
CERT-In's April 2022 directions reshaped how Indian organisations log, retain, and report security incidents. Four years on, they remain the baseline every enterprise auditor checks first. Here is a practical checklist to stay ready.
What the CERT-In directions actually require
The directions apply to companies, intermediaries, data centres, and government bodies operating in India. Three obligations carry the most weight in audits: mandatory incident reporting within six hours of detection, retention of logs for 180 days within Indian jurisdiction, and synchronisation of all system clocks to NTP servers traceable to NPL or NIC.
The intent is faster national visibility into attacks. The practical effect is that your logging, time-keeping, and incident-response runbooks all need to be provably in place, not just documented.
The six-hour reporting clock
Six hours is short. Most teams miss it not because they lack a process, but because detection-to-escalation is slow. Pre-build the report template, pre-assign the reporting owner, and rehearse the path from SOC alert to CERT-In submission.
A SIEM with correlation rules tuned to your environment is the difference between detecting an incident in minutes versus days. NetSentry SIEM ships with CERT-In-aligned alerting so the clock starts when it should.
Your 2026 readiness checklist
Run through these before your next audit:
- 180-day log retention enforced and stored on Indian soil
- All clocks synced to NPL/NIC-traceable NTP
- Six-hour incident report template and named owner ready
- Annual VAPT and findings remediation tracked
- Evidence collection automated across your security tools
- Tabletop exercise run in the last 90 days
Where teams still slip
The common gaps are stale NTP configuration on legacy OT devices, logs that roll over before 180 days under storage pressure, and an incident-reporting owner who has left the company. Treat the checklist as a quarterly review, not a one-time project.
The six-hour reporting clock
Time from detection to CERT-In report
See it in your environment
Talk to a NetSense security architect about applying this to your stack.