Skip to main content

Beta candidates wanted About the beta

← All insights

Individuals

India incident-reporting rules: the facts a cybersecurity seller should know

ASTRA Ready editorial ·

Cover image for India incident-reporting rules: the facts a cybersecurity seller should know

A buyer asks, “What are the reporting timelines in India?” That is not the moment for a seller to improvise legal advice.

The useful response is to know the dated public facts, state them accurately, and route interpretation to the customer’s or supplier’s authorised legal, privacy or security owner.

This article does exactly that. It does not interpret whether a particular organisation, incident or product is legally in scope.

CERT-In: the 2022 directions

CERT-In published directions under section 70B of the Information Technology Act on 28 April 2022. The official CERT-In page identifies them as directions relating to information-security practices, procedures, prevention, response and reporting of cyber incidents. [Source: CERT-In, 28 April 2022.]

The directions include a requirement for specified entities to report listed cyber incidents to CERT-In within six hours of noticing them or being brought to notice about them. [Source: CERT-In, 28 April 2022.]

That six-hour figure is often repeated in sales conversations. The important discipline is not to detach it from the directions themselves.

A salesperson should not decide on the spot whether a customer’s event meets the reporting criteria. The correct commercial behaviour is to recognise the published rule, identify the customer or supplier owner responsible for incident handling, and make sure product claims about notification or workflow are supported by the actual service terms and operating design.

CERT-In FAQs: incomplete information can be supplemented

The Press Information Bureau announced CERT-In’s FAQ document on 18 May 2022. The FAQ explains scope, reporting method, time frames, logging and other aspects of the directions. [Source: Press Information Bureau, 18 May 2022.]

One FAQ addresses what happens if all information requested in the incident-reporting form is not available within the six-hour period. CERT-In states that entities may report the information available at that time and provide additional information later within a reasonable time. [Source: CERT-In FAQ, released 18 May 2022.]

For sellers, the fact matters because incident-response conversations should separate two things: the reporting clock and the completeness of the information available at the first report.

Do not turn that into a promise that your product, service or managed team will make a regulatory determination for the customer unless the contract and operating scope explicitly say so.

DPDP: the commencement timeline is phased

The Digital Personal Data Protection Rules, 2025 were published in the Gazette on 13 November 2025. The Gazette text sets different commencement points for different rules. [Source: Ministry of Electronics and Information Technology, Gazette G.S.R. 846(E), 13 November 2025.]

Rules 1, 2 and 17 to 21 came into force on the date of Gazette publication. Rule 4 is stated to come into force one year after publication. Rules 3, 5 to 16, 22 and 23 are stated to come into force eighteen months after publication. [Source: Ministry of Electronics and Information Technology, 13 November 2025.]

The Press Information Bureau also announced the notified DPDP Rules on 14 November 2025 and described the Act-and-Rules framework. [Source: Press Information Bureau, 14 November 2025.]

For a page published on 11 October 2026, the one-year and eighteen-month commencement points described in that Gazette have not yet both arrived. [Source: Ministry of Electronics and Information Technology, Gazette G.S.R. 846(E), 13 November 2025.] This is only a calendar reading of the published notification; it is not a view on legal obligations for any particular customer.

What should a seller say?

Start by separating the customer’s question.

If the buyer asks, “What does the law require us to do?”, that is a legal or compliance question and should go to the authorised owner.

If the buyer asks, “Can your service detect an event quickly enough for our process?”, that is a product-and-operating question. Answer it from documented capability and service evidence.

If the buyer asks, “Who sends a notification?”, identify the contractual and operational owner instead of assuming that the software supplier, reseller or managed-service provider does it.

If the buyer asks, “Can you guarantee compliance?”, do not replace a legal assessment with a product claim.

Why this matters commercially

Regulatory pressure can make deals move quickly, but speed does not change authority.

A salesperson can help by keeping dates, source documents and product facts accurate. The seller can also make open dependencies visible: who monitors, who investigates, who decides an event is reportable, who communicates externally and what evidence the product supplies.

That is more useful than memorising a list of regulations.

The boundary is simple: know the published facts, understand what your product and service actually do, and send interpretation to the people authorised to make it.

Next step: Explore the ASTRA Cybersecurity Sales Specialist programme for practice in keeping regulatory facts, product evidence and customer authority separate: https://www.astraready.com/programmes/

Sources