Skip to content

CERT-In's April 2022 Directions Already Apply to You

Who this is for: CTO / Head of Engineering / DPO at an Indian SaaS company, any size.

Most Indian companies treat cybersecurity compliance as a 2027 problem, something that starts when DPDP Act enforcement begins. It isn't. A separate set of obligations has been in force since April 2022, and it doesn't wait for a data breach or a sector regulator to apply to you.

The Directions under Section 70B

On 28 April 2022, CERT-In issued Directions under Section 70B of the Information Technology Act. The document applies to "body corporate," a term it doesn't define, so it carries the meaning set out in the Explanation to Section 43A of the IT Act: any company, and also any firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities. That's broader than "incorporated company" alone. No sector carve-out. No size threshold. No licence class required.

Four of the six requirements apply directly to any Indian body corporate, today:

  1. Time synchronisation. ICT systems must sync to NIC or NPL time servers.
  2. 6-hour incident reporting. Any of 20 listed incident types (Annexure I: data breach, unauthorized access, DDoS, phishing, ransomware, among others) must be reported to CERT-In within 6 hours of detection.
  3. A designated Point of Contact with CERT-In (Annexure II).
  4. 180-day log retention, stored within Indian jurisdiction, and produced to CERT-In on request.
Four of the six requirements apply directly to any Indian body corporate, today.

Two further directions are narrow and entity-specific: 5-year subscriber records for data centre/VPS/cloud/VPN providers, and 5-year KYC/transaction records for virtual asset service providers. They don't generalize to a typical SaaS company. The four above do.

The July 2025 audit guidelines raise the stakes on evidence

In July 2025, CERT-In published its Comprehensive Cyber Security Audit Policy Guidelines (v1.0, dated 25.07.2025). Section 15 states that "verification of compliance to CERT-In direction ... dated 28 April 2022" must be included in "every audit assignment," with "relevant evidences" in the audit report. Section 4 scopes this to empanelled auditing organizations and auditee organizations "in both the public and private sectors"; Section 6 sets the cadence at least annually.

Whether this specific audit mandate applies to any given company is a scoping question this post doesn't resolve. It depends on your sector, your existing audit obligations, and definitions the guidelines themselves set out. What's not in question is the underlying 2022 Directions: those already apply, audit mandate or not.

The throughline is this: CERT-In's own guidance treats "we have controls" as insufficient. The bar is evidence, produced on demand, tied to the specific requirement, and dated. (For a broader look at what "produced on demand" evidence looks like for DPDP requirements specifically, see Juro's DPDP Technical Evidence Handbook. CERT-In evidence and DPDP evidence are separate obligations, but the underlying discipline is the same.)

Does this apply to my company?

If you run a company, firm, or sole proprietorship engaged in commercial or professional activity in India, the April 2022 Directions already apply to you: no sector, size, or licence exemption. What's genuinely unresolved is narrower: whether the July 2025 annual-audit-and-verification mandate applies to your specific audit cycle. That depends on your sector and existing audit obligations, and this post doesn't resolve it for you.

Detection tools answer a different question

Most companies that have looked at this have EDR, XDR, or SIEM tooling in place. That tooling answers "were we attacked, and did we detect it." It does not answer "can we produce, right now, evidence that our logs cover the last 180 days," "can we show our NTP configuration points to NIC/NPL servers," or "do we have a record of every incident report filed within the 6-hour window."

Those are three separate, specific, checkable facts. None of them show up in a SIEM dashboard by default. And CERT-In's Point of Contact requirement is a designation an organization makes internally. It's not something an outside party can verify by inspecting a company's systems, and this post makes no claim that it can be.

What this means in practice

Read the 28 April 2022 Directions directly if you haven't. They're short. Then check, specifically:

An EY India survey found more than 83% of organizations have not begun comprehensive implementation of the DPDP Act's requirements. CERT-In's Directions are a different statute with a different timeline, already in force, not phased in, and the same readiness gap likely applies. This post doesn't claim your company is or isn't meeting these requirements. That's a determination only you can make by checking the four items above against your own systems.

Frequently asked questions

What counts as a "body corporate" under CERT-In's Directions?

Any company, plus any firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities, per the Explanation to Section 43A of the IT Act, 2000. It's broader than "incorporated company."

Does the July 2025 annual audit mandate apply to every company covered by the 2022 Directions?

Not necessarily. The audit guidelines scope to empanelled auditing organizations and auditee organizations, at least annually, but whether that reaches your specific company depends on your sector and existing audit obligations. This post doesn't resolve that question for you.

Do I need to report every security incident to CERT-In within 6 hours?

Only incidents matching one of the 20 types listed in Annexure I of the April 2022 Directions (data breach, unauthorized access, DDoS, phishing, ransomware, among others), not every security event.

Can a scanning tool verify whether my company has a CERT-In Point of Contact designated?

No. That's an internal organizational designation, not something an outside party can verify by inspecting your systems.

About Juro

Check your own DPDP-relevant configuration

Juro (not to be confused with juro.com, a contract platform) runs non-custodial scans that produce signed, deterministic evidence of DPDP-relevant configuration: consent banners, cookie behaviour, CSP headers, and similar. Built for engineering teams who need to show their compliance work, not just claim it. Juro's scanner does not check NTP sync, incident-reporting timing, log retention, or CERT-In Point of Contact designation: the four items above are outside its scope.

Scan your site →

Share this article
LinkedIn X Email