GUIDE

The CISO's Guide to CERT-In Directions: 6-Hour Reporting Without the Panic

INDIA COMPLIANCE · 9 MIN READ · ZENC LABS RESEARCH · 2026

India's CERT-In Directions changed incident response from a best-effort discipline into a clock-driven legal obligation: specified cyber incidents must be reported to CERT-In within six hours of noticing or being notified. Four years on, most enterprises still discover the gaps in their pipeline during a live incident, the most expensive possible time.

▲ 6-HOUR REPORTING MANDATE · 20 REPORTABLE INCIDENT CATEGORIES · 180-DAY LOG RETENTION (IN INDIA) · NTP CLOCK SYNC REQUIRED

What the Directions actually require

Why teams miss the window

The six hours are rarely lost to slow detection, they're lost to ambiguity. Nobody is sure whether the event maps to a reportable category, who is authorized to file, what legal wants redacted, and where the evidence lives. Each open question burns an hour.

The playbook that works at 2 a.m.

Pre-map your taxonomy. Every alert category in your SOC should carry a pre-decided flag: reportable / not reportable / escalate-to-counsel. The classification debate happens once, in daylight, not per incident.

Pre-draft the report. CERT-In's format is known. Maintain templates with your organization's constants filled in, so the on-call engineer completes fields instead of composing prose.

Automate the evidence bundle. Your SIEM should export the incident timeline, affected assets, and indicators in one action. This is exactly what an agentic SOC does well, our platform drafts the CERT-In submission as a byproduct of triage.

Drill quarterly. Run a timed tabletop from "alert fires" to "report filed." If the drill takes longer than four hours, the real one will miss six.

One nuance leaders miss: the clock starts at "noticing", which includes being notified by a customer, vendor, or researcher. Your intake channels (support desk, disclosure inbox) are part of your compliance surface.
SOURCES: CERT-In Directions under Section 70B(6), IT Act 2000 (April 2022) · CERT-In FAQs · ZenC Labs incident-response practice

Is your incident workflow CERT-In ready?

We build and drill the entire reporting pipeline, taxonomy, templates, evidence, and the 2 a.m. run-book.

Book a readiness assessment