Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016

How this CERT-In Directions Practitioner Certification register is built

This trust page is the citation register for the CERT-In Directions Practitioner Certification course. It cites 35 authorities across 12 statutory instruments, drawn from the legal basis snapshot above (CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, extension dated 27 June 2022, May 2022 FAQ, Section 70B IT Act 2000 as amended by Jan Vishwas Act 2023, DPDP Act 2023 (No. 22 of 2023), DPDP Rules 2025 (notified 13 November 2025), RBI Master Direction on IT Governance (Nov 2023), SEBI CSCRF (20 August 2024), IRDAI Cyber Security Guidelines 2023, Telecom Cyber Security Rules 2024 (21 November 2024), Aadhaar Data Security Regulations 2016).

Primary sources: CERT-In FAQ May 2022 (13 entries), CERT-In Directions 2022 (8 entries), IT Act 2000 (4 entries).

Every claim in every CERT-In Directions Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
8
modules
22
lessons
35
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

Regulation 26 , Immediate notification to UIDAI on breach 14 Sep 2016
Plain summary: Under the Aadhaar (Data Security) Regulations 2016, an Authentication User Agency, e-KYC User Agency and Authentication Service Agency must notify UIDAI immediately of any breach that compromises identity information. There is no fixed hour clock. Practitioners treat this as within the shortest parallel clock, i.e. 6 hours.
The Authority shall be notified by the requesting entity of any breach of identity information or any breach of the applicable security controls, immediately upon becoming aware of such breach.

Annexure I , Types of cyber security incidents mandatorily to be reported by service providers, intermediaries, data centres, body corporate and Government organisations to CERT-In 28 Apr 2022
Plain summary: Annexure I lists 20 incident categories that trigger the 6-hour reporting clock, covering scanning, unauthorised access, defacement, malware, DDoS, phishing, breach, leak, IoT attacks, digital payment attacks, malicious mobile apps, cloud attacks, blockchain and virtual-asset attacks, and AI/ML attacks.
Types of cyber security incidents mandatorily to be reported by service providers, intermediaries, data centres, body corporate and Government organisations to CERT-In: i. Targeted scanning/probing of critical networks/systems ii. Compromise of critical systems/information iii. Unauthorised access of IT systems/data iv. Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc. v. Malicious code attacks such as spreading of Virus/Worm/Trojan/Bots/Spyware/Ransomware/Cryptominers vi. Attack on servers such as Database, Mail and DNS and network devices such as Routers vii. Identity Theft, spoofing and phishing attacks viii. Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks ix. Attacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks x. Attacks on Application such as E-Governance, E-Commerce etc. xi. Data Breach xii. Data Leak xiii. Attacks on Internet of Things (IoT) devices and associated systems, networks, software, servers xiv. Attacks or incident affecting Digital Payment systems xv. Attacks through Malicious mobile Apps xvi. Fake mobile Apps xvii. Unauthorised access to social media accounts xviii. Attacks or malicious/suspicious activities affecting Cloud computing systems/servers/software/applications xix. Attacks or malicious/suspicious activities affecting systems/servers/networks/software/applications related to Big Data, Block chain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones xx. Attacks or malicious/suspicious activities affecting systems/servers/software/applications related to Artificial Intelligence and Machine Learning
Direction (i) , NTP time synchronisation 28 Apr 2022
Plain summary: All in-scope entities must synchronise their ICT system clocks to the NIC or NPL Network Time Protocol servers, or to NTP servers traceable to these. Entities operating across multiple geographies may use other accurate standard time sources provided the time does not deviate from NIC and NPL.
All service providers, intermediaries, data centres, body corporate and Government organisations shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers, for synchronisation of all their ICT systems clocks. Entities having ICT infrastructure spanning multiple geographies may also use accurate and standard time source other than NPL and NIC, however it is to be ensured that their time source shall not deviate from NPL and NIC.
Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Plain summary: CERT-In Directions of 28 April 2022, Direction (ii): any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing. Runs in parallel with SEBI CSCRF 6-hour clock. Filing to one regulator does not satisfy the obligation to the other.
Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.
Direction (iii) , Information on demand and Point of Contact 28 Apr 2022
Plain summary: When CERT-In requires information, or orders an entity to take an action or extend assistance, the entity must comply in the specified format and timeframe. Every entity must designate a Point of Contact to interface with CERT-In and submit the PoC in the format at Annexure II to [email protected].
When required by order/direction of CERT-In, for the purposes of cyber incident response, protective and preventive actions related to cyber incidents, the service provider/intermediary/data centre/body corporate is mandated to take action or provide information or any such assistance to CERT-In, which may contribute towards cyber security mitigation actions and enhanced cyber security situational awareness. The order/direction may include the format of the information that is required (up to and including near real-time), and a specified timeframe. Compliance to such orders/directions is mandatory for the mentioned entities. The entities shall designate a Point of Contact to interface with CERT-In. The information relating to a Point of Contact shall be sent to CERT-In in the format specified at Annexure II and shall be updated from time to time. All communications from CERT-In seeking information and providing directions for compliance shall be sent to the said Point of Contact.
Direction (iv) , 180-day log retention within Indian jurisdiction 28 Apr 2022
Plain summary: All in-scope entities must enable logs of all ICT systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. Logs must be provided to CERT-In along with any incident report or on direction. FAQ Q35 clarifies that offshore storage is acceptable if logs can be produced to CERT-In in a reasonable time.
All service providers, intermediaries, data centres, body corporate and Government organisations shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction. These should be provided to CERT-In along with reporting of any incident or when ordered / directed by CERT-In.
Direction (v) , Five-year KYC for Data Centre, VPS, Cloud and VPN service providers 28 Apr 2022
Plain summary: Data Centres, Virtual Private Server providers, Cloud Service providers and VPN Service providers must register and retain seven categories of customer information for a period of 5 years or longer, after cancellation or withdrawal of registration by the customer.
Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers, shall be required to register the following accurate information which must be maintained by them for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration as the case may be:, (a) Validated names of subscribers/customers hiring the services; (b) Period of hire including dates; (c) IPs allotted to / being used by the members; (d) Email address and IP address and time stamp used at the time of registration / on-boarding; (e) Purpose for hiring services; (f) Validated address and contact numbers; (g) Ownership pattern of the subscribers / customers hiring services.
Direction (vi) , Five-year KYC and transaction records for virtual asset service providers 28 Apr 2022
Plain summary: Virtual Asset Service Providers, virtual asset exchange providers and custodian wallet providers must retain all information obtained during KYC and records of financial transactions for 5 years so as to reconstruct individual transactions along with the relevant elements: identities of parties, IP addresses, timestamps, transaction IDs, public keys / addresses, nature and date of transaction, and amount transferred.
The virtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by Ministry of Finance from time to time) shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of five years so as to ensure cyber security in the area of payments and financial markets for citizens while protecting their data, fundamental rights and economic freedom in view of the growth of virtual assets. For the purpose of KYC, the Reserve Bank of India (RBI) directed / regulated KYC norms for entities regulated by RBI, SEBI directed / regulated KYC norms for entities regulated by SEBI, and Department of Telecommunication (DoT) approved / regulated KYC norms for entities registered with DoT, may be considered. In any other case, the norms specified in Annexure III shall be considered. With respect to transaction records, accurate information shall be maintained in such a way that individual transaction can be reconstructed along with the relevant elements comprising of, but not limited to, information relating to the identification of the relevant parties including IP addresses along with timestamps and time zones, transaction ID, the public keys (or equivalent identifiers), addresses or accounts involved (or equivalent identifiers), the nature and date of the transaction, and the amount transferred.
Preamble , Instrument, authority, coverage 28 Apr 2022
Plain summary: Directions No. 20(3)/2022-CERT-In dated 28 April 2022. Issued under Section 70B(6) of the IT Act 2000. Titled: Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet. Effective 60 days from issue, i.e. 27 June 2022.
No. 20(3)/2022-CERT-In dated the 28th April, 2022. Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet. These directions shall be effective after 60 days from the date on which they are issued.

Extension Order , Partial extension for MSMEs and Direction (v)(a) & (v)(f) 27 Jun 2022
Plain summary: Effective date pushed from 27 June 2022 to 25 September 2022 for MSMEs classified under MoMSME S.O. 1702(E) dated 1 June 2020, and for the subscriber-name and address-validation obligations under Direction (v)(a) and (v)(f) applicable to Data Centre, VPS, Cloud and VPN service providers. All other obligations became effective on 27 June 2022 as originally notified.
The Directions dated 28.04.2022 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet shall become effective from 25th September, 2022 in respect of, (i) Micro, Small and Medium Enterprises (MSMEs), as classified in the notification of the Government of India in the Ministry of Micro, Small and Medium Enterprises S.O. 1702(E) dated 01.06.2020; and (ii) validation of subscriber/customer details required in point (v) sub-para (a) and sub-para (f) of the Annexure to the Directions, applicable to Data Centres, VPS, Cloud Service providers and VPN Service providers.

Q10 , Intermediaries under IT Rules 2021 18 May 2022
Plain summary: Intermediaries under the IT Rules 2021 have a wider reporting duty. They are expected to report any incident based on nature, severity, and impact, and are not limited to the twenty categories in Annexure I.
Intermediaries covered under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 are already required to report cyber security incidents. They are expected to consider nature, severity and impact of the incident while reporting cyber security incidents to CERT-In.
Q13 , Multi-party incident: reporting duty is not transferable 18 May 2022
Plain summary: When an incident affects multiple entities, each entity that notices the incident is independently obliged to report to CERT-In. The obligation cannot be transferred, indemnified or contracted away. A common contract clause that says "our vendor will report" does not discharge the primary entity.
The reporting obligation of any entity on noticing a cyber incident applies to that entity itself and is not transferable to any other entity by way of a contract. Every entity that has noticed a cyber incident is obligated to report it, irrespective of the fact that some other entity has also reported the same incident. This is because the obligation is a statutory obligation of every entity that notices an incident.
Q22 , NDAs do not override the reporting duty 18 May 2022
Plain summary: The reporting obligation overrides contractual non-disclosure by virtue of Section 81 of the IT Act 2000. Confidentiality contracts cannot be used to withhold information from CERT-In or to delay reporting.
Section 81 of Information Technology Act, 2000 states that the provisions of this Act shall have effect notwithstanding anything inconsistent therewith contained in any other law for the time being in force. Therefore, non-disclosure agreements shall not override the reporting obligation under these Directions.
Q24 , The 6-hour clock runs from awareness 18 May 2022
Plain summary: The 6-hour clock begins from the moment the entity notices the incident or is brought to notice about it. It does not begin from the moment the incident occurred. This matters when detection is delayed.
The time period of 6 hours for reporting cyber incidents to CERT-In shall be reckoned from the time of noticing the cyber incident or being brought to notice about such incidents.
Q25 , "Body corporate" definition per Section 43A 18 May 2022
Plain summary: Body corporate here has the meaning given in the explanation to Section 43A of the IT Act 2000: any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. Sole proprietors are therefore in scope.
The term "body corporate" has been defined in explanation (i) to sub-section (1) of section 43A of the Information Technology Act, 2000 as "any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities". The same definition applies for the Directions.
Q26 , Extraterritorial reach on foreign firms 18 May 2022
Plain summary: The Directions apply to any entity that operates in India, including foreign firms serving Indian users. Foreign entities without a physical India presence are still expected to designate a Point of Contact.
The Directions apply to all service providers, intermediaries, data centres, body corporates and Government organisations that provide services or operate in India, regardless of the jurisdiction of registration. Foreign entities that serve users in India are expected to designate a Point of Contact and comply with reporting.
Q3 , Definition of cyber security incident (suspected counts) 18 May 2022
Plain summary: A cyber security incident is any real or suspected adverse event, in relation to cyber security, that violates any explicitly or implicitly applicable security policy resulting in unauthorised access, denial or disruption of service, unauthorised use of a computer resource for processing or storage of information, or changes to data, information without authorisation. The phrase "suspected" is critical: an entity does not need a confirmed breach before the reporting duty is triggered.
Cyber security incident, in relation to cyber security, means any real or suspected adverse event that is likely to cause or causes an offence or contravention, harm to critical functions and services across the public and private sectors by impairing the confidentiality, integrity, or availability of electronic information, systems, services or networks resulting in unauthorized access, denial of service or disruption, unauthorized use of a computer resource for processing or storage of information or changes to data, information without authorization.
Q30 , Partial reporting at 6 hours is acceptable 18 May 2022
Plain summary: If complete information is not available at the 6-hour mark, entities may report the information available at the time and file additional information within a reasonable time later. The reporting duty is not held back by incomplete facts.
In case complete information is not available at the time of reporting a cyber incident, the entities may provide information to the extent available at the time of reporting. Additional information about the cyber incident may be reported to CERT-In in due course as and when it becomes available.
Q34 , Enterprise and corporate VPNs are NOT covered 18 May 2022
Plain summary: Direction (v) applies to VPN Service providers that provide Internet-proxy-like VPN services to general Internet subscribers. Enterprise or corporate VPNs used by a company internally are not within scope of the KYC and 5-year record retention obligations.
The Directions are meant for VPN Service providers who provide Internet proxy-like services through the use of VPN technologies, standard or proprietary, to general internet subscribers/users. The Directions do not apply to enterprise or corporate VPNs.
Q35 , Log storage location 18 May 2022
Plain summary: The 180-day log retention requirement under Direction (iv) reads "within the Indian jurisdiction". FAQ Q35 opens the door to offshore storage provided the entity can produce logs to CERT-In in a reasonable time. This is the softener a global CISO relies on.
The logs may be stored outside India also as long as the obligation to produce logs to CERT-In is adhered to by the entities in a reasonable time.
Q37 , Types of logs to be maintained 18 May 2022
Plain summary: Logs to be maintained include Firewall logs, IPS logs, SIEM logs, web/DB/mail/FTP/proxy server logs, event logs of critical systems, application logs, ATM switch logs, SSH logs, and VPN logs. Both successful and unsuccessful events must be recorded.
Logs to be maintained include, but are not limited to, Firewall logs, Intrusion Prevention Systems logs, SIEM logs, web/database/mail/FTP/proxy server logs, event logs of critical systems, application logs, ATM switch logs, SSH logs, VPN logs. Both successful as well as unsuccessful events shall be recorded.
Q38 , Only Deputy Secretary and above may requisition logs 18 May 2022
Plain summary: Logs can be requisitioned only by an officer of CERT-In not below the rank of Deputy Secretary. Requests received from officers of lower rank are not valid requisitions under the Directions.
The logs are to be provided to CERT-In only when directed by an officer of CERT-In not below the rank of Deputy Secretary or equivalent.
Q7 , Scope: who the Directions apply to 18 May 2022
Plain summary: The Directions apply to service providers, intermediaries, data centres, body corporates and Government organisations. Cloud service providers, VPN service providers, virtual asset service providers, exchange providers, custodian wallet providers, and virtual private server providers are included by name. Individual citizens are not in scope for the reporting duty.
These Directions cover service providers, intermediaries, data centres, body corporates and Government organisations, which includes both service providers and their users as legal entities except individual citizens.

Section 2(u) , Definition of personal data breach
Plain summary: Personal data breach means any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
Schedule , Penalty ceilings 11 Aug 2023
Plain summary: Item 1: Failure to take reasonable security safeguards under Section 8(5) — up to two hundred and fifty crore rupees. Item 2: Failure to give breach intimation under Section 8(6) — up to two hundred crore rupees. Item 3: Failure of children's data obligations under Section 9 — up to two hundred crore rupees. Item 4: Failure of SDF obligations under Section 10 — up to one hundred and fifty crore rupees. Item 5: Data Principal duty breach under Section 15 — up to ten thousand rupees. Item 7: Residual — any other breach of Act or Rules — up to fifty crore rupees.
Schedule (Section 33): Item 1 (Section 8(5) reasonable security safeguards): may extend to two hundred and fifty crore rupees. Item 2 (Section 8(6) breach intimation to Board and affected Data Principals): may extend to two hundred crore rupees. Item 3 (Section 9 additional obligations for children's personal data): may extend to two hundred crore rupees. Item 4 (Section 10 additional obligations for Significant Data Fiduciary): may extend to one hundred and fifty crore rupees. Item 5 (Section 15 duties of Data Principal): may extend to ten thousand rupees. Item 6 (breach of any term of voluntary undertaking accepted by Board under Section 32): may extend to the extent applicable for the relevant Item. Item 7 (any other breach of the provisions of this Act or rules): may extend to fifty crore rupees.

Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Plain summary: DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Rules 2025 Rule 7. On becoming aware of any personal data breach, the Data Fiduciary shall intimate each affected Data Principal in a concise, clear and plain manner and without delay; and shall intimate the Data Protection Board without delay of the initial description, followed by an updated and detailed report within seventy-two hours of becoming aware (extendable on written request to the Board).

Incident reporting , IRDAI cyber incident reporting to CERT-In and IRDAI 24 Apr 2023
Plain summary: The IRDAI Information and Cyber Security Guidelines, 2023 (notified 24 April 2023, full compliance from 1 April 2024) require insurers, reinsurers, intermediaries and insurance web aggregators to report cyber incidents to CERT-In within 6 hours and copy IRDAI. The clarificatory circular of 13 June 2023 confirmed this timeline.
Cyber incidents shall be reported to CERT-In within 6 hours of noticing/detecting the same in accordance with the CERT-In Directions dated 28 April 2022. A copy of every such report shall be furnished to the Authority.

Section 70B(1) , Constitution of CERT-In
Plain summary: Central Government constitutes the Indian Computer Emergency Response Team as the national agency for cyber security incident response.
70B. (1) The Central Government shall, by notification in the Official Gazette, appoint an agency of the Government to be called the Indian Computer Emergency Response Team.
Section 70B(4) , Functions of CERT-In
Plain summary: CERT-In collects and analyses cyber incident data, issues forecasts and alerts, coordinates response, issues guidelines and advisories, and performs other prescribed cyber-security functions.
70B. (4) The Indian Computer Emergency Response Team shall serve as the national agency for performing the following functions in the area of cyber security,, (a) collection, analysis and dissemination of information on cyber incidents; (b) forecast and alerts of cyber security incidents; (c) emergency measures for handling cyber security incidents; (d) coordination of cyber incidents response activities; (e) issue guidelines, advisories, vulnerability notes and whitepapers relating to information security practices, procedures, prevention, response and reporting of cyber incidents; (f) such other functions relating to cyber security as may be prescribed.
Section 70B(6) , Power to call for information and give directions
Plain summary: CERT-In may call for information and give directions to service providers, intermediaries, data centres, body corporates and any other person to carry out its functions. This is the authority under which the 28 April 2022 Directions were issued.
70B. (6) For carrying out the provisions of sub-section (4), the agency referred to in sub-section (1) may call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person.
Section 70B(7) , Penalty for non-compliance
Plain summary: Any service provider, intermediary, data centre, body corporate or person who fails to provide information called for or to comply with the direction issued under sub-section (6) is punishable with imprisonment up to one year and/or fine. The fine ceiling was raised from one lakh rupees to one crore rupees by the Jan Vishwas (Amendment of Provisions) Act, 2023.
70B. (7) Any service provider, intermediaries, data centres, body corporate or person who fails to provide the information called for or comply with the direction under sub-section (6), shall be punishable with imprisonment for a term which may extend to one year or with fine which may extend to one crore rupees or with both.

Schedule item on IT Act 70B(7) , Fine ceiling under Sec. 70B(7) raised from one lakh to one crore rupees
Plain summary: The Jan Vishwas (Amendment of Provisions) Act, 2023 (No. 18 of 2023) amended the penalty ceiling in Section 70B(7) of the IT Act 2000. The maximum fine for non-compliance with a CERT-In direction was raised from one lakh rupees to one crore rupees. Imprisonment ceiling remains one year. Practitioners should confirm the exact commencement date against the gazette on release day.
In section 70B of the Information Technology Act, 2000, in sub-section (7), for the words "one lakh rupees", the words "one crore rupees" shall be substituted.

Chapter VII , Cyber incident reporting and RCA 07 Nov 2023
Plain summary: Under the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023, effective 1 April 2024), regulated entities must proactively notify unusual cyber incidents to CERT-In and to the RBI as per applicable regulatory requirements. Root cause analysis and post-incident reports are to be filed within timelines set by the RBI, typically 21 days.
Regulated entities shall have in place a Board approved Incident Response and Recovery Plan and shall proactively notify unusual cyber security incidents to the CERT-In and to the Reserve Bank of India as per the regulatory requirements. Detailed root cause analysis and remediation report shall be submitted to the Reserve Bank of India as per the timelines specified by the Reserve Bank of India.

Incident Reporting , 6-hour incident reporting to SEBI + CERT-In 20 Aug 2024
Plain summary: Reportable cyber incidents must be reported to SEBI within 6 hours of detection, in alignment with the CERT-In Directions of 28 April 2022. Reporting is via the SEBI Incident Reporting portal. A parallel filing must be made to CERT-In under CERT-In's own format. Filing to one regulator does not satisfy the obligation to the other. Detection triggers the clock, not confirmation.
Cyber Incident Reporting: All SEBI Regulated Entities shall report cyber security incidents to SEBI within six hours of detection, aligned with the reporting timeline under the CERT-In Directions dated 28 April 2022. Reporting shall be via the SEBI Incident Reporting portal. A separate report shall be filed with CERT-In in the format prescribed by CERT-In. Detection of an incident, not confirmation, starts the six-hour clock.

Incident reporting , Telecom Cyber Security Rules 2024 — 6-hour + 24-hour follow-up 21 Nov 2024
Plain summary: Telecom Cyber Security Rules 2024 notified on 21 November 2024 under Section 22 of the Telecommunications Act 2023. Telecommunication entities must report cyber security incidents within 6 hours of awareness, with all relevant details within 24 hours. DoT may collect and analyse traffic data (containing personal data) for cyber security purposes with no explicit retention cap, creating an overlap tension with DPDP Section 8(7) erasure obligations.
A telecommunication entity shall report every cyber security incident affecting its telecommunication network or telecommunication service to the Central Government within six hours of becoming aware of it, followed by such other details as may be sought, within twenty-four hours of the report.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.