data-page="blog">
← All articles
Compliance

CERT-In 2022 Directions: A 2026 Compliance Checklist for Indian Enterprises

CERT-In 2022 Directions: A 2026 Compliance Checklist for Indian Enterprises

CERT-In's April 2022 directions reshaped how Indian organisations log, retain, and report security incidents. Four years on, they remain the baseline every enterprise auditor checks first. Here is a practical checklist to stay ready.

What the CERT-In directions actually require

The directions apply to companies, intermediaries, data centres, and government bodies operating in India. Three obligations carry the most weight in audits: mandatory incident reporting within six hours of detection, retention of logs for 180 days within Indian jurisdiction, and synchronisation of all system clocks to NTP servers traceable to NPL or NIC.

The intent is faster national visibility into attacks. The practical effect is that your logging, time-keeping, and incident-response runbooks all need to be provably in place, not just documented.

The six-hour reporting clock

Six hours is short. Most teams miss it not because they lack a process, but because detection-to-escalation is slow. Pre-build the report template, pre-assign the reporting owner, and rehearse the path from SOC alert to CERT-In submission.

A SIEM with correlation rules tuned to your environment is the difference between detecting an incident in minutes versus days. NetSentry SIEM ships with CERT-In-aligned alerting so the clock starts when it should.

Your 2026 readiness checklist

Run through these before your next audit:

Where teams still slip

The common gaps are stale NTP configuration on legacy OT devices, logs that roll over before 180 days under storage pressure, and an incident-reporting owner who has left the company. Treat the checklist as a quarterly review, not a one-time project.

Infographic

The six-hour reporting clock

DetectT + 0 Triage & confirmby T + 1h Escalate to ownerby T + 3h Report to CERT-Inby T + 6h
The directions mandate reporting within six hours of detection. Pre-built templates and a named owner keep every stage inside the window.
By the numbers

Time from detection to CERT-In report

CERT-In 6-hour window ~28 hrs Manual triage ~3 hrs NetSentry SIEM
Illustrative. Tuned correlation collapses detection-to-report time so the submission lands well inside the mandated six hours, instead of a day later.

See it in your environment

Talk to a NetSense security architect about applying this to your stack.

Get a Demo