Guides/6 min read

CERT-In 6-hour incident reporting, explained

The CERT-In directions require reportable cyber incidents to be reported within six hours. Here is what that means in practice and how to never miss the window.

Updated 22 June 2026

The six-hour rule

Under the CERT-In directions of 28 April 2022, organisations must report specified cyber incidents to the Indian Computer Emergency Response Team within six hours of noticing or being made aware of them. The list of reportable incidents is broad, covering data breaches, unauthorised access, and attacks on critical systems.

Logs and time synchronisation

The same directions require ICT system logs to be maintained securely for 180 days within Indian jurisdiction, and systems to synchronise their clocks to a trusted time source. Together these make incident timelines reconstructable and reports credible.

  • ▹Report reportable incidents within 6 hours of detection
  • ▹Retain ICT logs for 180 days, within India
  • ▹Synchronise system clocks to a trusted NTP source

Meeting the clock with Praman

Praman starts a visible six-hour countdown the moment an incident is flagged as cyber-reportable, pre-fills an editable CERT-In report from the incident data, and records every step as tamper-evident evidence. It never auto-sends — submission stays a deliberate human action.

FAQ

When does the 6-hour clock start?

From the point the organisation notices or is made aware of a reportable incident. Praman drives the countdown from the recorded detection time.

How long must logs be kept?

180 days, retained within Indian jurisdiction, per the CERT-In directions.

Turn this obligation into a live check.

Praman evaluates it against your real systems and proves the result.

Request a demo

This guide is general information, not legal advice. Verify obligations with qualified counsel.