Compliance/India/CERT-In Directions
Six directions: three leave evidence in the file.
CERT-In wants incidents reported within six hours and logs kept for 180 days. Vaultize adds records that stay with the data.
- No. 20(3)/2022-CERT-In · 28 Apr 2022
- Effective 60 days from issue
- Capability mapping, not legal advice
The answer in 30 seconds
Vaultize adds file-level records to three directions: six-hour incident reporting, information to CERT-In on order, and 180-day ICT logs. Clock synchronisation, service-provider registration and virtual-asset records belong to other owners.
The Directions in one view
Six directions. Three annexures. Where file evidence lands.
The Directions apply to service providers, intermediaries, data centres, body corporate and Government organisations, with two directions for specific sectors. Select a direction to see what a governed file can evidence.
i
Clock sync
Direction (i). Synchronise all ICT system clocks with the NTP servers of NIC or NPL, or servers traceable to them.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Time sources belong to the infrastructure owner. A governed file adds no evidence here.
- Evidence to retain
- None from Vaultize.
Direction by direction
What each direction asks. What the file can answer.
Direction and Annexure wording is quoted from the CERT-In Directions of 28 April 2022; longer directions are excerpted. Each row is a capability mapping, not legal advice.
Using this page
Where these rows fit under the Directions.
The Directions took effect 60 days after issue. The rows above are evidence for the directions that touch documents.
- 1
Confirm coverage
Service provider, intermediary, data centre, body corporate or Government organisation. Directions (v) and (vi) apply to named sectors.
- 2
Designate the Point of Contact
Direction (iii) and Annexure II. Keep it updated with CERT-In.
- 3
Enable and keep the logs
Direction (iv). 180 days, securely, within India. These rows belong here.
Bring the rows above as evidence of the logs kept and of what the records can say within six hours.
- 4
Report within six hours
Direction (ii) and Annexure I, by email, phone or fax to CERT-In.
- 5
Assist on order
Direction (iii). Provide information in the format and timeframe specified.
Responsibility boundary
Records support the report. They do not make it.
Vaultize contributes file-level records for documents. It does not decide whether an event is a reportable incident, make the report, synchronise clocks, or keep every ICT system’s logs. Read the Directions, CERT-In’s FAQs and the IT Act, and take qualified advice before relying on this page.
“This direction will become effective after 60 days from the date on which it is issued.”
CERT-In Directions, 28 April 2022
Official references
Read the source before relying on the mapping.
Direction and Annexure wording comes from the first item. The second is CERT-In’s own explanation.
- CERT-In Directions under section 70B(6), 28 April 2022No. 20(3)/2022-CERT-In. The six directions and Annexures I to III. Every direction quoted on this page is from it.
- CERT-In FAQs on the Cyber Security Directions, May 2022CERT-In’s explanatory FAQs. They do not replace the Act, the Rules or the Directions.
A practical next step
Bring one document you would have to report on.
We will show what the governed document’s records can say within six hours today. We will name the owner responsible for the rest.
