CERT-In's April 2022 directions on information security practices created one of the most demanding incident response requirements in the world: organisations must report cyber incidents to CERT-In within six hours of detection. Not six hours of the incident occurring — six hours of detection. The distinction matters, because it means the requirement is directly coupled to how fast your organisation can detect that something has gone wrong.
The 2022 directions apply to service providers, intermediaries, data centres, body corporates, and government organisations. They sit alongside, and are separate from, sector-specific regulations such as RBI's Master Direction. An organisation that is already RBI-regulated must satisfy both.
What the 6-hour rule actually requires
The 6-hour reporting window applies to a specific list of incident categories, including data breaches, ransomware attacks, phishing campaigns, unauthorised access to IT systems and data, attacks on critical infrastructure, and denial-of-service attacks above defined thresholds. The report must go to CERT-In directly, not through an intermediary or a sector regulator.
The practical implication is that organisations must have a detection and response capability fast enough to identify a reportable incident, classify it, and route it to the team with authority to file a CERT-In report — all within six hours. The IBM breach detection average of 181 days is the opposing data point: most organisations cannot currently detect breaches fast enough to meet the 6-hour window.
The log retention requirement
The 2022 directions require organisations to maintain logs of ICT systems for 180 days within Indian jurisdiction. This is not a recommendation — it is a legal requirement, and the logs must be maintained in India, not in offshore data centres or global logging platforms that store data outside the country.
The 180-day requirement creates a challenge for organisations that use global SIEM platforms with data residency in the United States or Europe. Forwarding logs to an offshore system for storage or analysis means the primary copy may not be in India. Many organisations address this with a local log archive that satisfies the residency requirement, forwarded to a global SIEM for analysis — a two-tier architecture that adds cost and operational complexity.
Empanelled auditors and the Safe to Host requirement
CERT-In maintains an empanelled list of organisations authorised to conduct VAPT assessments for compliance purposes. The empanelment criteria include technical capability, professional qualifications, and operational security of the auditing organisation itself. An assessment conducted by a non-empanelled entity does not satisfy the CERT-In compliance requirement, regardless of its technical quality.
The Safe to Host certification — issued by CERT-In upon successful completion of a VAPT assessment — is increasingly required by clients and partners as a condition of doing business. It functions similarly to a compliance attestation: it confirms that an independent, empanelled auditor has assessed the organisation's infrastructure and found it meets the minimum security baseline.
What good looks like
An organisation that genuinely satisfies the CERT-In requirements has four things in place: a detection capability fast enough to identify reportable incidents within the six-hour window; a log architecture that stores 180 days of ICT logs within India; a VAPT programme that uses empanelled auditors and completes re-testing after remediation; and an incident response plan that has been exercised, not just documented.
The VAPT component is the most visible element because it is the one that produces a report that auditors can review. But the detection speed requirement is the most operationally demanding, because it requires not just the right tools but the right processes and the right team availability to act within six hours at any time of day or night.
Continuous testing and the compliance programme
Continuous security validation directly supports CERT-In compliance in two ways. First, it reduces the attack surface that would generate reportable incidents by finding and closing exploitable paths before attackers reach them. Second, it generates continuous evidence of security posture that can be presented to CERT-In auditors as evidence of an ongoing programme, not just a point-in-time assessment.
An organisation that runs continuous testing can demonstrate to an empanelled auditor that its security posture is assessed and maintained on an ongoing basis. The annual VAPT becomes a formal attestation of a programme that is already running, rather than a standalone exercise that produces findings no one has seen before.
Close your security gaps — continuously.
Arxiis maps every finding directly to CERT-In requirements, runs entirely on-premise within your Indian jurisdiction, and generates board-ready reports that satisfy empanelled auditor review. Continuous testing means your compliance posture is maintained, not just assessed.