The applicability text at the top of the Directions is short: "service providers, intermediaries, data centres, body corporate and Government organisations". Read casually, that reads like a list of technology companies. Read carefully, it catches almost every business in India.
What "body corporate" means here
The term takes its meaning from the explanation to Section 43A of the IT Act 2000. FAQ Q25 confirms this: body corporate means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities [L3-C1]. So the term does not just mean a listed company or a PLC. It catches a partnership firm running a chartered accountancy practice, a sole proprietor running an e-commerce store, and a two-founder LLP running a SaaS product.
The one clean exclusion from FAQ Q7 is the individual citizen. If you are simply an individual using digital services in India, the Directions do not impose reporting obligations on you. If you run any commercial activity through a business form, they do [L3-C2].
What "service provider" and "intermediary" cover
The FAQ lists cloud service providers, VPN service providers, virtual asset service providers, exchange providers, custodian wallet providers and virtual private server providers as explicitly in scope. "Intermediary" here takes its IT Act 2000 meaning: any person who on behalf of another person receives, stores or transmits an electronic record or provides any service with respect to it. That catches internet service providers, telecom service providers, search engines, online marketplaces, payment gateways, social media platforms and cyber cafes.
Intermediaries under the Intermediary Guidelines Rules, 2021 have a wider reporting duty. Under FAQ Q10, they are expected to report incidents based on nature, severity and impact, not only the twenty types listed in Annexure I [L3-C3].
Foreign entities and Indian users
FAQ Q26 addresses the extraterritorial reach. The Directions apply to any entity that operates in India, including foreign firms serving Indian users. A foreign SaaS company that has no physical office in India but has paying customers in India is expected to designate a Point of Contact and comply with the reporting duty [L3-C4].
This mirrors, on a smaller scale, the extraterritorial application of the DPDP Act. But note the difference: the DPDP Act reaches foreign processing "in connection with offering of goods or services to Data Principals within the territory of India". The CERT-In Directions do not use that precise phrasing. Instead, the FAQ treats "operating in India" as broad enough to catch any entity that provides service into India, whether the customers are consumers, businesses or Government.
The multi-party trap
FAQ Q13 is the sleeper. It says the reporting obligation is not transferable by contract. Every entity that notices an incident is independently obliged to report to CERT-In. So if a data centre and its tenant both notice the same DDoS attack, both must report. If a SaaS company and its cloud provider both notice the same data leak, both must report. A common contract clause that says "the cloud provider will report" does not discharge the SaaS company's own duty. The clause is not, on its own, illegal, but it does not protect the primary entity [L3-C5].
MSMEs got a one-time extension
The Directions were originally to become effective on the 27th of June, 2022. On the same day, CERT-In extended the effective date to the 25th of September, 2022 for two limited things: MSMEs classified under MoMSME S.O. 1702(E) of 1 June 2020, and the subscriber-name and address-validation obligations under Direction (v)(a) and (v)(f) applicable to DC, VPS, Cloud and VPN service providers [L3-C6]. All other obligations became effective on the 27th of June, 2022 as originally notified. Since the 25th of September, 2022, MSMEs are within the Directions on the same footing as any other body corporate.
A practical checklist
Run through these questions. If you answer yes to any of the first six, you are within the Directions:
- Do you operate any company, firm, LLP, sole proprietorship or association in India that carries out commercial or professional activity?
- Are you a Government organisation of any tier?
- Do you run a data centre or offer cloud, VPS or VPN Service to Indian subscribers?
- Do you operate a virtual asset exchange, VASP or custodian wallet for Indian users?
- Are you a telecommunications service provider, ISP or intermediary under the IT Rules 2021?
- Are you a foreign entity that provides any digital service to users in India?
- Are you an individual using digital services purely for personal purposes? If yes, only then are you outside the reporting duty.
Almost every organisation you can think of answers yes to at least one of the first six.