The six-hour rule
Under the CERT-In directions of 28 April 2022, organisations must report specified cyber incidents to the Indian Computer Emergency Response Team within six hours of noticing or being made aware of them. The list of reportable incidents is broad, covering data breaches, unauthorised access, and attacks on critical systems.
Logs and time synchronisation
The same directions require ICT system logs to be maintained securely for 180 days within Indian jurisdiction, and systems to synchronise their clocks to a trusted time source. Together these make incident timelines reconstructable and reports credible.
- ▹Report reportable incidents within 6 hours of detection
- ▹Retain ICT logs for 180 days, within India
- ▹Synchronise system clocks to a trusted NTP source
Meeting the clock with Praman
Praman starts a visible six-hour countdown the moment an incident is flagged as cyber-reportable, pre-fills an editable CERT-In report from the incident data, and records every step as tamper-evident evidence. It never auto-sends — submission stays a deliberate human action.