India CERT-In Cyber Security Directions 2022
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
CERT-In Audit + Drills + Training
Audit + Drills + Training operationalise the Directions through ongoing assurance + cyber preparedness. (1) CERT-In Cyber Security Audit: organisations should undergo periodic cyber security audit by CERT-In Empanelled Information Security Auditing Organisations (currently 100+ empanelled auditors including STQC + ICERT-Cert + Deloitte + KPMG + EY + PwC + IBM Security + Wipro + TCS + Infosys + L&T Infotech and others) + initial audit + periodic recurring audit (typically annual) + post-incident audit + Vulnerability Assessment and Penetration Testing (VAPT) + Source Code Audit + Web Application Audit + Mobile App Audit + Cloud Audit + scope coverage per CERT-In Audit Guidelines + audit report submission + remediation tracking + RBI/SEBI/IRDAI sectoral audit alignment. (2) CERT-In Cyber Security Drills/Exercises: organisations participate in CERT-In coordinated national cyber exercises +
- CERT-In empanelled auditor engagement + periodic audit + VAPT + report + remediation + records
- Cyber drill participation + tabletop + technical + Red-Team Blue-Team + national exercises + records
- Awareness program + role-based training + phishing simulations + completion records + KPIs
- CISO appointed + reporting line to CEO/Board + Indian empanelment + certifications + records
- CCMP documented + CIIIP integration + maturity model assessment + Cyber Swachhta engagement
- No CERT-In empanelled auditor (non-Indian auditor used)
- Drill participation absent (no national-level coordination test)
- Awareness program annual e-learning only (no role-specific or phishing simulations)
- CISO role unfilled or reporting to CIO (not C-suite)
- CCMP absent or untested (no crisis simulation)
CERT-In Compliance + Cooperation (Dir 14-17)
Directions 14-17 establish the cooperation regime + enforcement framework. Direction 14: When required by CERT-In + service providers + intermediaries + data centres + body corporates + government organisations shall provide information sought + take such action as directed by CERT-In within stipulated time + the said information and actions are critical for analysis + investigations + coordination as per the provisions of sub-section (6) of section 70B of IT Act 2000 + Rules notified thereunder + relate to cyber security in the country. Direction 15: CERT-In may seek information + carry out compliance verification + issue further specific orders + directives for compliance + service providers + intermediaries + data centres + body corporates + government organisations shall extend complete cooperation + provide all support + assistance to CERT-In and its officers including for collectio
- CERT-In Coordination Officer appointed + role definition + playbook + escalation + records
- Information provision capability + format + authentication + secure transmission + records
- CERT-In order compliance log + stipulated time tracked + action records + ATR
- Extraterritorial assessment + India service mapping + customer/user/client data + records
- Penalty risk register + Sec 70B(7) imprisonment/fine + Sec 44 daily + Sec 79 safe harbour
- No CERT-In Coordination Officer (no central point for cooperation)
- Information provision capability untested (would miss stipulated time)
- CERT-In orders treated as informal (no formal compliance log)
- Extraterritorial applicability ignored (non-India entity providing to India users)
- Penalty risk not assessed at board level (safe harbour erosion not understood)
CERT-In Coordination + Cross-Regulator
Coordination positions CERT-In Directions within the broader Indian + international cyber ecosystem. (1) RBI Cyber Security Framework: RBI Cyber Security Framework for Banks (June 2016) + Cyber Resilience Framework for NBFCs + Master Direction on IT Outsourcing + sectoral RBI cyber resilience requirements + reporting timelines (RBI 2-6 hour windows often shorter than CERT-In 6 hour). (2) SEBI System Audit Framework: SEBI System Audit + Cyber Resilience Framework + Surveillance and Risk Management + reporting to SEBI in addition to CERT-In. (3) IRDAI Information and Cyber Security Guidelines for Insurance Companies + cyber drills for insurance sector. (4) DPDP Act 2023: Digital Personal Data Protection Act passed 11 August 2023 + Rules 2025 + breach notification within 72 hours to Data Protection Board of India (DPBI) under Section 8(6) + obligation runs alongside CERT-In 6-hour reporting
- RBI + SEBI + IRDAI compliance + cyber resilience reporting matrix + records + cross-mapping
- DPDP Act 2023 breach notification + 72-hour DPBI + alongside 6-hour CERT-In + records
- I4C cybercrime reporting + cybercrime.gov.in + NCIIPC CII engagement + records
- Sectoral CERT coordination + CERT-Fin + CERT-Power + CERT-Healthcare + records
- International CSIRT + APCERT + FIRST + cross-jurisdictional reporting matrix + records
- Multi-regulator reporting fragmented (only CERT-In, RBI/SEBI/IRDAI missed)
- DPDP Act 72h not coordinated with CERT-In 6h (parallel rather than integrated)
- I4C cybercrime not reported (only CERT-In and not financial fraud)
- Sectoral CERTs unknown (no engagement with CERT-Fin/CERT-Power)
- International coordination absent (no CSIRT or APCERT engagement)
CERT-In Incident Reporting (Dir 1-4)
Directions 1-4 establish the mandatory incident reporting regime - the highest-profile and most operationally demanding element of the 2022 Directions. Direction 1: Mandatory cyber incident reporting to CERT-In by service providers + intermediaries + data centres + body corporates + government organisations within 6 hours of noticing such incident or being brought to notice about such incident. Direction 2: Expanded list of 20 Cyber Incident Categories that must be reported - (1) Targeted scanning/probing of critical networks/systems; (2) Compromise of critical systems/information; (3) Unauthorised access of IT systems/data; (4) Defacement of website or intrusion into a website and unauthorised changes; (5) Malicious code attacks; (6) Attack on servers + databases + storage + critical infrastructure; (7) Identity Theft + spoofing + phishing attacks; (8) Denial of Service (DoS) and Distri
- 6-hour reporting SLA + detection pipeline + triage procedure + records of reported incidents
- 20 incident categories awareness + per-category trigger criteria + procedures + records
- Standard Annexure I template + submitted reports archive + acknowledgement records
- Designated POC + 24x7 contact info + backup + CERT-In notification + updates
- Multi-regulator coordination matrix + RBI 6h + SEBI + DPDP 72h + IRDAI + I4C records
- 6-hour SLA missed (reports beyond 6 hours of notice)
- Not all 20 categories covered (e.g. IoT/AI/quantum/blockchain treated as low priority)
- Reports submitted without Annexure I format (free-form not accepted)
- POC unfilled or not 24x7 (escalation gap during off-hours)
- Multi-regulator reporting fragmented (only CERT-In done, RBI/SEBI/DPDP missed)
CERT-In Logging + Clock Sync (Dir 5-7)
Directions 5-7 establish the technical baseline for evidence preservation + forensic readiness + time integrity. Direction 5: All service providers + intermediaries + data centres + body corporates + government organisations shall mandatorily enable logs of all their ICT systems + maintain them securely for a rolling period of 180 days. Logs to be maintained within the Indian jurisdiction (data localisation). Log scope: system logs + access logs + audit logs + firewall logs + IDS/IPS logs + WAF logs + endpoint logs + cloud service logs + DNS logs + email logs + authentication logs + API logs + database logs + privileged session logs + network flow logs. Log integrity: tamper-evident + WORM storage where feasible + cryptographic hash + chain of custody preparation + log forensics readiness. Direction 6: Connect to Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or
- 180-day retention policy + India region storage + records + verified during audits
- Log scope coverage + system + access + audit + firewall + IDS + endpoint + cloud + DNS + records
- Tamper-evident + WORM + hash + chain of custody + Indian Evidence Act Section 65B compliance
- NTP sync to NIC/NPL + traceable + clock-skew monitoring + audit trail + records
- Log provision capability + format + access workflow + cooperation procedures + CERT-In channel
- Log retention <180 days or offshored (data localisation violation)
- Log scope incomplete (only system logs, no DNS/API/authentication)
- Tamper-evidence absent (logs editable in production)
- NTP sync to public Internet servers (not NIC/NPL or traceable)
- Log provision capability untested (would not meet CERT-In order timeline)
CERT-In Scope + Section 70B Authority
Indian Computer Emergency Response Team (CERT-In) Directions issued by Ministry of Electronics and Information Technology (MeitY) Government of India on 28 April 2022 (Notification No. 20(3)/2022-CERT-In) under sub-section (6) of section 70B of the Information Technology Act 2000 (IT Act 2000). Authority basis: Section 70B(1) of IT Act 2000 designates CERT-In as the national agency for cyber incident response since 27 October 2009 Gazette notification + Section 70B(4) lists CERT-In functions including collection + analysis + dissemination of cyber incident information + forecasts + emergency measures + coordination + guidelines + advisories + vulnerability notes + Section 70B(6) empowers CERT-In to call for information from service providers + intermediaries + data centres + body corporates + persons. IT (CERT-In and Manner of performing functions and duties) Rules 2013 (notified 16 Janu
- CERT-In applicability assessment + role classification (service provider/intermediary/DC/body corp/VASP/govt)
- Section 70B IT Act 2000 compliance + IT Rules 2013 + functions awareness + Gazette notifications
- Effective date compliance evidence + post-28 June 2022 + extended provisions + records
- 17 Directions implementation matrix + per-section coverage + status + records
- Penalty awareness + Sec 70B(7) + Sec 44 IT Act + mitigation plan + non-compliance remediation
- CERT-In applicability not assessed (operating in India without classification)
- Section 70B basis not understood (treating directions as advisory)
- Effective date compliance partial (not all 17 Directions met)
- Direction-by-direction implementation not tracked (no compliance matrix)
- Penalty exposure unmitigated (operations continue with known gaps)
CERT-In Service Provider Obligations (Dir 8-10)
Directions 8-10 impose detailed customer KYC + subscriber-records retention obligations on Data Centre + Cloud Service Provider + Virtual Private Server (VPS) + Virtual Private Network (VPN) service providers - a controversial set of provisions affecting India-facing VPN market. Direction 8: Data Centres + Virtual Private Server (VPS) providers + Cloud Service Providers + Virtual Private Network (VPN) Service providers shall be required to register accurate information of subscribers/customers hiring the services for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration. Direction 9: Categories of subscriber information to be maintained: (a) Validated names of subscribers/customers hiring the services; (b) Period of hire including dates; (c) IPs allotted to/being used by the members; (d) Email address and IP address and tim
- Classification assessment + DC/VPS/VPN/Cloud SP role + applicability per Direction 8-10 + records
- Customer KYC workflow + 7 elements + validated identity + address + IP + ownership + records
- 5-year retention policy + cancellation tracking + retention beyond service end + India storage
- Provision capability + CERT-In + law enforcement order workflow + records + audit
- DPDP Act 2023 alignment + customer consent + purpose limitation + privacy notice + records
- VPN service operating in India without 5-year subscriber records (compliance gap)
- Customer KYC missing elements (e.g. ownership pattern not captured for org customers)
- 5-year retention not enforced (records purged at cancellation)
- Provision capability absent (cannot respond to law enforcement order)
- DPDP Act compliance overlooked (subscriber records without consent or purpose limitation)
CERT-In VASP Requirements (Dir 11-13)
Directions 11-13 impose specific obligations on Virtual Asset (cryptocurrency) ecosystem + digital payment systems given the elevated cyber risk + financial crime risk. Direction 11: Virtual Asset Service providers (VASPs) + Virtual Asset Exchange providers and Custodian Wallet Providers (as defined by Ministry of Finance from time to time) shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of five years so as to ensure cyber security in the area of payments and financial markets for citizens while protecting their data + fundamental rights + economic freedom in view of the growth of virtual assets. KYC includes: identity verification per Prevention of Money Laundering Act PMLA + Aadhaar + PAN + or alternative IDs + address proof + risk assessment + beneficial ownership + customer due diligence. Direc
- VASP classification per Ministry of Finance + service portfolio + applicability assessment + records
- PMLA KYC + identity + address + ownership + risk + Travel Rule FATF 16 + records
- 5-year transaction records + reconstruction capability + IP/PubKey/timestamp + retention
- Digital Payment System incident reporting + elevated SLA + CERT-In + RBI + records
- Coordination FIU-IND + Income Tax 30%+1% TDS + ED + RBI + SEBI + FATF + records
- VASP definition unclear (operating below regulatory radar)
- PMLA KYC weak (no beneficial ownership for high-net-worth customers)
- Transaction reconstruction not tested (cannot produce IP/timestamp/pubkey on demand)
- Digital payment incident SLA missed (treated as ordinary cyber)
- FIU-IND/Income Tax/ED reporting fragmented or absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the India CERT-In Cyber Security Directions 2022 framework page.