HomeFrameworksNational Cyber & Cloud SchemesCERT-IN

Framework  National Cyber & Cloud Schemes

CERT-IN

CERT-In is the Indian Computer Emergency Response Team, the national agency under the Ministry of Electronics and Information Technology. In compliance lists the label refers to the binding Cyber Security Directions CERT-In issued on April 28, 2022 under Section 70B(6) of the Information Technology Act, 2000, which took effect sixty days later.

The directions require service providers, intermediaries, data centers, body corporates, and government organizations to report a listed set of cyber incidents to CERT-In within six hours of noticing them; to synchronize system clocks to Indian time sources; to keep logs of all ICT systems for a rolling 180 days within India; and to designate a point of contact.

Virtual private server, cloud, and VPN providers must keep subscriber records for five years, and virtual asset providers must keep KYC and transaction records. CERT-In also runs an empanelment scheme for information security auditing organizations that Indian regulators and government bodies use for mandated audits.

In writing, an in-scope organization needs an incident response procedure that meets the six-hour clock (including who decides what is reportable and how the CERT-In form is filed), a log management policy proving 180-day retention in India, NTP configuration standards, the designated contact registration, and for the named provider categories the customer record retention procedures.

Organizations subject to sectoral audits (for example under SEBI or RBI rules) need audit reports from CERT-In empanelled auditors.

AI-compiled
Share
Sponsored
CERT-IN
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CERT-IN
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Any service provider, intermediary, data center, body corporate, or government organization operating in India or serving Indian users, with specific additional duties for VPS, cloud, and VPN providers and virtual asset service providers. Company size does not matter; some duties were clarified through FAQs, including a carve-out for enterprise VPNs.

What the assessor asks to see

Incident response procedure and reporting workflow with sample CERT-In submissions; incident register with detection and report timestamps; log management policy and evidence of 180-day retention in Indian jurisdiction; NTP configuration; designated point of contact registration; customer record retention procedures for VPS, cloud, VPN, and virtual asset providers; audit reports from empanelled auditors where required; vulnerability management and remediation records.

Assessors

Who assesses CERT-IN

CERT-In itself supervises and can request information; CERT-In empanelled information security auditing organizations conduct audits where a regulator or government body requires one (for example for government websites and applications and certain regulated sectors). The empanelment is a public list maintained by CERT-In.

Accredited by CERT-In empanels auditing organizations directly through periodic empanelment rounds.

Public register of assessors: https://www.cert-in.org.in/PDF/Empanel_org.pdf

No firm has claimed a CERT-IN assessor listing yet. Claim yours →

Consultants

Who helps with CERT-IN

Indian cybersecurity consultancies, managed SOC providers, and CERT-In empanelled auditors help organizations design reporting workflows, log retention architectures, and compliance documentation. Engagements range from a few weeks for a gap assessment to ongoing managed logging services.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CERT-IN consultant listing yet. Claim yours →

Software

Tools for CERT-IN

Tools that name this framework in their own material.

No firm has claimed a CERT-IN tool listing yet. Claim yours →

Related reading

  1. 2022 CERT-In directions on reporting cyber incidentsSets out the six-hour reporting clock, the 180-day log retention duty and who the directions actually reach.Trilegal
  2. CERT-In directionsIndian counsel on the reportable incident categories, the India log-storage requirement and the penalties for missing them.AZB & Partners
  3. Internet impact brief: India CERT-In cybersecurity directions 2022Independent critique of what the directions demand of VPN, cloud and crypto intermediaries and why that proved contentious.Internet Society

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CERT-IN

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CERT-IN

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.