India CERT-In Cyber Security Directions 2022
The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Audit
| Code | Title |
|---|---|
| CERTIN-17 | Audit of Compliance |
Compliance and Cooperation
| Code | Title |
|---|---|
| Dir. 14 | CERT-In Orders Compliance |
| Dir. 15 | Action and Information Directives |
| Dir. 16 | Applicability to All Entities |
| Dir. 17 | Penalties for Non-Compliance |
Coordination
| Code | Title |
|---|---|
| CERTIN-11 | Sectoral CERT Coordination |
Customer onboarding
| Code | Title |
|---|---|
| CERTIN-12 | Validation of Subscriber Details |
| CERTIN-18 | Subscriber Records on Cancellation |
| CERTIN-7 | Data Centre and VPS KYC |
| CERTIN-8 | Subscriber Information Categories |
| CERTIN-9 | Virtual Asset Customer KYC |
Enforcement
| Code | Title |
|---|---|
| CERTIN-13 | Penalties for Non Compliance |
Governance
| Code | Title |
|---|---|
| CERTIN-4 | Single Point of Contact |
Incident Reporting
Cyber incident reporting and preservation
Incident Reporting Requirements
| Code | Title |
|---|---|
| Dir. 1 | Mandatory Incident Reporting |
| Dir. 2 | Expanded Incident Categories |
| Dir. 3 | Incident Report Format |
| Dir. 4 | Point of Contact Designation |
| Sec. 2242(a) | Covered cyber incident report |
| Sec. 2242(b) | Ransom payment report |
| Sec. 2242(c) | Supplemental reports |
| Sec. 2242(d) | Report contents |
| Sec. 2242(e) | Preservation of information |
Incident reporting
| Code | Title |
|---|---|
| CERTIN-2 | Six Hour Incident Reporting |
Incident scope
| Code | Title |
|---|---|
| CERTIN-3 | Reportable Incident Categories |
Logging
| Code | Title |
|---|---|
| CERTIN-14 | Log Storage Location |
| CERTIN-5 | Log Retention 180 Days |
| CERTIN-6 | Log Provision on Order |
Logging integrity
| Code | Title |
|---|---|
| CERTIN-1 | Time Synchronisation with NTP |
Operational reporting
| Code | Title |
|---|---|
| CERTIN-10 | Reporting Mechanism |
Service Provider Obligations
| Code | Title |
|---|---|
| Dir. 10 | Virtual Private Server Provider Records |
| Dir. 8 | Data Centre and Cloud Provider Records |
| Dir. 9 | VPN Service Provider Customer Data |
System Logging and Clock Synchronization
| Code | Title |
|---|---|
| Dir. 5 | ICT System Log Maintenance |
| Dir. 6 | Clock Synchronization via NTP |
| Dir. 7 | Log Availability to CERT-In |
Technical Requirements
ICT accessibility technical standards
Third party
| Code | Title |
|---|---|
| CERTIN-15 | Cloud Service Provider Obligations |
Training
| Code | Title |
|---|---|
| CERTIN-16 | Drills and Awareness |
Virtual Asset and Financial Platform Requirements
| Code | Title |
|---|---|
| Dir. 11 | Virtual Asset Service Provider KYC |
| Dir. 12 | Financial Transaction Records |
| Dir. 13 | Digital Payment System Incident Reporting |
Your Compliance Coverage
If you comply with India CERT-In Cyber Security Directions 2022, you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
10%
4 controls mapped
Compare →Nevada Gaming Control Board Cybersecurity Requirements
10%
4 controls mapped
Compare →Lloyd's Minimum Standards - Cyber Security
10%
4 controls mapped
Compare →+ 313 more: South Korea Cloud Security Assurance Program (CSAP) (10%), TISAX - Trusted Information Security Assessment Exchange (10%)
See all 316 mapped frameworks ↓Maps to 316 other frameworks
Frequently Asked Questions
What is India CERT-In Cyber Security Directions 2022?
India CERT-In Cyber Security Directions 2022 is a compliance framework from India with 19 domains and 40 controls. The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does India CERT-In Cyber Security Directions 2022 have?
India CERT-In Cyber Security Directions 2022 has 40 controls organised across 19 domains. The largest domains are Incident Reporting Requirements (9 controls), Customer onboarding (5 controls), Compliance and Cooperation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does India CERT-In Cyber Security Directions 2022 map to?
India CERT-In Cyber Security Directions 2022 maps to 316 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (10% coverage), Nevada Gaming Control Board Cybersecurity Requirements (10% coverage), Lloyd's Minimum Standards - Cyber Security (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with India CERT-In Cyber Security Directions 2022 compliance?
Start your India CERT-In Cyber Security Directions 2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about India CERT-In Cyber Security Directions 2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required