CERT-In door. 6-hour clock. 180-day logs.

The CERT-In 6-hour clock, actually managed.

Incident detection, 6-hour reporting workflow, 180-day log retention, mandatory fields, audit trail. From the moment an incident is logged, the clock and the format handle themselves. dcomply covers all 20 reportable incident categories from the April 2022 Directions, timestamps the noticing moment into an immutable audit record, and produces the CERT-In-ready submission email in the exact format inspectors expect.

⚠ Reportable incident: 1 open (3h elapsed)
6h deadline: 3h remaining
✓ Log retention: Configured (180 days)
✓ Sync with NTP: Verified
Last assessed: Today
Real-time CERT-In compliance posture dashboard
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

You've never actually filed a CERT-In incident and you're not sure who does it when it happens.

Your log retention is "whatever the SIEM keeps" and you don't know if it's 180 days.

The mandatory fields in the CERT-In format are in an old email chain.

Your incident response runbook is a Word document from 2021.

If you're RBI-regulated, the RBI door pairs CERT-In with the Cybersecurity Framework. If you're a fintech, the Fintech door covers the full stack.

Your regulator stack

Here's what sits above the foundation.

The CERT-In Directions do not stand alone. They interact with sector-specific incident reporting (RBI, SEBI), DPDP breach obligations, and the IT Act itself. dcomply ships modules for each layer.

SEBI CSCRF (if listed / market intermediary)
Parallel 6-hour SEBI incident report, VAPT scheduling, CISO evidence.
RBI Cybersecurity Framework (if regulated)
Parallel 2 to 6-hour RBI incident report, CSF control evidence, board pack.
DPDP Act 2023 breach notification
72-hour DPBI notification if personal data was affected. Same event, different clock.
IT Act 2000, Section 70B(6)
The statutory basis for CERT-In authority. Penalties under 70B(7) for non-reporting.
CERT-In Directions April 2022
The foundation. 6-hour reporting for 20 incident categories, 180-day log retention in India, VPN/cloud KYC 5-year records.
The Problem

CERT-In Directions 2022 Have Strict Penalties

Every organisation with a digital presence in India must comply, penalties reach ₹1 lakh per day for non-reporting. Most companies have no system to meet the 6-hour deadline.

6-Hour Deadline Missed

Without a dedicated system, by the time an incident is escalated, classified, and reported, the 6-hour window has already closed

ICT Logs Not Maintained

180-day log retention across all ICT systems, servers, network devices, cloud, is mandatory. Most companies lack centralised log management

CERT-In Queries Unanswered

CERT-In may query your organisation about incidents or vulnerabilities, no designated contact or response process creates regulatory risk

Capabilities

Everything You Need for CERT-In Compliance

Reportable Incident Tracking (20 Categories)

All 20 CERT-In reportable incident categories pre-configured, targeted scanning, malware, ransomware, data breach, DDoS, spoofing, and more, with classification guidance.

6-Hour Countdown Timer for Notification

Automated countdown timer triggered on incident classification, escalation alerts at 2h, 4h, and 5h remaining, with CERT-In notification report pre-filled from incident data.

ICT Log Retention Compliance (180 Days)

Policy checker confirming 180-day retention configuration across system types, servers, network devices, applications, and cloud, with evidence records for audit.

CERT-In Query Response Workflow

Designated contact management, query receipt tracking, response drafting workflow, and response submission records for all CERT-In communications and advisories.

Vulnerability Disclosure Tracking

Track discovered vulnerabilities, CERT-In coordination obligations for critical vulnerabilities, responsible disclosure timelines, and patch deployment records.

NTP Synchronisation Verification

Verify and document NTP synchronisation for all ICT systems to Indian Standard Time, a mandatory CERT-In requirement for log integrity and incident timeline accuracy.

CERT-In Direction Compliance Tracker

Track compliance against each specific CERT-In Direction, implementation status, evidence uploaded, responsible owner, and last verified date across all mandatory controls.

Penetration Testing Records

Maintain mandatory pentest records, schedule, scope, vendor, findings, remediation status, and re-test results, meeting CERT-In requirements for periodic security testing documentation.

What's Included

Full CERT-In Compliance Coverage

All CERT-In Directions 2022 obligations mapped to operational controls with automation, evidence, and audit trail.

20 reportable incident categories

Pre-mapped incident types with classification guidance, severity assessment, and automatic 6-hour clock trigger on classification.

Automated 6h deadline alerts

Multi-channel alerts (email, in-app) at configurable thresholds before the 6-hour reporting deadline, never miss a notification window.

Log retention policy checker

System-by-system log retention audit with 180-day compliance status, gap identification, and recommended remediation steps.

Incident report templates for CERT-In

Pre-built report templates matching CERT-In's required format, auto-populated from incident data with one-click submission preparation.

CISO contact details maintenance

Register CISO, CERT-In point of contact, and escalation chain, required for CERT-In Directions compliance and query response.

Penalty risk if non-compliant (up to ₹1 lakh/day)

Compliance risk dashboard showing penalty exposure for each open obligation, quantified risk drives urgency and prioritisation.

CERT-In compliance FAQs

Questions CISOs actually ask.

The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for responding to computer security incidents. Its April 2022 direction under IT Act Section 70B(6) requires all service providers, intermediaries, data centres, body corporates and government organisations to report specified cyber incidents to CERT-In within 6 hours of noticing them, maintain ICT logs for 180 days, and enable KYC-based user record retention where applicable.

20 categories in the annexure include: targeted scanning, compromise of critical systems, unauthorised access, network probes, DoS/DDoS, data leaks, defacement, malicious code, ransomware, attacks on IoT and OT, attacks on cryptocurrency systems, phishing, attacks on mobile networks, C2 traffic, supply chain compromises, and unauthorised access to social media accounts.

The 6-hour clock starts when the entity "notices" the incident, which CERT-In has clarified means the first credible indication (a triggered alert, a user report, a detection). Not from breach occurrence, and not from full investigation completion. dcomply timestamps the noticing moment and locks it into an immutable audit record.

All ICT system logs must be maintained securely within India for a rolling 180 days and made available to CERT-In on request. This applies even where the ICT system is hosted abroad. Logs must be shipped to India for retention. dcomply's evidence locker stores logs in India (Mumbai/Hyderabad AWS regions) and enforces the 180-day retention.

Yes. The direction requires VPN service providers, cloud providers and data centres to maintain 5-year records of subscriber KYC plus purpose plus IP allocations plus payment records. Several international VPN providers withdrew Indian servers in 2022 rather than comply. Indian entities using such services must reassess.

Failure to report or maintain logs can attract imprisonment up to 1 year or fine up to ₹1 lakh (or both) under IT Act Section 70B(7). Beyond the statutory penalty, CERT-In actively lists non-compliant entities and coordinates with sectoral regulators (RBI, SEBI, IRDAI) for follow-on enforcement.

If you're a service provider, intermediary, data centre, body corporate, or government organisation in India, yes. Practically, most Indian businesses over a certain size.

CERT-In's April 2022 Directions specify categories including unauthorised access, data breach, ransomware, and more. The module includes the classification workflow.

The module tracks source system retention settings and flags shortfall against the CERT-In minimum.

File as soon as possible and document the reason for delay. The module still produces the audit trail. Under-reporting or non-reporting invites regulator action.

Log retention integrations are available for major SIEM platforms. Incident logging is a manual step by design. CERT-In requires human classification.
Real teams, real programmes

"Nobody was hunting for the format at 2 AM."

"We had one incident in the last twelve months. The 6-hour filing happened on time because the workflow ran it. Nobody was hunting for the format at 2 AM."
CISO, a fintech.

Track CERT-In Compliance

Never miss the 6-hour reporting deadline, automated countdown, alerts, and report templates built in

View All Features