CERT-In’s 6-hour incident reporting rule requires service providers, intermediaries, data centres, body corporates and government organisations in India to report mandated cyber security incidents to CERT-In within 6 hours of noticing them. The rule comes from the CERT-In Directions issued on 28 April 2022 under section 70B of the IT Act 2000, and failing to comply can draw up to one year of imprisonment, a fine of up to ₹1 lakh, or both. If you are inside the window right now, our free CERT-In reporting clock shows exactly how much time you have left.
What is CERT-In’s 6-hour incident reporting rule?
The Indian Computer Emergency Response Team (CERT-In) is the national agency for cyber security incident response, appointed under section 70B of the Information Technology Act 2000. On 28 April 2022 it issued directions under that section - in force since late June 2022 - that tightened how organisations operating in India handle cyber incidents. The headline obligation: mandated incident types must be reported to CERT-In within 6 hours of the incident being noticed or brought to your notice.
The directions apply broadly: service providers, intermediaries, data centres, body corporates and government organisations. If your company runs IT systems serving Indian users, assume you are covered. There is no small-business carve-out and no materiality threshold - a minor incident that fits a mandated category is still reportable.
Which incidents must be reported within 6 hours?
The annexure to the directions lists around twenty reportable incident types. In practice, they cluster into these categories:
- Unauthorized access to IT systems or data
- Malware and ransomware attacks
- Phishing and social-engineering attacks
- Data breaches and data leaks
- Denial-of-service and distributed denial-of-service (DoS/DDoS) attacks
- Website defacement and intrusion into applications
- Supply-chain and third-party compromise
- Compromise of cloud services, IoT devices, and SCADA/OT systems
- Targeted scanning and probing of critical networks and systems
- Attacks on digital payment systems and identity infrastructure
The 6-hour duty also exists in sectoral form: SEBI’s CSCRF expects regulated entities to report to SEBI, the exchanges and depositories within 6 hours, and RBI’s framework expects banks to report unusual incidents within 2 to 6 hours. One incident can easily trigger several of these clocks at once.
How does the 6-hour clock actually work?
The clock starts when the incident is noticed or brought to your notice - not when the attacker got in. If a ransomware note appears at 09:00, your deadline is 15:00 the same day, regardless of when the encryption actually began. This is the detail most organisations get wrong: they wait for confirmation, forensics, or a management decision, and the window closes while they deliberate.
Reports go to [email protected]. The initial report must state the incident type, the time of occurrence and of detection, the affected systems and networks, the actions taken so far, and a point of contact. An early report can be updated as the investigation progresses - CERT-In expects a fast first report followed by detail, not a perfect report delivered late. Keep [email protected] copied on material updates until the incident is closed.
Two supporting duties matter as much as the report itself. First, logs of all ICT systems must be retained for 180 days within Indian jurisdiction, and CERT-In can call for them during an investigation. Second, system clocks must be synchronised to NIC/NTP time sources, because timestamps you cannot trust will not survive an investigation.
What happens if you miss the 6-hour deadline?
Section 70B(7) of the IT Act makes failure to provide information called for by CERT-In, or to comply with its directions, punishable with imprisonment for up to one year, a fine of up to ₹1 lakh, or both. The criminal penalty is the floor, not the real exposure: a missed report also converts a containable incident into a compliance failure that regulators, cyber insurers and enterprise customers will all ask about later.
Late reporting with a documented reason is far better than silence. If the window has already passed, report immediately and state why the report is late - discovery timeline, escalation gaps, whatever the facts are. Our CERT-In reporting clock handles this case too: it tells you how far past the deadline you are and what to include in the late report.
CERT-In reporting vs DPDP breach notification
These are separate obligations that often fire on the same incident. CERT-In’s 6-hour rule sits under the IT Act and covers the mandated incident types above. The DPDP Act 2023 separately requires a Data Fiduciary to notify the Data Protection Board and every affected Data Principal of a personal data breach as soon as possible. A ransomware hit that exfiltrates customer data can trigger both clocks, plus sectoral ones from RBI, SEBI or IRDAI. Build your incident runbook so one intake form feeds every obligation, not one scramble per regulator.
Check your own window with the free calculator
The CERT-In 6-hour reporting clock takes three inputs - hours since you noticed the incident, the incident type, and whether you have already reported - and returns the time left in your window, what the report must contain, and the log-retention duty that follows. It runs in your browser; nothing is stored. And if you are inside a live incident and need hands, our incident response team works to a CERT-In aligned methodology with a senior responder on the phone within 30 minutes during Indian business hours.
CERT-In 6-hour reporting FAQ
Does the 6-hour deadline apply to every company in India?
When exactly does the 6-hour clock start?
What is the penalty for not reporting to CERT-In?
Is CERT-In reporting the same as DPDP breach notification?
What must the first report to CERT-In contain?
We already missed the deadline. What now?
Inside the 6-hour window right now?
Call first, read second. A senior responder is on the phone within 30 minutes during Indian business hours, and we work the incident with you until it is contained and reported.

