VITI Security

CERT-In's 6-Hour Incident Reporting Rule: Deadline, Requirements and Free Calculator

by CyberZestJul 24, 2026

CERT-In's April 2022 directions give Indian organisations 6 hours to report mandated cyber incidents. What must be reported, when the clock starts, what it costs to miss, and a free calculator to check your window.

CERT-In's 6-Hour Rule - VITI Security

CERT-In’s 6-hour incident reporting rule requires service providers, intermediaries, data centres, body corporates and government organisations in India to report mandated cyber security incidents to CERT-In within 6 hours of noticing them. The rule comes from the CERT-In Directions issued on 28 April 2022 under section 70B of the IT Act 2000, and failing to comply can draw up to one year of imprisonment, a fine of up to ₹1 lakh, or both. If you are inside the window right now, our free CERT-In reporting clock shows exactly how much time you have left.

What is CERT-In’s 6-hour incident reporting rule?

The Indian Computer Emergency Response Team (CERT-In) is the national agency for cyber security incident response, appointed under section 70B of the Information Technology Act 2000. On 28 April 2022 it issued directions under that section - in force since late June 2022 - that tightened how organisations operating in India handle cyber incidents. The headline obligation: mandated incident types must be reported to CERT-In within 6 hours of the incident being noticed or brought to your notice.

The directions apply broadly: service providers, intermediaries, data centres, body corporates and government organisations. If your company runs IT systems serving Indian users, assume you are covered. There is no small-business carve-out and no materiality threshold - a minor incident that fits a mandated category is still reportable.

Which incidents must be reported within 6 hours?

The annexure to the directions lists around twenty reportable incident types. In practice, they cluster into these categories:

  • Unauthorized access to IT systems or data
  • Malware and ransomware attacks
  • Phishing and social-engineering attacks
  • Data breaches and data leaks
  • Denial-of-service and distributed denial-of-service (DoS/DDoS) attacks
  • Website defacement and intrusion into applications
  • Supply-chain and third-party compromise
  • Compromise of cloud services, IoT devices, and SCADA/OT systems
  • Targeted scanning and probing of critical networks and systems
  • Attacks on digital payment systems and identity infrastructure

The 6-hour duty also exists in sectoral form: SEBI’s CSCRF expects regulated entities to report to SEBI, the exchanges and depositories within 6 hours, and RBI’s framework expects banks to report unusual incidents within 2 to 6 hours. One incident can easily trigger several of these clocks at once.

How does the 6-hour clock actually work?

The clock starts when the incident is noticed or brought to your notice - not when the attacker got in. If a ransomware note appears at 09:00, your deadline is 15:00 the same day, regardless of when the encryption actually began. This is the detail most organisations get wrong: they wait for confirmation, forensics, or a management decision, and the window closes while they deliberate.

Reports go to [email protected]. The initial report must state the incident type, the time of occurrence and of detection, the affected systems and networks, the actions taken so far, and a point of contact. An early report can be updated as the investigation progresses - CERT-In expects a fast first report followed by detail, not a perfect report delivered late. Keep [email protected] copied on material updates until the incident is closed.

Two supporting duties matter as much as the report itself. First, logs of all ICT systems must be retained for 180 days within Indian jurisdiction, and CERT-In can call for them during an investigation. Second, system clocks must be synchronised to NIC/NTP time sources, because timestamps you cannot trust will not survive an investigation.

What happens if you miss the 6-hour deadline?

Section 70B(7) of the IT Act makes failure to provide information called for by CERT-In, or to comply with its directions, punishable with imprisonment for up to one year, a fine of up to ₹1 lakh, or both. The criminal penalty is the floor, not the real exposure: a missed report also converts a containable incident into a compliance failure that regulators, cyber insurers and enterprise customers will all ask about later.

Late reporting with a documented reason is far better than silence. If the window has already passed, report immediately and state why the report is late - discovery timeline, escalation gaps, whatever the facts are. Our CERT-In reporting clock handles this case too: it tells you how far past the deadline you are and what to include in the late report.

CERT-In reporting vs DPDP breach notification

These are separate obligations that often fire on the same incident. CERT-In’s 6-hour rule sits under the IT Act and covers the mandated incident types above. The DPDP Act 2023 separately requires a Data Fiduciary to notify the Data Protection Board and every affected Data Principal of a personal data breach as soon as possible. A ransomware hit that exfiltrates customer data can trigger both clocks, plus sectoral ones from RBI, SEBI or IRDAI. Build your incident runbook so one intake form feeds every obligation, not one scramble per regulator.

Check your own window with the free calculator

The CERT-In 6-hour reporting clock takes three inputs - hours since you noticed the incident, the incident type, and whether you have already reported - and returns the time left in your window, what the report must contain, and the log-retention duty that follows. It runs in your browser; nothing is stored. And if you are inside a live incident and need hands, our incident response team works to a CERT-In aligned methodology with a senior responder on the phone within 30 minutes during Indian business hours.

CERT-In 6-hour reporting FAQ

Does the 6-hour deadline apply to every company in India?
It applies to service providers, intermediaries, data centres, body corporates and government organisations - which in practice covers nearly every company operating IT systems in India. There is no size exemption and no materiality threshold for the mandated incident types.
When exactly does the 6-hour clock start?
When the incident is noticed or brought to your notice, not when it occurred. Detection time is what matters - which is also why monitoring and log retention determine whether you can meet the deadline at all.
What is the penalty for not reporting to CERT-In?
Section 70B(7) of the IT Act 2000: imprisonment for up to one year, or a fine of up to ₹1 lakh, or both, for failing to provide information called for or to comply with CERT-In directions. The reputational and insurance consequences of an unreported incident usually cost more than the statutory penalty.
Is CERT-In reporting the same as DPDP breach notification?
No. CERT-In’s 6-hour rule is an IT Act obligation covering mandated cyber incidents. The DPDP Act separately requires notifying the Data Protection Board and affected Data Principals of a personal data breach as soon as possible. A single incident can trigger both, plus sectoral reporting to RBI, SEBI or IRDAI.
What must the first report to CERT-In contain?
The incident type, the time of occurrence and of detection, the affected systems and networks, the actions taken so far, and a point of contact. Send it to [email protected]. An early report can be supplemented as forensics progress - do not wait for complete information.
We already missed the deadline. What now?
Report immediately and document the reason for the delay - when the incident was discovered, how it escalated internally, and why the report could not go out in time. A late report with an honest timeline is treated very differently from an incident the regulator discovers on its own.

Inside the 6-hour window right now?

Call first, read second. A senior responder is on the phone within 30 minutes during Indian business hours, and we work the incident with you until it is contained and reported.