CERT-IN Compliance
CERT-In (the Indian Computer Emergency Response Team) issued Directions under Section 70B of the Information Technology Act, 2000 — effective since June 2022 — that apply to essentially every business operating IT systems, websites, or cloud services in India. Unlike many compliance thresholds, there's no minimum company size or revenue exemption: if you run IT infrastructure touching India, these Directions apply to you.
What CERT-In Directions Actually Require
- 6-hour incident reporting — organizations must report cybersecurity incidents to CERT-In within 6 hours of noticing them or being informed of them, covering 20 categories of reportable incidents ranging from ransomware to unauthorized access and fake mobile app impersonation.
- Time synchronization — all ICT systems must sync clocks to authorized time sources, so incident timelines are accurate and reconcilable across systems.
- Log retention — logs of ICT systems must be maintained securely for 180 days within Indian jurisdiction.
- Empanelled audits — regulated entities and government organizations need annual security audits performed by a CERT-In empanelled auditor; private businesses are strongly advised to do the same, at minimum annually or after major infrastructure changes.
Why the 6-Hour Rule Is Harder Than It Sounds
A 6-hour reporting window only works if you actually detect the incident quickly. Most organizations running quarterly or annual security testing have no realistic way to meet that window — they simply don't find out about an incident fast enough for 6 hours to be a meaningful deadline rather than one they've already blown by the time they notice.
Where Alastor InfoSec Fits
Alastor Pulse's continuous monitoring and Dark Web Monitoring exist precisely to close that detection gap — the same real-time findings pipeline that surfaces your first critical vulnerability in hours is what makes a 6-hour reporting window achievable instead of aspirational. Alastor Shield then handles the documentation side: maintaining the audit trail and log retention evidence a CERT-In empanelled auditor will expect to see.
Who Needs This
Every business operating IT infrastructure, websites, or cloud services with any nexus to India falls under CERT-In's Directions — there's no small-business exemption. If you've never had a CERT-In empanelled audit, that's the first gap worth closing, well before an incident forces the question.
Talk to our team about getting audit-ready for CERT-In empanelled review and 6-hour incident response readiness.