Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this CERT-In Directions Practitioner Certification register is built
This trust page is the citation register for the CERT-In Directions Practitioner Certification course. It cites 35 authorities across 12 statutory instruments, drawn from the legal basis snapshot above (CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016).
Primary sources: CERT-In FAQ May 2022 (13 entries), CERT-In Directions 2022 (8 entries), IT Act 2000 (4 entries).
Every claim in every CERT-In Directions Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
Regulation 26 , Immediate notification to UIDAI on breach 14 Sep 2016
Annexure I , Types of cyber security incidents mandatorily to be reported by service providers, intermediaries, data centres, body corporate and Government organisations to CERT-In 28 Apr 2022
Direction (i) , NTP time synchronisation 28 Apr 2022
Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Direction (iii) , Information on demand and Point of Contact 28 Apr 2022
Direction (iv) , 180-day log retention within Indian jurisdiction 28 Apr 2022
Direction (v) , Five-year KYC for Data Centre, VPS, Cloud and VPN service providers 28 Apr 2022
Direction (vi) , Five-year KYC and transaction records for virtual asset service providers 28 Apr 2022
Preamble , Instrument, authority, coverage 28 Apr 2022
Extension Order , Partial extension for MSMEs and Direction (v)(a) & (v)(f) 27 Jun 2022
Q10 , Intermediaries under IT Rules 2021 18 May 2022
Q13 , Multi-party incident: reporting duty is not transferable 18 May 2022
Q22 , NDAs do not override the reporting duty 18 May 2022
Q24 , The 6-hour clock runs from awareness 18 May 2022
Q25 , "Body corporate" definition per Section 43A 18 May 2022
Q26 , Extraterritorial reach on foreign firms 18 May 2022
Q3 , Definition of cyber security incident (suspected counts) 18 May 2022
Q30 , Partial reporting at 6 hours is acceptable 18 May 2022
Q34 , Enterprise and corporate VPNs are NOT covered 18 May 2022
Q35 , Log storage location 18 May 2022
Q37 , Types of logs to be maintained 18 May 2022
Q38 , Only Deputy Secretary and above may requisition logs 18 May 2022
Q7 , Scope: who the Directions apply to 18 May 2022
Section 2(u) , Definition of personal data breach
Schedule , Penalty ceilings 11 Aug 2023
Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Incident reporting , IRDAI cyber incident reporting to CERT-In and IRDAI 24 Apr 2023
Section 70B(1) , Constitution of CERT-In
Section 70B(4) , Functions of CERT-In
Section 70B(6) , Power to call for information and give directions
Section 70B(7) , Penalty for non-compliance
Schedule item on IT Act 70B(7) , Fine ceiling under Sec. 70B(7) raised from one lakh to one crore rupees
Chapter VII , Cyber incident reporting and RCA 07 Nov 2023
Incident Reporting , 6-hour incident reporting to SEBI + CERT-In 20 Aug 2024
Incident reporting , Telecom Cyber Security Rules 2024 — 6-hour + 24-hour follow-up 21 Nov 2024
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.