Framework National Cyber & Cloud Schemes
CERT-IN
CERT-In is the Indian Computer Emergency Response Team, the national agency under the Ministry of Electronics and Information Technology. In compliance lists the label refers to the binding Cyber Security Directions CERT-In issued on April 28, 2022 under Section 70B(6) of the Information Technology Act, 2000, which took effect sixty days later.
The directions require service providers, intermediaries, data centers, body corporates, and government organizations to report a listed set of cyber incidents to CERT-In within six hours of noticing them; to synchronize system clocks to Indian time sources; to keep logs of all ICT systems for a rolling 180 days within India; and to designate a point of contact.
Virtual private server, cloud, and VPN providers must keep subscriber records for five years, and virtual asset providers must keep KYC and transaction records. CERT-In also runs an empanelment scheme for information security auditing organizations that Indian regulators and government bodies use for mandated audits.
In writing, an in-scope organization needs an incident response procedure that meets the six-hour clock (including who decides what is reportable and how the CERT-In form is filed), a log management policy proving 180-day retention in India, NTP configuration standards, the designated contact registration, and for the named provider categories the customer record retention procedures.
Organizations subject to sectoral audits (for example under SEBI or RBI rules) need audit reports from CERT-In empanelled auditors.
help
Who has to comply
Any service provider, intermediary, data center, body corporate, or government organization operating in India or serving Indian users, with specific additional duties for VPS, cloud, and VPN providers and virtual asset service providers. Company size does not matter; some duties were clarified through FAQs, including a carve-out for enterprise VPNs.
What the assessor asks to see
Incident response procedure and reporting workflow with sample CERT-In submissions; incident register with detection and report timestamps; log management policy and evidence of 180-day retention in Indian jurisdiction; NTP configuration; designated point of contact registration; customer record retention procedures for VPS, cloud, VPN, and virtual asset providers; audit reports from empanelled auditors where required; vulnerability management and remediation records.
Assessors
Who assesses CERT-IN
CERT-In itself supervises and can request information; CERT-In empanelled information security auditing organizations conduct audits where a regulator or government body requires one (for example for government websites and applications and certain regulated sectors). The empanelment is a public list maintained by CERT-In.
Accredited by CERT-In empanels auditing organizations directly through periodic empanelment rounds.
Public register of assessors: https://www.cert-in.org.in/PDF/Empanel_org.pdf
No firm has claimed a CERT-IN assessor listing yet. Claim yours →
Consultants
Who helps with CERT-IN
Indian cybersecurity consultancies, managed SOC providers, and CERT-In empanelled auditors help organizations design reporting workflows, log retention architectures, and compliance documentation. Engagements range from a few weeks for a gap assessment to ongoing managed logging services.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CERT-IN consultant listing yet. Claim yours →
Software
Tools for CERT-IN
Tools that name this framework in their own material.
No firm has claimed a CERT-IN tool listing yet. Claim yours →
Related reading
- 2022 CERT-In directions on reporting cyber incidentsSets out the six-hour reporting clock, the 180-day log retention duty and who the directions actually reach.Trilegal
- CERT-In directionsIndian counsel on the reportable incident categories, the India log-storage requirement and the penalties for missing them.AZB & Partners
- Internet impact brief: India CERT-In cybersecurity directions 2022Independent critique of what the directions demand of VPN, cloud and crypto intermediaries and why that proved contentious.Internet Society
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CERT-IN
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CERT-IN
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.