Frameworks · India regulatory

CERT-In Directions compliance, run as a living system

CERT-In's cyber security directions set binding obligations for reporting specified cyber incidents within six hours of noticing them, retaining ICT logs for a rolling 180 days within the country, synchronising system clocks to national time sources, and maintaining a designated point of contact.

Who it applies to

Service providers, intermediaries, data centres, body corporates and government organisations operating in India, including cloud and managed service providers serving Indian entities.

What it demands

Incident reporting

Specified incident types notified within six hours of noticing, to the designated authority, from a named point of contact.

Log retention

ICT system logs maintained for a rolling 180 days and produced on request.

Time synchronisation

System clocks synchronised to the designated national time sources.

Contact and records

Point of contact registered and kept current; subscriber and customer records maintained where applicable.

How Compli-Once runs it

  • 1

    The six-hour window runs as a live countdown on the incident record, timestamped from detection to notification.

  • 2

    Log retention and clock synchronisation are held as controls with owners, evidence and expiry, not as tribal knowledge.

  • 3

    Notification drafts assemble from the incident record, so the filing and the facts never diverge.

What you already satisfy

CERT-In Directions overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

What do the CERT-In directions require?

They require specified cyber incidents to be reported within six hours of being noticed, ICT logs to be retained for a rolling 180 days in-country, system clocks to be synchronised to national time sources, and a designated point of contact to be maintained.

How is the six-hour clock managed?

It starts on the incident record at detection. The owner, deadline and notification trail live on the same record, so the filing is assembled from evidence rather than reconstructed afterwards.

Does this overlap with sector mandates?

Substantially. Reporting and logging obligations map across sector cyber mandates and ISO 27001, so one implementation satisfies each framework it is mapped to.

Can retention evidence be automated?

Retention configuration and periodic verification are held as controls with evidence and expiry dates, so a lapse raises a task before it becomes a finding.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.