Infosek
INFOSEK

CERT-In 6-Hour Breach Reporting: A Plain-English Guide for Regulated Entities

CERT-In mandates reporting cybersecurity incidents within 6 hours of detection. This guide explains what qualifies as a reportable incident, how to report, and how to build your SOP before a breach happens.

CERT-In 6-Hour Breach Reporting: A Plain-English Guide for Regulated Entities

The CERT-In Direction of 2022: Background

In April 2022, CERT-In (the Indian Computer Emergency Response Team, operating under the Ministry of Electronics and Information Technology) issued a Direction under Section 70B(6) of the IT Act. This Direction imposed several significant obligations on Indian entities, of which the 6-hour incident reporting requirement is the most immediately operationally impactful. The Direction applies to all service providers, intermediaries, data centres, body corporates, and government organisations.

What Qualifies as a Reportable Incident?

CERT-In lists over 20 types of incidents that must be reported. These include (but are not limited to):

If you are uncertain whether an event qualifies, report it. The cost of over-reporting is administrative. The cost of under-reporting is regulatory.

How to Report: The Process

CERT-In provides multiple reporting channels:

Your report should include as much of the following as you can provide within the 6-hour window (you can submit a preliminary report and follow up with details):

Who Must Comply?

The CERT-In Direction applies universally to all entities in India, including:

There is no minimum size threshold. A two-person startup and a large bank are equally obligated to report qualifying incidents within 6 hours.

Common Mistakes That Lead to Non-Compliance

Building Your 6-Hour SOP

A 6-hour SOP for CERT-In incident reporting should cover the following stages:

A 6-hour clock starts the moment you detect an incident — not when you understand it. Build your SOP for speed, not thoroughness. You can always supplement with a follow-up report.

Infosek Team

Common questions

What is the CERT-In 6-hour reporting rule?

Under the CERT-In Directions of 2022, specified cyber incidents must be reported to CERT-In within six hours of noticing them or being brought to notice. The clock runs from awareness, not from completing an investigation.

Which incidents must be reported to CERT-In?

CERT-In lists over twenty categories, including targeted scanning or probing of critical networks, compromise of critical systems or information, unauthorised access to IT systems or data, website defacement or intrusion, and malicious code attacks such as ransomware.

Topics CERT-In

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment