India CERT-In Cyber Security Directions 2022
The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Compliance and Cooperation
| Code | Title |
|---|---|
| Dir. 14 | CERT-In Orders Compliance |
| Dir. 15 | Action and Information Directives |
| Dir. 16 | Applicability to All Entities |
| Dir. 17 | Penalties for Non-Compliance |
Incident Reporting
Cyber incident reporting and preservation
Incident Reporting Requirements
| Code | Title |
|---|---|
| Dir. 1 | Mandatory Incident Reporting |
| Dir. 2 | Expanded Incident Categories |
| Dir. 3 | Incident Report Format |
| Dir. 4 | Point of Contact Designation |
| Sec. 2242(a) | Covered cyber incident report |
| Sec. 2242(b) | Ransom payment report |
| Sec. 2242(c) | Supplemental reports |
| Sec. 2242(d) | Report contents |
| Sec. 2242(e) | Preservation of information |
Service Provider Obligations
| Code | Title |
|---|---|
| Dir. 10 | Virtual Private Server Provider Records |
| Dir. 8 | Data Centre and Cloud Provider Records |
| Dir. 9 | VPN Service Provider Customer Data |
System Logging and Clock Synchronization
| Code | Title |
|---|---|
| Dir. 5 | ICT System Log Maintenance |
| Dir. 6 | Clock Synchronization via NTP |
| Dir. 7 | Log Availability to CERT-In |
Technical Requirements
ICT accessibility technical standards
Virtual Asset and Financial Platform Requirements
| Code | Title |
|---|---|
| Dir. 11 | Virtual Asset Service Provider KYC |
| Dir. 12 | Financial Transaction Records |
| Dir. 13 | Digital Payment System Incident Reporting |
Your Compliance Coverage
If you comply with India CERT-In Cyber Security Directions 2022, you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
18%
4 controls mapped
Compare →Nevada Gaming Control Board Cybersecurity Requirements
18%
4 controls mapped
Compare →Lloyd's Minimum Standards — Cyber Security
18%
4 controls mapped
Compare →+ 444 more: FTC Safeguards Rule (16 CFR Part 314) (18%), US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements (18%)
See all 447 mapped frameworks ↓Maps to 447 other frameworks
Frequently Asked Questions
What is India CERT-In Cyber Security Directions 2022?
India CERT-In Cyber Security Directions 2022 is a compliance framework from India with 7 domains and 22 controls. The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does India CERT-In Cyber Security Directions 2022 have?
India CERT-In Cyber Security Directions 2022 has 22 controls organised across 7 domains. The largest domains are Incident Reporting Requirements (9 controls), Compliance and Cooperation (4 controls), Service Provider Obligations (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does India CERT-In Cyber Security Directions 2022 map to?
India CERT-In Cyber Security Directions 2022 maps to 447 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (18% coverage), Nevada Gaming Control Board Cybersecurity Requirements (18% coverage), Lloyd's Minimum Standards — Cyber Security (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with India CERT-In Cyber Security Directions 2022 compliance?
Start your India CERT-In Cyber Security Directions 2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about India CERT-In Cyber Security Directions 2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 693 frameworks.
Get Started Free →Free forever — no credit card required