𝕏in
Compliance & AdvisoryPublished on March 10, 2026β€’12 min readβ€’Peer-Reviewed Paper

CERT-In Mandatory Incident Reporting: Technical Compliance Playbook for Indian CTOs & CISOs

An exhaustive technical breakdown of Section 70B of the Information Technology Act. Step-by-step reporting protocols, mandatory NTP clock synchronization, 180-day secure logging pipelines, and sample incident disclosure templates.

SC
Saket ChoudharyLead Architect
Founder & Lead Security Architect, Cyberfact Security
πŸ’¬ Technical Inquiries (WhatsApp)
CERT-In Mandatory Incident Reporting: Technical Compliance Playbook for Indian CTOs & CISOs

The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology (MeitY), issued cyber security directions under sub-section (6) of section 70B of the Information Technology Act, 2000. These directives impose non-negotiable statutory obligations on all service providers, intermediaries, data centers, body corporates, and digital business entities operating within the Indian sovereign cyber territory.

Chief Technology Officers (CTOs) and Chief Information Security Officers (CISOs) who fail to establish continuous compliance run direct legal risk, including statutory penalties and imprisonment under Section 70B(7) of the IT Act.

This playbook provides the definitive engineering architecture, logging pipelines, and operational runbooks required to maintain 100% compliance with CERT-In directives.


1. The Mandatory 6-Hour Incident Notification Rule

Under Annexure I of the CERT-In Directions, any covered entity must report specified cybersecurity incidents to CERT-In within six (6) hours of noticing or being brought to notice of such events.

[ Security Event Occurs ]
           β”‚
           β–Ό
[ Detection & Triage ] ────────── (SIEM / SOC Alert Triggered)
           β”‚
           β–Ό (Clock Starts: < 6 Hours Window)
[ Initial Severity Assessment ] ─ (Incident Commander Mobilized)
           β”‚
           β–Ό
[ CERT-In Incident Dispatch ] ── (Email to incident@cert-in.org.in or Portal)
           β”‚
           β–Ό
[ Containment & Remediation ] ── (Network isolation, forensic memory capture)
           β”‚
           β–Ό
[ Final Root Cause Analysis (RCA) ] ── (Submitted within statutory review cycle)

The 20 Mandatory Reportable Incident Categories:

  1. Targeted scanning/probing of critical networks and systems.
  2. Compromise of critical systems or information assets.
  3. Unauthorized access of IT systems, databases, or cloud accounts.
  4. Defacement of website or intrusion into network perimeter.
  5. Malicious code attacks (ransomware, worms, spyware, trojans).
  6. Attack on servers such as Database, Mail and DNS and network devices such as Routers.
  7. Identity theft, spoofing and phishing attacks.
  8. Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.
  9. Attacks on Critical Information Infrastructure (CII), SCADA and operational technology systems.
  10. Data breaches, data leaks, and unintended exposure of customer records.

2. Mandatory NTP Clock Synchronization Architecture

CERT-In mandates that all ICT systemsβ€”including physical bare-metal hosts, virtual hypervisors, cloud containers, network switches, firewalls, and database clustersβ€”must synchronize their system clocks strictly to designated time servers:

  • National Informatics Centre (NIC) NTP Servers: samay1.nic.in, samay2.nic.in
  • National Physical Laboratory (NPL) NTP Servers: time.nplindia.org

Production Chrony Configuration (/etc/chrony/chrony.conf):

# CERT-In Compliant NTP Configuration
server samay1.nic.in iburst minpoll 4 maxpoll 6
server samay2.nic.in iburst minpoll 4 maxpoll 6
server time.nplindia.org iburst minpoll 4 maxpoll 6

# Reject unverified time sources
maxdistance 1.0
driftfile /var/lib/chrony/drift
makestep 1.0 3
rtcsync
logchange 0.5

Verifying active synchronization on production Linux nodes:

# Verify upstream synchronization status
chronyc sources -v
chronyc tracking

3. The 180-Day Secure Log Retention Pipeline

Organizations must maintain complete, immutable, tamper-evident logs of all ICT systems for a rolling window of not less than 180 days within Indian jurisdiction.

Log Stream Mandatory Fields Storage Tier & Retention
Edge & WAF Logs Source IP, User-Agent, Request URI, HTTP Status, TLS Cipher S3 Glacier (Mumbai / Hyderabad), 180 Days
Authentication Logs User ID, Source IP, Timestamp (UTC+05:30), Auth Result (Success/Fail) OpenSearch / Elastic, Hot 30d, Cold 150d
Database Audit Logs Query execution, schema mutations, admin connections Append-only encrypted bucket, 180 Days
Operating System Syslog Sudo escalations, SSH sessions, kernel security alerts Rsyslog forwarding to central SIEM cluster
[ Microservices / EC2 / Cloud ]
               β”‚
               β–Ό
[ FluentBit / Vector Agent ] ──── (Local cryptographic hashing)
               β”‚
               β–Ό
[ Apache Kafka Ingestion Stream ]
               β”‚
               β–Ό
[ Immutable S3 Bucket (ap-south-1) ] ── (WORM Object Lock, 180-day retention)

4. Production CERT-In Reporting Incident Template

When dispatching the initial notification to incident@cert-in.org.in, the reporting email must adhere to standardized structured data formatting:

To: incident@cert-in.org.in
Subject: STATUTORY INCIDENT REPORT: [Entity Name] - [Incident Classification] - [Date]

1. Contact Details of Organization:
   - Organization Name: [Legal Entity Name]
   - Designated Incident Officer: [Name, Designation, Phone, Email]
   - Physical Location / Registered Office: [City, State, India]

2. Incident Chronology:
   - Time of Detection: YYYY-MM-DD HH:MM:SS IST (UTC+05:30)
   - Estimated Time of Inception: YYYY-MM-DD HH:MM:SS IST
   - Time of Initial Containment: YYYY-MM-DD HH:MM:SS IST

3. Impacted Systems & Perimeter:
   - Affected IP Addresses / Domains: [Public IPv4/IPv6, FQDNs]
   - Asset Classification: [Production Database / Auth Microservice / Public Web]
   - Nature of Exploitation: [e.g. Unauthenticated Remote Code Execution / Ransomware]

4. Summary of Observed Indicators of Compromise (IoCs):
   - Malicious IP Addresses: [List IPs]
   - Payload Hashes (SHA-256): [Hashes of captured artifacts]
   - User Accounts Involved: [Redacted identifiers]

5. Containment Actions Executed:
   - Network isolation of affected nodes completed.
   - Credentials revoked and session tokens invalidated globally.
   - Forensic memory dump captured for evidentiary preservation.

5. Engaging Cyberfact Security for Incident Response & VAPT Audits

Under the guidance of Saket Choudhary, Cyberfact Security delivers end-to-end CERT-In readiness audits, periodic mandated VAPT certifications, and emergency incident triage across Indian tech ecosystems.

  • Emergency Incident Desk: 24/7 technical hotline for containment and regulatory notifications.
  • Pre-Audit Gap Assessments: Evaluating your existing logging architecture and NTP topology against CERT-In checklists.
  • Empanelled VAPT Testing: Certified reports satisfying banking, fintech, and regulatory audit mandates.
Topics:#CERT-In#Incident Response#Compliance#IT Act 2000#Cybersecurity India#SIEM Architecture
SC
Saket Choudhary

Founder and Lead Security Architect at Cyberfact Security. Specializing in offensive penetration testing (VAPT), distributed cloud architectures, and hardened full-stack engineering for high-growth enterprises.

EXECUTIVE AUDIT & ENGINEERING DESK

Initiate a Technical Audit or Custom Engineering Scope

Cyberfact Security delivers certified VAPT audits, source code reviews, and enterprise software engineering for institutions across India. Direct technical engagements with Founder Saket Choudhary.

WhatsApp