Quick Answer
Indian IT companies are subject to binding cybersecurity obligations under the Information Technology Act 2000, the CERT-In Directions of April 2022, and the Digital Personal Data Protection Act 2023. The most operationally demanding requirement is CERT-In’s 6-hour incident reporting window, which runs from the moment of detection not from impact assessment. Non-compliance carries penalties up to ₹250 crore under the DPDP Act, in addition to CERT-In enforcement powers.
India’s cybersecurity legal framework has moved decisively from advisory to enforceable. The CERT-In Directions issued in April 2022 imposed mandatory, time-bound obligations on every IT company operating in India. The Digital Personal Data Protection Act 2023 added a parallel layer of data breach accountability. Together, these two frameworks require IT companies to manage cybersecurity not just as a technical function but as a regulated legal obligation with documentary, reporting, and audit requirements attached.
This guide is written for CISOs, CTOs, and IT compliance heads who need operational clarity on what Indian cybersecurity law requires, by when, and with what documentation. We cover the legal framework, CERT-In’s specific compliance obligations, how the CERT-In Directions and the DPDP Act interact during a breach, and the data breach response plan your organization must have in place before an incident occurs.
For the broader legal environment in which these cybersecurity obligations sit, refer to our Legal Framework for IT Companies in India guide.
Legal Framework for Cybersecurity in India
India’s cybersecurity obligations for IT companies arise from four overlapping sources: the IT Act 2000, the CERT-In Directions 2022, the DPDP Act 2023, and sector-specific frameworks issued by financial and critical infrastructure regulators.
IT Act 2000: Section 43A (Data Security) and Section 72A
Section 43A of the Information Technology Act 2000 applies to body corporates that possess, deal with, or handle any sensitive personal data or information in a computer resource that they own, control, or operate. It imposes an obligation to implement and maintain reasonable security practices and procedures. Where a body corporate is negligent in maintaining these practices and causes wrongful loss or gain to any person, it is liable to pay damages.
The Reasonable Security Practices and Procedures Rules 2011, issued under Section 43A, specify that compliance with ISO/IEC 27001 constitutes a recognized security standard. IT companies holding ISO 27001 certification should document this formally in their security governance records.
Section 72A creates criminal liability for disclosure of information, in breach of a lawful contract, with the intent to cause or knowing that it is likely to cause wrongful loss or wrongful gain. It carries imprisonment of up to three years, a fine of up to ₹5 lakh, or both. This provision applies to employees, contractors, and third-party service providers who handle personal information under a contractual arrangement.
CERT-In Directions 2022: Mandatory Incident Reporting
The Ministry of Electronics and Information Technology issued the CERT-In Directions on April 28, 2022, under Section 70B(6) of the IT Act 2000. These Directions are legally binding on all service providers, intermediaries, data centers, body corporates, and government organizations.
The Directions impose five core compliance obligations: mandatory incident reporting within 6 hours of detection, NTP clock synchronization with NIC servers, 180-day log retention, VPN subscriber data retention for 5 years, and annual cybersecurity audits. Each of these is addressed in detail in the section below.
Non-compliance with CERT-In Directions is a criminal offense under Section 70B(7) of the IT Act 2000, carrying imprisonment of up to one year, a fine, or both.
DPDP Act 2023: Reasonable Security Safeguards
The Digital Personal Data Protection Act 2023 requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. The Act does not prescribe a specific technical standard; what constitutes “reasonable” is assessed contextually, based on the volume and sensitivity of data processed, the state of the art in security technology, and the risk profile of the organization’s processing activities.
In the event of a personal data breach, the DPDP Act requires the Data Fiduciary to notify the Data Protection Board of India (DPBI) and affected Data Principals “as soon as possible.” The DPDP Rules 2025 are phasing in the notification framework, with full enforcement anticipated from May 2027. For a detailed analysis of DPDP Act compliance requirements, refer to our DPDP Act Compliance Guide for IT and Tech Companies.
Penalties for breach of the DPDP Act reach up to ₹250 crore per violation. This penalty threshold applies per breach event, not per data record.
Sector-Specific Cybersecurity Frameworks
IT companies serving regulated sectors face additional cybersecurity obligations layered on top of the IT Act and CERT-In framework. The Reserve Bank of India has issued a Master Direction on Information Technology Governance, Risk, Controls, and Assurance Practices, which applies to regulated entities and their technology service providers. SEBI has issued a Cybersecurity and Cyber Resilience Framework for market infrastructure institutions and registered intermediaries. IRDAI has issued cybersecurity guidelines for insurers. CERT-In obligations apply in parallel to all of these sector-specific frameworks; they do not replace them.
CERT-In Mandatory Compliance Requirements: Detailed
6-Hour Incident Reporting: 20 Mandatory Categories
The 6-hour reporting window is the most operationally demanding obligation in the CERT-In Directions. The clock starts from the moment of detection, not from the completion of impact assessment, forensic investigation, or executive sign-off. This distinction is critical and frequently misunderstood.
The CERT-In Directions mandate reporting for 20 specific categories of cyber incidents. These categories are:
- Targeted scanning or probing of critical networks or systems
- Compromise of critical systems or information
- Unauthorized access to IT systems or data
- Defacement of websites or intrusion into a website and unauthorized changes
- Attacks on servers and network infrastructure (DNS, routing, BGP)
- Identity theft, spoofing, and phishing attacks
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
- Attacks on critical infrastructure, SCADA, and operational technology systems
- Attacks on applications, including e-governance and e-commerce applications
- Data breach
- Data leak
- Attacks on Internet of Things (IoT) devices and associated systems
- Attacks on digital payment systems
- Attacks on satellites
- Ransomware attacks
- Botnet attacks
- Attacks on power systems
- Email phishing (not limited to financial fraud)
- Fake mobile apps
- Unauthorized access to social media accounts
Incident reports must be submitted to CERT-In through the designated reporting portal. The report at 6 hours need not be complete; it must be filed. Additional information can be supplemented as it becomes available.
Synchronised ICT System Clocks
All ICT systems within the organization must synchronize their clocks with the National Informatics Centre (NIC) Network Time Protocol (NTP) servers. The designated servers are stratum-1.nic.in and stratum-2.nic.in. Organizations with entities connecting from outside India may use NTP servers of other countries, provided those servers maintain synchronization with the NIC servers.
Clock synchronization is not a technical nicety. Accurate timestamps are foundational to log integrity, forensic chain of custody, and the credibility of any incident report submitted to CERT-In. Unsynchronized clocks have the potential to undermine the evidentiary value of an entire log archive.
180-Day Log Retention
Organizations must retain logs of their ICT systems for a rolling period of 180 days. Logs must be maintained within India’s jurisdiction. Retention on cloud infrastructure hosted outside India does not satisfy this requirement unless the data is simultaneously stored on infrastructure within India.
The log retention obligation applies across system logs, network logs, and application logs. IT companies using multi-cloud or hybrid cloud architectures should audit their log storage configurations explicitly to confirm India-jurisdictional compliance.
Virtual Private Network (VPN) Provider Obligations
VPN service providers are required to maintain subscriber data for 5 years. The subscriber information to be retained includes: validated names of subscribers, period of hire, IPs allotted to members, email addresses and IP addresses used at the time of registration, registration timestamp and purpose for hiring services, validated addresses and contact numbers, and ownership patterns.
This obligation applies to corporate VPN providers and has particular significance for IT companies that operate VPN services as a product. Internal enterprise VPN infrastructure used solely by an organization’s own employees may carry different operational implications, but organizations should obtain legal advice on their specific configuration.
Annual Cybersecurity Audit
Organizations covered by the CERT-In Directions must conduct an annual cybersecurity audit. The audit must be conducted by a CERT-In empaneled auditor. A list of empaneled auditors is maintained on the CERT-In website. Audit reports must be shared with CERT-In and must record compliance status against the Directions.
The annual audit cycle should be integrated into the organization’s broader information security governance calendar, not treated as a standalone compliance event. Organizations pursuing ISO 27001 certification will find significant procedural overlap, but the CERT-In audit is a separate, mandatory regulatory requirement.
DPDP Act + CERT-In: How They Interact on Data Breaches
The CERT-In Directions and the DPDP Act impose parallel, not sequential, obligations when a data breach occurs. An IT company experiencing a breach that qualifies as both a CERT-In reportable incident and a personal data breach must manage both regulatory streams simultaneously.
The interaction produces the following compound obligations on a breach timeline:
Obligation | Framework | Deadline |
Report incident to CERT-In | CERT-In Directions 2022 | Within 6 hours of detection |
Notify DPBI of personal data breach | DPDP Act 2023 | As soon as possible (DPDP Phase III) |
Notify affected Data Principals | DPDP Act 2023 | As soon as possible (DPDP Phase III) |
Coordinate with sector regulator (if applicable) | Sector-specific framework | Per sector regulator’s timeline |
Conduct forensic investigation | CERT-In / internal governance | Ongoing from detection |
Produce post-incident remediation report | Internal governance / CERT-In | Post-containment |
The CERT-In report at 6 hours is a regulatory filing, not a public disclosure. The DPDP Act’s notification obligations to Data Principals are a separate legal requirement that may involve public or individual communication. These must be managed through separate processes and documented independently.
IT compliance heads should note that CERT-In does not notify affected individuals that obligation sits entirely with the Data Fiduciary under the DPDP Act. The two frameworks address different audiences: CERT-In addresses the national cybersecurity response infrastructure; the DPDP Act addresses the rights of affected individuals.
Data Breach Response Plan: What IT Companies Must Have
A documented breach response plan is both a governance best practice and a practical prerequisite for meeting the 6-hour CERT-In reporting window. The following seven-step framework reflects the integrated structure required to satisfy both CERT-In and DPDP obligations simultaneously.
Step 1: Detection and Containment (within 1 hour)
Identify and isolate the affected systems to prevent further unauthorized access or data exfiltration. Log the exact timestamp of detection. This timestamp governs the 6-hour CERT-In reporting deadline.
Step 2: Severity Assessment (within 1 to 2 hours)
Determine whether the incident falls within one or more of the 20 CERT-In reportable categories. Assess whether personal data has been or is likely to have been compromised, triggering DPDP Act notification obligations.
Step 3: CERT-In Notification (within 6 hours of detection)
Submit an incident report to CERT-In through the designated reporting portal. The initial report need not be complete. File it, then supplement with additional detail as the investigation progresses.
Step 4: Forensic Investigation (from detection, ongoing)
Engage internal or external forensic resources to determine the scope, origin, and method of the breach. Preserve all logs and evidence in a manner consistent with forensic chain of custody requirements.
Step 5: DPBI and Data Principal Notification (as soon as possible)
Where personal data has been compromised, notify the Data Protection Board of India and the affected Data Principals in accordance with the DPDP Act. This obligation becomes fully enforceable under DPDP Phase III from May 2027, but organizations should establish notification workflows now.
Step 6: Sector Regulator Coordination (per applicable framework)
Where the organization operates in a regulated sector (banking, insurance, securities), notify the relevant sector regulator within its prescribed timeline. RBI, SEBI, and IRDAI each have separate incident notification requirements that operate alongside CERT-In obligations.
Step 7: Post-Incident Review and Remediation Report
Document the root cause, the scope of impact, the regulatory notifications made, and the remediation steps taken. Prepare a formal post-incident report for submission to CERT-In and for internal governance records. This report also forms the evidentiary basis for any regulatory inquiry that follows.
Cyber Insurance: Compliance Is Not a Substitute
Cyber insurance coverage is increasingly available from Indian and international insurers. It does not replace legal compliance. Coverage typically extends to breach response costs (forensic investigation, legal counsel, notification), business interruption losses, and third-party liability claims.
Policy coverage for regulatory fines requires careful scrutiny. CERT-In penalties and DPDP Act penalties may not be covered under standard policy wording. Organizations should review policy terms specifically against their CERT-In and DPDP obligations before treating insurance as a risk transfer mechanism for regulatory non-compliance.
We recommend that IT companies review their cyber insurance policy wording alongside their legal compliance framework, not as an alternative to it. Altacit Global’s technology law team can assist in aligning policy terms with your specific regulatory exposure.
Build Your Cybersecurity Compliance Framework with Altacit Global
India’s cybersecurity legal obligations are specific, time-bound, and enforceable. The 6-hour CERT-In reporting window, the 180-day log retention requirement, the annual audit obligation, and the DPDP Act’s breach notification framework together create a compliance environment that requires structured preparation, not reactive response.
Altacit Global advises IT companies on CERT-In compliance, DPDP Act cybersecurity obligations, incident response planning, and sector-specific cybersecurity framework alignment. Our technology law team in Bangalore, Hyderabad, and Chennai assists companies in building legally compliant cybersecurity frameworks that are operationally practical and audit-ready. Contact us at info@altacit.com.
Frequently Asked Questions: Cybersecurity Law India
Q1: What are the CERT-In 20 mandatory incident categories?
The CERT-In Directions 2022 specify 20 categories of cyber incidents that must be reported within 6 hours of detection. These include targeted scanning of critical systems, unauthorized access, data breaches, data leaks, ransomware attacks, DDoS attacks, phishing, IoT compromises, attacks on digital payment systems, defacement, identity theft, botnet attacks, and attacks on power and satellite infrastructure. The full list is set out in our CERT-In compliance section above.
Q2: What is the penalty for failing to report a cyber incident to CERT-In?
Non-compliance with the CERT-In Directions 2022 is a criminal offense under Section 70B(7) of the Information Technology Act 2000. It carries imprisonment of up to one year, a fine, or both. CERT-In also has the authority to issue directions and take enforcement action against non-compliant organizations. The penalty structure is separate from, and in addition to, the financial penalties applicable under the DPDP Act 2023.
Q3: Does a company need to notify customers after a data breach in India?
Under the Digital Personal Data Protection Act 2023, Data Fiduciaries must notify both the Data Protection Board of India and affected Data Principals “as soon as possible” following a personal data breach. This obligation is being phased in under the DPDP Rules 2025, with full enforcement from May 2027. CERT-In reporting, by contrast, is directed at the national cybersecurity authority and does not constitute notification to affected individuals. Both obligations apply independently and must be managed through separate workflows.
Q4: What does "reasonable security safeguard" mean under the DPDP Act?
The Digital Personal Data Protection Act 2023 does not prescribe a specific technical standard for reasonable security safeguards. The standard is assessed contextually, taking into account the volume and sensitivity of personal data processed, the current state of available security technology, and the organization’s risk profile. Compliance with ISO/IEC 27001, as recognized under the IT (Reasonable Security Practices and Procedures) Rules 2011, provides a strong evidentiary basis. Organizations should document their security controls, conduct regular risk assessments, and align their practices with recognized standards.



