National Cyber Compliance · India
National Cyber Compliance in India
Readiness for India's national cyber obligations — the CERT-In Directions, sectoral mandates from the RBI, SEBI and IRDAI, and critical information infrastructure duties — for organisations in Bengaluru, Mumbai, Delhi NCR, Hyderabad, Chennai and Pune.
Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm
National cyber compliance in India means meeting the obligations that apply to you regardless of your customers' demands — principally the CERT-In Directions issued under Section 70B(6) of the IT Act 2000, which require six-hour incident reporting, 180 days of ICT log retention within Indian jurisdiction and synchronised system time; the duties attaching to protected systems and critical information infrastructure under Section 70A; and your sector regulator's cyber mandates. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA); we assess where you actually stand against each and close the gaps.
India's national cyber obligations, and who they bind
These obligations are not optional and are not driven by customer procurement — they attach by law or by regulator. The common failure is assuming they only apply to large or 'critical' organisations:
- CERT-In Directions (28 April 2022, effective 28 June 2022) — the broadest of them. They bind service providers, intermediaries, data centres, body corporates and government organisations alike. Six-hour reporting of specified incidents, 180-day ICT log retention within India, and NIC or NPL time synchronisation.
- Provider record-keeping — data centres, virtual private server providers, cloud service providers and VPN providers must register and retain accurate subscriber and customer records for five years after cancellation or withdrawal, and virtual asset service providers carry equivalent KYC and transaction record duties.
- Critical information infrastructure — computer resources declared protected systems under Section 70A of the IT Act carry heightened obligations, with the national nodal agency for critical information infrastructure protection setting the practices expected of them.
- Sectoral mandates — the RBI for banks, NBFCs and payment system operators; SEBI's CSCRF for market infrastructure institutions and intermediaries; IRDAI for insurers. These sit on top of, not instead of, the CERT-In Directions.
- DPDP Act 2023 — breach notification to the Data Protection Board, running in parallel with CERT-In incident reporting, plus the independent data audit duty for a Significant Data Fiduciary. Phased in with the DPDP Rules, 2025 (notified 13 November 2025): the Board's provisions are already in force, the substantive duties commence in May 2027.
- Government and PSU procurement — many tenders require a security audit performed by a CERT-In empanelled organisation, which is a commercial obligation with the force of a compliance one.
Where organisations actually fail these
Across our assessments the gaps are consistent, and rarely about technology spend:
- The six-hour clock — the organisation has monitoring, but no one is authorised to decide 'this is reportable' out of hours, so the window is missed while the incident is still being triaged.
- Log retention — logs exist but roll off before 180 days, or are retained in a region outside Indian jurisdiction, which does not satisfy the Direction.
- Time synchronisation — endpoints and cloud workloads pointing at public NTP pools rather than NIC or NPL sources, which undermines the evidential value of every log downstream.
- Nobody owns it — CERT-In compliance sits between IT operations, security and legal, and each assumes another has it.
- Parallel reporting duties — a single incident can trigger CERT-In reporting, a DPDP breach notification and a sectoral regulator's report, on different clocks, and only one gets filed.
- Providers unaware of their status — cloud, VPS and VPN providers who did not realise the customer record-keeping obligations attach to them.
What the engagement produces
We assess against each applicable obligation and give you the artefacts that demonstrate compliance rather than assert it:
- An obligation register: every national and sectoral requirement that binds you, with your current position against each and a named owner.
- A tested incident-reporting runbook that can actually meet six hours, including out-of-hours decision authority and the CERT-In reporting route.
- A log retention and time-synchronisation design that satisfies the Directions, with evidence of retention period and jurisdiction.
- Alignment of the parallel duties — CERT-In, DPDP and your sector regulator — into one incident process rather than three that compete during a live incident.
- A prioritised remediation plan, and re-testing after remediation so closure is evidenced.
How long does this take?
A focused CERT-In readiness review is typically a short engagement measured in weeks, because the obligations are finite and testable. Adding sectoral frameworks or critical infrastructure scope extends it. As with all our work we agree scope in writing and quote fixed before starting, and if you are working to a regulator's deadline we will tell you plainly whether it is reachable.
Why CyberSigma for national cyber compliance
We are CERT-In empanelled, which means we work with these Directions as a matter of routine rather than reading them for the first time on your engagement — and where a tender or regulator requires an empanelled organisation's report, ours is accepted. We assess the obligation as it is written, tell you plainly where you do not meet it, and stay to help you close it.
Related services
Cybersecurity audit
Independent audit against CERT-In, RBI, SEBI and ISO 27001.
Data privacy audit
DPDP Act readiness, consent, rights and breach response.
VAPT & penetration testing
Web, mobile, API, network and cloud penetration testing.
AI security
Security and governance for AI and LLM systems.
Frequently asked questions
Do the CERT-In Directions apply to us if we are a small company?
Very likely, yes. The Directions are drafted broadly — service providers, intermediaries, data centres, body corporates and government organisations — and do not carry a small-business exemption. Size affects how much work compliance is, not whether the obligation attaches.
What has to be reported to CERT-In within six hours?
The Directions list the types of cyber incident that must be reported on noticing them, covering categories such as targeted scanning, compromise of critical systems, unauthorised access to IT systems and data, website defacement, malicious code and ransomware attacks, data breaches and leaks, and attacks on servers and network appliances. The practical test in an audit is not whether you know the list — it is whether a decision can be made and a report filed inside six hours, including at 2am on a Sunday.
Do our logs have to be stored in India?
The Direction requires ICT logs to be maintained for a rolling period of 180 days and maintained within Indian jurisdiction. A common finding is that logs are retained for long enough but in a cloud region outside India, which does not satisfy it.
What is a protected system under Section 70A?
Section 70A of the IT Act allows the government to declare a computer resource that directly or indirectly affects critical information infrastructure to be a protected system, which brings heightened security obligations and a designated national nodal agency's practices into play. If you operate in power, telecom, transport, banking, health or government services, it is worth establishing formally whether any of your systems are so declared.
How does this differ from ISO 27001?
ISO 27001 is a voluntary management-system standard you certify against because customers and tenders ask for it. National cyber compliance is a legal obligation that applies whether or not anyone asks. They complement each other — an ISO 27001 management system is a good vehicle for evidencing the Directions — but certification does not by itself demonstrate compliance with them.
Can you do this alongside our existing audit?
Yes, and we usually recommend it. The evidence overlaps substantially with a cybersecurity audit, so running them together means one evidence-gathering exercise, one remediation backlog and one set of interviews for your team.
Sources & references
- Digital Personal Data Protection Act, 2023 — official Gazette text — Act No. 22 of 2023, as published in the Gazette of India
- Digital Personal Data Protection Rules, 2025 — MeitY — notified 13 November 2025 (G.S.R. 843(E)); commences in phases
- CERT-In (Indian Computer Emergency Response Team) — the national nodal agency under Section 70B of the IT Act 2000
- CERT-In Directions under Section 70B(6), 28 April 2022 — the binding directions text — incident reporting, log retention and NTP synchronisation
- MeitY — Data Protection Framework — the administering ministry's own page for the DPDP Act and its rules
- Reserve Bank of India — IT governance, cyber security and outsourcing directions for regulated entities
- Securities and Exchange Board of India — the Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
