Pentapod
Insights/Security

CERT-In readiness: what is required, and what is only recommended

CERT-In's 2022 Directions bind most Indian organisations, from hospitals to MSMEs. The four core obligations, how the 2025 MSME controls fit in, and a five-step readiness plan.

Pentapod · 14 September 2026 · 8 min read

Who the Directions apply to

On 28 April 2022, CERT-In issued Directions under section 70B(6) of the Information Technology Act, 2000. They apply to service providers, intermediaries, data centres, body corporates and government organisations. CERT-In's FAQs explain that "body corporate" follows the IT Act's meaning, which includes a company, a firm or a sole proprietorship — so private hospitals, manufacturers and most MSMEs are covered. Individual citizens are not.

The Directions took effect 60 days after issue. For MSMEs, CERT-In extended the date to 25 September 2022.

The four core obligations

  1. 01

    Report incidents within six hours

    Annexure I lists 20 types of incident, including targeted scanning, unauthorised access, website defacement, ransomware and other malware, denial-of-service attacks, data breaches and leaks, phishing, and attacks on IoT, cloud and AI systems. The six hours run from noticing the incident or being told about it. Reports go to incident@cert-in.org.in or 1800-11-4949. The FAQs allow a first report with partial information; this duty cannot be contracted out, and it overrides confidentiality clauses.

  2. 02

    Keep logs for 180 days

    Enable logs on all ICT systems and keep them for a rolling 180 days within Indian jurisdiction, ready to share with CERT-In with an incident report or on request. The FAQs clarify that logs may be stored outside India if they can be produced within a reasonable time, but service providers offering services to users in India are expected to keep them within Indian jurisdiction.

  3. 03

    Synchronise clocks

    Connect systems to the NTP servers of the National Informatics Centre or the National Physical Laboratory, or to sources traceable to them, so timestamps line up during an investigation. Clocks do not have to be set to IST, and cloud customers may use their provider's time service.

  4. 04

    Name a Point of Contact

    Designate a Point of Contact and send their details to CERT-In at info@cert-in.org.in in the Annexure II format.

Some organisations carry extra duties. Data centres and VPS, cloud and VPN service providers must keep validated subscriber records for five years after a service ends — a requirement the FAQs say does not apply to an enterprise's own corporate VPN. Virtual asset service providers must keep KYC and transaction records for five years.

Penalties

Failing to comply can be punished under section 70B(7) of the IT Act with imprisonment of up to one year, a fine of up to ₹1 lakh, or both. CERT-In's FAQs say this power will be used reasonably, where non-compliance is deliberate. A serious breach can also bring separate consequences under the Digital Personal Data Protection Act once its penalties apply from May 2027.

The 2025 controls for MSMEs

On 1 September 2025, CERT-In published "15 Elemental Cyber Defense Controls for Micro, Small, and Medium Enterprises" (reference CISG-2025-03). It maps 15 controls to 45 baseline recommendations. The language is advisory: MSMEs "may use" the recommendations for self-assessment, and "may conduct" baseline audits through CERT-In empanelled auditors at least once a year. Two controls restate duties that are already binding — six-hour incident reporting and 180-day log retention.

  • Asset management, secure configurations and patch management.
  • Network and email security (including SPF, DKIM and DMARC), and endpoint and mobile security.
  • Passwords with multi-factor authentication, and access control reviewed at least quarterly.
  • Logging and monitoring, incident management, and data protection with backups and recovery.
  • Awareness training at least twice a year, third-party risk, physical security, governance, and an independent vulnerability assessment at least yearly.

Government organisations

Central government bodies have more to do. CERT-In's June 2023 Guidelines on Information Security Practices for Government Entities cover ministries, departments, their attached offices and public sector undertakings. They call for internal audits at least every six months and third-party audits at least yearly, and require applications and websites to be audited by CERT-In empanelled auditors before hosting, at least once a year and after major changes. The guidelines do not name state government bodies.

CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (July 2025) set how empanelled auditors and the organisations they audit must conduct audits. They do not, by themselves, require every private organisation to be audited. CERT-In had 231 empanelled auditing organisations as of early 2026.

Readiness in five steps

  1. 01

    Register your Point of Contact

    Send the Annexure II details to CERT-In, save the reporting form and contacts, and decide who makes the call to report in the first hour.

  2. 02

    Switch on and protect logs

    Collect logs from servers, network devices, firewalls, applications and cloud services in one place, protect them from tampering, and keep 180 days. Plan for one year, which the DPDP Rules require from May 2027.

  3. 03

    Synchronise every clock

    Point servers, network devices and applications at NIC or NPL time sources, and check that they stay in sync.

  4. 04

    Rehearse the six hours

    Run a tabletop exercise — a ransomware attack at 2 a.m. is a good one. Practise a partial first report, and combine it with your data breach process so one incident does not need two separate scrambles.

  5. 05

    Baseline against the 15 controls

    Even where they are optional, the MSME controls are a sound checklist. Close the gaps that matter most — multi-factor authentication, patching, backups and email security — and arrange a formal audit through an empanelled auditor wherever a rule or a customer requires one.

Pentapod is not a CERT-In empanelled auditing organisation. We help organisations prepare and fix gaps; where a formal audit is required, it must be carried out by an empanelled organisation. CERT-In does not certify organisations, so be wary of anyone offering to make you "CERT-In certified".

This article is general information, not legal advice. Rules change — check the official sources below before acting.

Sources
  1. 01CERT-In: Directions under section 70B(6), 28 April 2022
  2. 02CERT-In: FAQs on the Cyber Security Directions (May 2022)
  3. 03CERT-In: Extension of timelines for MSMEs, 27 June 2022
  4. 04CERT-In: 15 Elemental Cyber Defense Controls for MSMEs, v1.0 (September 2025)
  5. 05CERT-In: Guidelines on Information Security Practices for Government Entities (June 2023)
  6. 06CERT-In: Comprehensive Cyber Security Audit Policy Guidelines (July 2025)
  7. 07PIB: Cyber security measures and empanelled auditors (January 2026)
  8. 08CERT-In: List of empanelled information security auditing organisations
  9. 09MeitY: Digital Personal Data Protection Rules, 2025
Work with us

Have a project in mind?

Tell us what you need to build, connect or protect. We'll come back with honest next steps.

Start a project