, Extension Order (Partial extension for MSMEs and Direction (v)(a) & (v)(f)) L3-C6
Effective date pushed from 27 June 2022 to 25 September 2022 for MSMEs classified under MoMSME S.O. 1702(E) dated 1 June 2020, and for the subscriber-name and address-validation obligations under Direction (v)(a) and (v)(f) applicable to Data Centre, VPS, Cloud and VPN service providers. All other obligations became effective on 27 June 2022 as originally notified.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Law Itself
Module 2: The 6-Hour Rule
  • Direction (ii) and when the clock actually starts
  • Annexure I: the twenty incident types you must report
  • Reporting channels, the incident form, and what to include
  • Building an internal 6-hour SLA
Module 3: Log Retention, 180 Days, in India
  • Direction (iv) and what counts as an ICT log
  • FAQ Q35: offshore storage and the producible-on-demand carve-out
  • FAQ Q38: only Deputy Secretary may requisition, and when to say no
Module 4: VPN, VPS, Cloud, VDR and Crypto KYC
  • Direction (v) and the seven KYC fields
  • FAQ Q34: enterprise VPNs are NOT covered
  • Direction (vi): VASPs, and how to reconcile 5-year KYC with DPDP minimisation
Module 5: NTP Time-Sync
  • Why time-sync is the foundation of every incident report
  • Configuring NTP against NIC and NPL
Module 6: Incident Response Playbook
  • The detect, triage, report, contain, review cycle
  • Coordinating with CERT-In after the initial report
  • Empanelled auditors and independent VAPT
Module 7: DPDP + CERT-In Together
  • DPDP Rule 7 alongside the CERT-In 6-hour clock
  • The parallel clocks runbook: seven destinations, one incident
  • Sectoral overlays: RBI, SEBI, IRDAI, DoT and UIDAI
Module 8: Final Exam and Certificate