India CERT-In Cyber Security Directions 2022
The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Compliance and Cooperation
| Code | Title |
|---|---|
| Dir. 14 | CERT-In Orders Compliance |
| Dir. 15 | Action and Information Directives |
| Dir. 16 | Applicability to All Entities |
| Dir. 17 | Penalties for Non-Compliance |
Incident Reporting
Cyber incident reporting and preservation
Incident Reporting Requirements
| Code | Title |
|---|---|
| Dir. 1 | Mandatory Incident Reporting |
| Dir. 2 | Expanded Incident Categories |
| Dir. 3 | Incident Report Format |
| Dir. 4 | Point of Contact Designation |
| Sec. 2242(a) | Covered cyber incident report |
| Sec. 2242(b) | Ransom payment report |
| Sec. 2242(c) | Supplemental reports |
| Sec. 2242(d) | Report contents |
| Sec. 2242(e) | Preservation of information |
Service Provider Obligations
| Code | Title |
|---|---|
| Dir. 10 | Virtual Private Server Provider Records |
| Dir. 8 | Data Centre and Cloud Provider Records |
| Dir. 9 | VPN Service Provider Customer Data |
System Logging and Clock Synchronization
| Code | Title |
|---|---|
| Dir. 5 | ICT System Log Maintenance |
| Dir. 6 | Clock Synchronization via NTP |
| Dir. 7 | Log Availability to CERT-In |
Technical Requirements
ICT accessibility technical standards
Virtual Asset and Financial Platform Requirements
| Code | Title |
|---|---|
| Dir. 11 | Virtual Asset Service Provider KYC |
| Dir. 12 | Financial Transaction Records |
| Dir. 13 | Digital Payment System Incident Reporting |
Maps to 447 other frameworks
Frequently Asked Questions
What is India CERT-In Cyber Security Directions 2022?
India CERT-In Cyber Security Directions 2022 is a compliance framework from India with 7 domains and 22 controls. The Indian Computer Emergency Response Team (CERT-In) Directions of April 2022 mandate cybersecurity practices for service providers, intermediaries, data centres, and government organizations in India. Key requirements include 6-hour incident reporting, 180-day log retention, KYC for VPN/cloud providers, and synchronized system clocks. Applies to all entities covered by the Information Technology Act 2000. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does India CERT-In Cyber Security Directions 2022 have?
India CERT-In Cyber Security Directions 2022 has 22 controls organised across 7 domains. The largest domains are Incident Reporting Requirements (9 controls), Compliance and Cooperation (4 controls), Service Provider Obligations (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does India CERT-In Cyber Security Directions 2022 map to?
India CERT-In Cyber Security Directions 2022 maps to 447 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (18% coverage), Nevada Gaming Control Board Cybersecurity Requirements (18% coverage), Lloyd's Minimum Standards — Cyber Security (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with India CERT-In Cyber Security Directions 2022 compliance?
Start your India CERT-In Cyber Security Directions 2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about India CERT-In Cyber Security Directions 2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required