The CERT-In 6-hour clock, actually managed.
Incident detection, 6-hour reporting workflow, 180-day log retention, mandatory fields, audit trail. From the moment an incident is logged, the clock and the format handle themselves. dcomply covers all 20 reportable incident categories from the April 2022 Directions, timestamps the noticing moment into an immutable audit record, and produces the CERT-In-ready submission email in the exact format inspectors expect.
If any of this sounds familiar, you're in the right place.
These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.
You've never actually filed a CERT-In incident and you're not sure who does it when it happens.
Your log retention is "whatever the SIEM keeps" and you don't know if it's 180 days.
The mandatory fields in the CERT-In format are in an old email chain.
Your incident response runbook is a Word document from 2021.
If you're RBI-regulated, the RBI door pairs CERT-In with the Cybersecurity Framework. If you're a fintech, the Fintech door covers the full stack.
Here's what sits above the foundation.
The CERT-In Directions do not stand alone. They interact with sector-specific incident reporting (RBI, SEBI), DPDP breach obligations, and the IT Act itself. dcomply ships modules for each layer.
CERT-In Directions 2022 Have Strict Penalties
Every organisation with a digital presence in India must comply, penalties reach ₹1 lakh per day for non-reporting. Most companies have no system to meet the 6-hour deadline.
6-Hour Deadline Missed
Without a dedicated system, by the time an incident is escalated, classified, and reported, the 6-hour window has already closed
ICT Logs Not Maintained
180-day log retention across all ICT systems, servers, network devices, cloud, is mandatory. Most companies lack centralised log management
CERT-In Queries Unanswered
CERT-In may query your organisation about incidents or vulnerabilities, no designated contact or response process creates regulatory risk
Everything You Need for CERT-In Compliance
Reportable Incident Tracking (20 Categories)
All 20 CERT-In reportable incident categories pre-configured, targeted scanning, malware, ransomware, data breach, DDoS, spoofing, and more, with classification guidance.
6-Hour Countdown Timer for Notification
Automated countdown timer triggered on incident classification, escalation alerts at 2h, 4h, and 5h remaining, with CERT-In notification report pre-filled from incident data.
ICT Log Retention Compliance (180 Days)
Policy checker confirming 180-day retention configuration across system types, servers, network devices, applications, and cloud, with evidence records for audit.
CERT-In Query Response Workflow
Designated contact management, query receipt tracking, response drafting workflow, and response submission records for all CERT-In communications and advisories.
Vulnerability Disclosure Tracking
Track discovered vulnerabilities, CERT-In coordination obligations for critical vulnerabilities, responsible disclosure timelines, and patch deployment records.
NTP Synchronisation Verification
Verify and document NTP synchronisation for all ICT systems to Indian Standard Time, a mandatory CERT-In requirement for log integrity and incident timeline accuracy.
CERT-In Direction Compliance Tracker
Track compliance against each specific CERT-In Direction, implementation status, evidence uploaded, responsible owner, and last verified date across all mandatory controls.
Penetration Testing Records
Maintain mandatory pentest records, schedule, scope, vendor, findings, remediation status, and re-test results, meeting CERT-In requirements for periodic security testing documentation.
Full CERT-In Compliance Coverage
All CERT-In Directions 2022 obligations mapped to operational controls with automation, evidence, and audit trail.
20 reportable incident categories
Pre-mapped incident types with classification guidance, severity assessment, and automatic 6-hour clock trigger on classification.
Automated 6h deadline alerts
Multi-channel alerts (email, in-app) at configurable thresholds before the 6-hour reporting deadline, never miss a notification window.
Log retention policy checker
System-by-system log retention audit with 180-day compliance status, gap identification, and recommended remediation steps.
Incident report templates for CERT-In
Pre-built report templates matching CERT-In's required format, auto-populated from incident data with one-click submission preparation.
CISO contact details maintenance
Register CISO, CERT-In point of contact, and escalation chain, required for CERT-In Directions compliance and query response.
Penalty risk if non-compliant (up to ₹1 lakh/day)
Compliance risk dashboard showing penalty exposure for each open obligation, quantified risk drives urgency and prioritisation.
Questions CISOs actually ask.
"Nobody was hunting for the format at 2 AM."
"We had one incident in the last twelve months. The 6-hour filing happened on time because the workflow ran it. Nobody was hunting for the format at 2 AM."
Track CERT-In Compliance
Never miss the 6-hour reporting deadline, automated countdown, alerts, and report templates built in