Individuals
CERT-In’s incident-reporting direction uses a six-hour clock
ASTRA Ready editorial ·

The fact
CERT-In’s directions dated 28 April 2022 require specified entities to report listed cyber incidents within six hours of noticing them or being brought to notice about them. CERT-In’s FAQ, released 18 May 2022, says that when all requested information is not available within that period, entities may report what is available and provide additional information later within a reasonable time. [Sources: CERT-In, 28 April 2022; Press Information Bureau/CERT-In FAQ, 18 May 2022.]
This is a statement of the published directions, not advice on whether a particular customer or event is legally in scope.
What this means for a seller
Know the published clock, but do not turn it into a product-compliance promise. Explain what your product or service detects, records or routes, then let the customer’s authorised security or legal owner decide how the regulatory obligation applies.
Relevant programme: Practise regulatory-fact boundaries through the ASTRA Cybersecurity Sales Specialist programme: https://www.astraready.com/programmes/