---
title: "CERT-IN Compliance"
description: "How Alastor InfoSec supports CERT-In compliance in India — the 6-hour incident reporting rule, empanelled audit methodology, and continuous monitoring evidence."
keywords:
  - CERT-In compliance
  - CERT-In empanelment
  - 6-hour incident reporting
  - India cybersecurity directions
  - CERT-In audit
---

# CERT-IN Compliance

CERT-In (the Indian Computer Emergency Response Team) issued Directions under Section 70B of the Information Technology Act, 2000 — effective since June 2022 — that apply to essentially every business operating IT systems, websites, or cloud services in India. Unlike many compliance thresholds, there's no minimum company size or revenue exemption: if you run IT infrastructure touching India, these Directions apply to you.

## What CERT-In Directions Actually Require

- **6-hour incident reporting** — organizations must report cybersecurity incidents to CERT-In within 6 hours of noticing them or being informed of them, covering 20 categories of reportable incidents ranging from ransomware to unauthorized access and fake mobile app impersonation.
- **Time synchronization** — all ICT systems must sync clocks to authorized time sources, so incident timelines are accurate and reconcilable across systems.
- **Log retention** — logs of ICT systems must be maintained securely for 180 days within Indian jurisdiction.
- **Empanelled audits** — regulated entities and government organizations need annual security audits performed by a CERT-In empanelled auditor; private businesses are strongly advised to do the same, at minimum annually or after major infrastructure changes.

## Why the 6-Hour Rule Is Harder Than It Sounds

A 6-hour reporting window only works if you actually detect the incident quickly. Most organizations running quarterly or annual security testing have no realistic way to meet that window — they simply don't find out about an incident fast enough for 6 hours to be a meaningful deadline rather than one they've already blown by the time they notice.

## Where Alastor InfoSec Fits

[Alastor Pulse](/products/alastor-pulse)'s continuous monitoring and [Dark Web Monitoring](/features/dark-web-monitoring) exist precisely to close that detection gap — the same real-time findings pipeline that surfaces your first critical vulnerability in hours is what makes a 6-hour reporting window achievable instead of aspirational. [Alastor Shield](/products/alastor-shield) then handles the documentation side: maintaining the audit trail and log retention evidence a CERT-In empanelled auditor will expect to see.

## Who Needs This

Every business operating IT infrastructure, websites, or cloud services with any nexus to India falls under CERT-In's Directions — there's no small-business exemption. If you've never had a CERT-In empanelled audit, that's the first gap worth closing, well before an incident forces the question.

[Talk to our team](/about-us) about getting audit-ready for CERT-In empanelled review and 6-hour incident response readiness.
