Skip to main content

Beta candidates wanted About the beta

← All insights

Individuals

CERT-In’s incident-reporting direction uses a six-hour clock

ASTRA Ready editorial ·

Cover image for CERT-In’s incident-reporting direction uses a six-hour clock

The fact

CERT-In’s directions dated 28 April 2022 require specified entities to report listed cyber incidents within six hours of noticing them or being brought to notice about them. CERT-In’s FAQ, released 18 May 2022, says that when all requested information is not available within that period, entities may report what is available and provide additional information later within a reasonable time. [Sources: CERT-In, 28 April 2022; Press Information Bureau/CERT-In FAQ, 18 May 2022.]

This is a statement of the published directions, not advice on whether a particular customer or event is legally in scope.

What this means for a seller

Know the published clock, but do not turn it into a product-compliance promise. Explain what your product or service detects, records or routes, then let the customer’s authorised security or legal owner decide how the regulatory obligation applies.

Relevant programme: Practise regulatory-fact boundaries through the ASTRA Cybersecurity Sales Specialist programme: https://www.astraready.com/programmes/

Sources