CERT-In 6-Hour Incident Reporting
The obligation to report specified cyber incidents to CERT-In within six hours of noticing them, imposed by the 28 April 2022 CERT-In Directions.
The 6-hour reporting SLA is imposed by paragraph (ii) of the CERT-In Directions dated 28 April 2022, issued under Section 70B(6) of the Information Technology Act 2000. Every service provider, intermediary, data centre, body corporate and government organisation in India must report specified cyber security incidents to CERT-In within six hours of noticing the incident or being brought to their notice about the incident.
The Annexure I to the Directions lists twenty-plus categories of reportable incidents including targeted scanning or probing of critical networks, compromise of critical systems, unauthorised access to IT systems and data, defacement of websites, malicious code attacks including ransomware, identity theft, spoofing and phishing attacks, DoS and DDoS attacks, data breach and data leak, and attacks or malicious code affecting IoT devices and applications.
Reports are made through the CERT-In portal or by email, using the templates published on the CERT-In website. The report includes the time of incident, incident description, IP addresses affected, systems affected, actions taken. In practice, running the 6-hour clock reliably requires log retention (paragraph iii of the Directions mandates 180 days of ICT system logs), NPL clock synchronisation (paragraph iv), and a rehearsed incident-response runbook — all of which the dcomply Academy CERT-In Directions Practitioner Certification walks through.