Key takeaways
- The CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the IT Act, require covered entities to report 20 listed types of cyber incident within 6 hours of noticing them.1
- The same Directions require logs of all ICT systems to be kept securely for a rolling 180 days, and system clocks to be synced with NIC or NPL time servers or a source that does not drift from them.1
- Data centres, VPS, cloud and VPN providers must keep validated customer records for 5 years, and virtual asset providers must keep KYC and transaction records for 5 years.1
- SEBI's CSCRF says its audits must be done by CERT-In empanelled auditing organisations, and CERT-In's 2025 audit policy says a cyber security audit should happen at least once a year.148
- Not following a CERT-In direction can lead to up to one year in prison, a fine of up to ₹1 crore since the Jan Vishwas Act 2023, or both.45
- CERT-In tracked 29,44,248 cyber security incidents in 2025, up from 15,92,917 in 2023.17
It is 2:10 on a Sunday morning. An alert says a database server is sending data to an address nobody recognises. The on-call engineer is not sure it is real. The security head is asleep. Nobody knows who talks to CERT-In. In India, that alert may already have started a legal clock. If the event is one of the 20 incident types CERT-In lists, your organisation has six hours from the moment it was noticed to report it. Most teams learn the rule during their first real incident. This guide is for teams that would rather learn it now.
Last reviewed on 8 October 2026 against the CERT-In Directions (28 April 2022), CERT-In's FAQs (May 2022), the Comprehensive Cyber Security Audit Policy Guidelines (25 July 2025), SEBI CSCRF and Section 70B of the IT Act.
What are the CERT-In guidelines?
CERT-In guidelines is a loose name for two kinds of documents from India's national cyber agency. The binding one is the set of Cyber Security Directions dated 28 April 2022, issued under Section 70B(6) of the IT Act. The others, such as the 2025 audit policy and SBOM guidance, set good practice that regulators and buyers often adopt.
CERT-In is the Indian Computer Emergency Response Team. It sits under the Ministry of Electronics and Information Technology (MeitY). Section 70B(4) of the IT Act gives it jobs such as collecting information on cyber incidents, issuing alerts and coordinating response. Section 70B(6) lets it call for information and give directions to service providers, intermediaries, data centres, body corporates and any other person.4 That second power is where the 6-hour rule comes from.
- Direction vs guideline
- A direction under Section 70B(6) is a legal order. Failing to follow it is an offence under Section 70B(7). A guideline explains good practice. It becomes binding for you only when a law, a regulator or a contract says so.
People search for "CERT-In guidelines" when they mean any of the documents below. Knowing which one you are reading saves a lot of confusion in audit meetings.
| Document | Date | Legal weight | What it covers |
|---|---|---|---|
| Cyber Security Directions, No. 20(3)/2022-CERT-In | 28 April 2022 | Direction under Section 70B(6)1 | 6-hour reporting, 180-day logs, clock sync, point of contact, 5-year customer and KYC records |
| FAQs on the Directions | May 2022 | Official clarification2 | Scope, partial reports, where logs may sit, which logs |
| Extension notice | 27 June 2022 | Timeline change3 | MSMEs and subscriber validation moved to 25 September 2022 |
| Guidelines on Information Security Practices for Government Entities | June 2023 | For government entities67 | CISO, audits, logs, clock sync, 6-hour reporting |
| Technical Guidelines on SBOM, QBOM and CBOM, AIBOM and HBOM, v2.0 | 9 July 2025 | Guidance ("encouraged", "should")9 | Bills of materials for software, crypto, AI and hardware in procurement |
| Comprehensive Cyber Security Audit Policy Guidelines, v1.0 | 25 July 2025 | Guideline for empanelled auditors and auditees8 | Audit at least yearly, 26 engagement types, audit data handling |
| Guidelines on AI-Accelerated Vulnerability Protection for OEMs and Technology Providers, v1.0 | 10 June 2026 | Advisory ("should")10 | Telling customers and CERT-In about critical and high severity flaws at once |
This article focuses on the first three rows, because they carry the penalties, and on the empanelled auditor question, because regulators have turned it into a hard rule in several sectors.
Who must follow the CERT-In directions?
The CERT-In directions apply to service providers, intermediaries, data centres, body corporates and government organisations. CERT-In's FAQs say a body corporate includes any company, firm, sole proprietorship or association in business, and that the directions also reach foreign firms serving Indian customers. Individual citizens are not covered.
In practice, that covers almost every business with IT systems. A two-person consultancy is a body corporate under the FAQ's definition. So is a listed bank. The FAQs answer the foreign-firm question in plain terms: the Directions "are applicable to any entity whatsoever, in the matter of cyber incidents and cyber security incidents".2
Extra duties for some types of entity
- Everyone covered: sync clocks, report listed incidents within 6 hours, name a point of contact, keep 180 days of logs, and share information when CERT-In asks.1
- Data centres, VPS providers, cloud service providers and VPN service providers: keep validated customer details for 5 years or longer if the law requires it.1
- Virtual asset service providers, exchanges and custodian wallet providers: keep KYC details and financial transaction records for 5 years.1
- Government entities: follow CERT-In's 2023 guidelines as well, which ask for a named CISO, internal audits at least every 6 months and third-party audits at least once a year.6
The Directions took effect 60 days after issue. On 27 June 2022, CERT-In gave micro, small and medium enterprises until 25 September 2022. It gave the same date to data centre, VPS, cloud and VPN providers for validating customer names and contact details.3 Both deadlines passed long ago, so no one gets extra time now.
Your regulator adds its own clock
The CERT-In rule does not replace sector rules. It stacks on top of them. RBI's 2026 Directions for commercial banks require cyber incidents to be reported on its DAKSH platform within six hours.19 SEBI's CSCRF asks regulated entities to report incidents through the SEBI incident reporting portal.14 The DPDP Rules, 2025 require data fiduciaries to tell affected people about a personal data breach without delay.20 See our guides to the RBI Cyber Security Directions 2026 for banks and NBFCs and the DPDP Rules security safeguards checklist for those clocks.
Not legal advice. This guide explains what the CERT-In documents say, with clause references, as of 8 October 2026. CERT-In can issue new directions or change reporting formats at any time. Check the latest text on cert-in.org.in and ask your counsel before you rely on any reading here.
What is the CERT-In 6-hour reporting rule?
The CERT-In 6-hour rule is direction (ii) of the 28 April 2022 Directions. Any covered entity must report the incident types in Annexure I to CERT-In within 6 hours of noticing the incident or being told about it. CERT-In's FAQs allow a first report with the facts known at that time and more details later.
The exact words are that entities "shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents".1 Three parts of that sentence matter most.
When does the clock start?
The clock starts at "noticing" or "being brought to notice". It does not wait for a root cause, a forensic report or a board call. A customer email, a partner warning, a threat intel alert or a SOC ticket can all count as being brought to notice. Our reading is simple. Treat the first credible sign that reaches someone with a duty to act as T+0, and write that time down.
The six-hour clock starts when you notice, not when you are sure.Arxiis Research
You can report what you know
CERT-In's FAQs deal with the fear of reporting too early. If the full reporting form cannot be filled in within 6 hours, "the entities may provide information to the extent available at the time of reporting. Additional information may be reported later within reasonable time to CERT-In."2 A short, honest first report on time beats a complete report that arrives late.
How to report
The Directions list three channels: email to incident@cert-in.org.in, phone on 1800-11-4949, and fax on 1800-11-6969.1 CERT-In also publishes an incident reporting form on its website. The FAQs say the methods and formats are published at cert-in.org.in and "will be updated from time to time", so check the site when you build your runbook, not during the incident.2
Six hours is long for an attacker
Six hours sounds tight for a compliance team. For an attacker it is a long time. CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time, from first access to moving across the network, at 29 minutes.21 By the time you file, the attacker may have moved several times. That is why the playbook below puts containment before paperwork, and why the best way to meet the rule is to have fewer incidents to report. Our post on 194 days of attacker dwell time explains what happens when detection is slow.
Which incidents must be reported to CERT-In?
Annexure I of the CERT-In directions lists 20 types of cyber security incident that must be reported within 6 hours. They range from targeted scanning of critical systems and ransomware to data leaks, fake mobile apps, and attacks on cloud, IoT and AI systems. CERT-In's FAQs also ask entities to report serious incidents that are not on the list.
The table groups the 20 items so a triage team can scan them fast. The item numbers and wording follow Annexure I.1
| Group | Annexure I item | In plain words |
|---|---|---|
| Intrusion | i. Targeted scanning/probing of critical networks/systems | Someone is mapping your key systems on purpose |
| Intrusion | ii. Compromise of critical systems/information | An attacker has control of an important system or data |
| Intrusion | iii. Unauthorised access of IT systems/data | Someone got in who should not have |
| Intrusion | iv. Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc. | Your website was changed or planted with bad code |
| Intrusion | vi. Attack on servers such as Database, Mail and DNS and network devices such as Routers | Core servers or network gear under attack |
| Malware | v. Malicious code attacks such as spreading of virus/worm/Trojan/Bots/Spyware/Ransomware/Cryptominers | Any malware outbreak, including ransomware |
| Identity and fraud | vii. Identity Theft, spoofing and phishing attacks | Phishing, fake senders, stolen identities |
| Identity and fraud | xvii. Unauthorised access to social media accounts | Your brand's social accounts were taken over |
| Identity and fraud | xiv. Attacks or incident affecting Digital Payment systems | UPI, cards, wallets or payment gateways hit |
| Availability | viii. Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks | Services flooded or knocked offline |
| Data | xi. Data Breach | Data was accessed or taken by an attacker |
| Data | xii. Data Leak | Data was exposed, for example an open storage bucket |
| Critical systems | ix. Attacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks | Plant, grid, OT or Wi-Fi attacks |
| Applications | x. Attacks on Application such as E-Governance, E-Commerce etc. | Customer-facing apps under attack |
| Mobile | xv. Attacks through Malicious mobile Apps | A harmful app targets your users or staff |
| Mobile | xvi. Fake mobile Apps | Someone publishes an app pretending to be yours |
| Emerging tech | xiii. Attacks on Internet of Things (IoT) devices and associated systems, networks, software, servers | Cameras, sensors, smart devices |
| Emerging tech | xviii. Attacks or malicious/suspicious activities affecting Cloud computing systems/servers/software/applications | Cloud accounts, workloads or SaaS |
| Emerging tech | xix. Attacks or malicious/suspicious activities affecting systems related to Big Data, Block chain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones | Crypto, blockchain, robotics and drone systems |
| Emerging tech | xx. Attacks or malicious/suspicious activities affecting systems related to Artificial Intelligence and Machine Learning | AI models, agents and ML pipelines |
Note the words "malicious/suspicious activities" in items xviii to xx. For cloud, AI and similar systems, the list does not wait for a confirmed attack. Suspicious activity is enough to be in scope.
The list is a floor, not a ceiling. CERT-In's FAQs say entities must also report incident types that are not in Annexure I, "considering the nature, severity and impact of the incident".2 Agree in advance what "targeted" scanning means for your critical systems, since routine internet noise hits every public IP all day. Write the rule down so the on-call engineer does not have to guess at 2 a.m.
What are the log retention and clock sync rules?
The CERT-In log retention rule requires logs of all ICT systems to be enabled and kept securely for a rolling 180 days within Indian jurisdiction. Logs must be shared with CERT-In along with an incident report or when it asks. All systems must also sync their clocks with NIC or NPL time servers.
Which logs count
The Directions say "all their ICT systems". The FAQs give examples: firewall logs, intrusion prevention system logs, SIEM logs, web, database, mail, FTP and proxy server logs, event logs of critical systems, and application logs.2 If you would need it to rebuild the story of an attack, keep it.
Where the logs can sit
Direction (iv) says logs "shall be maintained within the Indian jurisdiction".1 The FAQs add that logs "may be stored outside India also as long as the obligation to produce logs to CERT-In is adhered to by the entities in a reasonable time".2 If your SIEM runs in a foreign cloud region, test that you can export 180 days of logs quickly. Many teams keep a copy in India anyway to avoid the question.
Clock sync
Direction (i) requires systems to connect to the NTP server of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or to sync with servers that trace back to them. Entities spread across several countries may use another accurate time source, as long as it "shall not deviate from NPL and NIC".1 CERT-In's guidelines for government entities name samay1.nic.in, samay2.nic.in and time.nplindia.org as sources.6 Clock sync sounds dull, but when firewall, cloud and endpoint logs disagree by four minutes, your timeline falls apart.
Point of contact
Direction (iii) asks every covered entity to name a Point of Contact to deal with CERT-In, in the Annexure II format, sent to info@cert-in.org.in. The details are name, designation, organisation, office address, email, mobile, office phone and fax. Update CERT-In when that person changes.1
Five-year records for some providers
Direction (v) asks data centres, VPS providers, cloud service providers and VPN service providers to register and keep, for 5 years or longer, validated customer names, hire dates, assigned IP addresses, the email and IP used to register, the purpose of hiring the service, validated addresses and contact numbers, and the customer's ownership pattern. Direction (vi) asks virtual asset service providers, exchanges and custodian wallet providers to keep KYC data and transaction records for 5 years.1
What is a CERT-In empanelled auditor, and when do you need one?
A CERT-In empanelled auditor is an information security auditing organisation that CERT-In has vetted and placed on its official list. Empanelment is a status for the auditing firm, not a certificate for your systems. You need one when a regulator, a government buyer or a contract requires it, as SEBI's CSCRF does for its audits.
The pool is small for a country this size. A PIB release of 23 January 2026 counts 231 empanelled security audit organisations.16 In a Rajya Sabha reply summarised by PIB on 26 July 2025, the government said over 9,700 CERT-In audits were carried out in 2024 to 25, including 7,547 in banking, financial services and insurance.18
Who asks for an empanelled auditor
| Who | What the text says | Source |
|---|---|---|
| SEBI regulated entities (CSCRF) | "Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization." VAPT findings must be closed within 3 months of the VAPT report. | SEBI circular, 20 August 202414 |
| Application service providers to NSE members | For both cyber audit and VAPT, the auditing organisation "must mandatorily be CERT-In empanelled". | NSE circular, 30 April 202615 |
| Government entities | Internal audit at least once in 6 months, third-party audit at least once a year, using CERT-In empanelled auditors. | CERT-In guidelines, June 20236 |
| Any organisation using an empanelled auditor | An audit "should be conducted at least once in a year", and sector regulators may raise the frequency. | CERT-In audit policy, 25 July 20258 |
| Banks and NBFCs | RBI's 2026 Directions point banks to CERT-In's audit policy when they use empanelled auditors. Read our RBI guide for the exact paragraphs. | Arxiis RBI guide |
If you are in capital markets, our breakdown of SEBI CSCRF VAPT requirements covers the category-wise rules. If you are planning a budget, VAPT cost in India in 2026 explains what drives the price of an empanelled engagement.
What CERT-In's 2025 audit policy expects
The Comprehensive Cyber Security Audit Policy Guidelines apply to empanelled auditing organisations and to the organisations they audit. They list 26 types of engagement, from compliance audits and vulnerability assessments to penetration testing, cloud testing and AI system audits.8 If the contract does not set a period, the auditor should keep auditee data for 1 year from the end of the project.8 CERT-In's older guidelines for empanelled auditors also say auditee data should be stored only on systems in India, and that written approval must be in place before any penetration test.13
How do you verify a CERT-In empanelled auditor?
To verify a CERT-In empanelled auditor, open the official list on cert-in.org.in and match the firm's exact legal name, address and contact details. CERT-In says that list is kept up to date as soon as anything changes. Do not rely on a logo, a certificate image, or the claims on the vendor's own website.
- Open the official list. CERT-In publishes "Empanelled Information Security Auditing Organisations" as a PDF on cert-in.org.in. Its header says it is the "up-to-date valid list" and is updated "as soon as there is any change in it".11
- Match the legal entity. Check the exact company name and registered address. A sister company or a reseller with a similar name is not empanelled.
- Match the contacts. The list shows contact people, phone numbers and email addresses. Your proposal should come from the same organisation and email domain.
- Check the logo claim. CERT-In's terms say empanelled firms "shall not use the CERT-In logo" without prior written permission, and may only say the organisation "is empanelled by CERT-In for providing information Security Auditing Service".12 A CERT-In logo on a sales deck is a warning sign.
- Match scope to skills. Some entries include a capability snapshot. Confirm the firm has done the kind of work you need, such as cloud, mobile or OT testing.
- Check again before sign-off. CERT-In can end an empanelment at any time.12 Re-check the list when you sign the contract and again before the report is issued. Save a dated copy for your audit file.
Red flags: a "CERT-In certified" badge (CERT-In empanels auditing firms, it does not certify products), a firm that cannot be found by its legal name on the list, a report that names a different firm from the one you paid, or a plan to store your audit data on servers outside India.
What are the penalties for not complying with CERT-In directions?
Section 70B(7) of the IT Act makes failing to give information to CERT-In, or failing to follow its directions, an offence. The penalty is imprisonment of up to one year, a fine, or both. The Jan Vishwas Act 2023 raised the maximum fine from ₹1 lakh to ₹1 crore, in force from 30 November 2023.
The Directions themselves warn that non-compliance "may invoke punitive action under sub-section (7) of the section 70B".1 The original Section 70B(7) set a fine of up to one lakh rupees, and CERT-In's 2022 FAQs still quote that figure.24 The Jan Vishwas (Amendment of Provisions) Act, 2023 raised the maximum fine to ₹1,00,00,000, and those IT Act changes took effect on 30 November 2023.5 Under Section 70B(8), a court can take up the offence only on a complaint made by an officer authorised by CERT-In.4
The fine is rarely the biggest cost. A late report can also breach RBI, SEBI or DPDP duties, each with its own penalties. The breach itself costs far more: IBM's 2026 study puts the average cost of a data breach in India at ₹25.5 crore.22
Check the current text. Parliament has passed further Jan Vishwas amendments since 2023. Read Section 70B as it stands on India Code before quoting a penalty in a board paper.
A 6-hour incident playbook, step by step
A 6-hour incident playbook splits the CERT-In window into short time boxes. Record the notice time in the first 30 minutes. Classify against Annexure I by the first hour. Contain and save evidence by hour three. Draft and review the report by hour four and a half. File by hour five, and keep one hour spare.
The time boxes below are our suggestion, not a CERT-In rule. Adjust them to your team size, but keep the order and keep the buffer.
- 0:00 to 0:30 · Record the time and raise the alarm. Write down when the event was noticed and by whom. Open an incident ticket. Page the incident lead and the named CERT-In point of contact.
- 0:30 to 1:00 · Classify. Match what you see to the 20 Annexure I types. If you cannot rule it out, treat it as reportable. Note which other regulators may need a report.
- 1:00 to 3:00 · Contain and preserve. Isolate affected hosts, disable abused accounts, snapshot cloud workloads and export logs before they roll over. Check that system clocks agree so the timeline holds.
- 3:00 to 4:30 · Draft and review. Write the first report with the facts you have: who you are, the contact person, what happened, when it was noticed, which systems are affected, and what you have done so far. Get a quick legal or compliance review.
- 4:30 to 5:00 · File. Submit through the CERT-In form or email incident@cert-in.org.in. Save the sent email or acknowledgement with a timestamp.
- After 5:00 · Buffer, then updates. Use the spare hour if something slips. After filing, send more details as you learn them, as the FAQs allow, and run a retest once fixes are in.
When is your CERT-In report due?
Enter when the incident was noticed and pick what it looks like. You get the deadline in IST, a live countdown, whether the type is on Annexure I, and a checklist with suggested time boxes.
Your deadline and time boxes update as you type. One hour of buffer is left before the deadline.
Indicative only. Time boxes are an Arxiis suggestion. The legal duty is the 6-hour window in the CERT-In Directions; your regulator may set its own clock. Not legal advice.
Find the gaps before the clock startsCERT-In compliance checklist
A CERT-In compliance checklist turns the 2022 Directions into tasks you can test. Sync clocks to NIC or NPL, keep 180 days of logs, name and register a point of contact, map incidents to Annexure I, rehearse the 6-hour report, and check any auditor against the official empanelment list before you sign.
- All servers, network devices, cloud workloads and endpoints sync time with NIC or NPL, or a source that does not drift from them.
- Logging is on for all ICT systems, including firewall, IPS, SIEM, web, database, mail, proxy and application logs.
- Logs are kept securely for a rolling 180 days, and you have tested exporting them within a few hours.
- Your log storage location is documented, with a copy in India or a tested way to hand logs to CERT-In quickly.
- A Point of Contact is registered with CERT-In in the Annexure II format, with a named backup.
- Your incident policy lists the 20 Annexure I types and defines what "targeted scanning" and "critical systems" mean for you.
- The runbook says T+0 is the moment of noticing, and names who records that time.
- A first-report template exists, and the team knows the email, phone and form channels.
- Other clocks are mapped in one sheet: RBI, SEBI or DPDP duties, whichever apply to you.
- If you run a data centre, VPS, cloud or VPN service, validated customer records are kept for 5 years.
- If you handle virtual assets, KYC and transaction records are kept for 5 years.
- Any auditor your regulator requires to be empanelled is on the current CERT-In list, with a dated copy on file.
- You run a tabletop drill of the 6-hour playbook at least twice a year, and fix what slows you down.
Testing is the part most teams skip. A yearly audit shows where you stood on one day. Our post on the 363-day blind spot explains why the gaps between tests are where incidents happen, and the difference between vulnerability assessment and penetration testing matters when an auditor asks what you tested.
Frequently asked questions
Does the CERT-In 6-hour clock start at detection or at confirmation?
The Directions say within 6 hours of noticing the incident or being brought to notice about it. That wording does not wait for confirmation or a root cause. Treat the first credible sign that reaches someone responsible as the start, and record that time. If facts are missing, CERT-In's FAQs allow you to report what you know and add details later.
Do small businesses and startups have to follow the CERT-In directions?
Yes, in most cases. The Directions cover body corporates, and CERT-In's FAQs define a body corporate to include any company, firm or sole proprietorship in business. MSMEs got extra time until 25 September 2022, but that extension has ended. Only individual citizens are outside the Directions, according to the FAQs.
Can logs be stored outside India under the CERT-In rules?
Direction (iv) says logs must be kept for a rolling 180 days within Indian jurisdiction. CERT-In's FAQs then say logs may also be stored outside India, as long as the entity can produce them to CERT-In in reasonable time. Many teams keep a copy in India and test how fast they can export 180 days of logs.
Is a CERT-In empanelled auditor mandatory for VAPT?
It depends on your regulator. SEBI's CSCRF says its audits must be done by CERT-In empanelled auditing organisations unless stated otherwise, and CERT-In's June 2023 guidelines ask government entities to use empanelled auditors. The 2022 Directions do not require every business to use one. Check your sector rules and your customer contracts.
How do I report a cyber incident to CERT-In?
The Directions list three channels: email to incident@cert-in.org.in, phone on 1800-11-4949 and fax on 1800-11-6969. CERT-In also publishes an incident reporting form on cert-in.org.in and says formats may be updated. Send what you know within 6 hours, keep the acknowledgement, and send updates as your investigation moves forward.
What is the penalty for not reporting an incident to CERT-In?
Section 70B(7) of the IT Act covers failure to give information or follow a CERT-In direction. It allows imprisonment of up to one year, a fine, or both. The Jan Vishwas Act 2023 raised the maximum fine from ₹1 lakh to ₹1 crore from 30 November 2023. A court acts only on a complaint by an officer CERT-In authorises.
If I report to RBI or SEBI, do I still need to report to CERT-In?
Plan for both. The CERT-In Directions do not say that a report to a sector regulator replaces the CERT-In report. RBI's 2026 Directions for commercial banks set their own six-hour window on the DAKSH platform, and SEBI's CSCRF uses its own incident portal. Build one workflow that files every required report on time.
How do I check if an auditor is CERT-In empanelled?
Open the list of empanelled information security auditing organisations on cert-in.org.in and match the firm's exact legal name, address and contact details. CERT-In says it updates the list as soon as anything changes. Empanelled firms may not use the CERT-In logo without written permission, so treat logo badges with care and keep a dated copy of the list.
Fewer incidents to report, and evidence ready when the clock starts
The six-hour rule rewards teams that already know their weak spots. If you find the exposed service, the weak password and the open path to the database before an attacker does, there is nothing to report. If something does happen, you want recent test results that show what was exposed and what was fixed.
Arxiis is an autonomous AI red teaming and penetration testing platform. It is a testing tool, not an auditor. Where your regulator requires a CERT-In empanelled auditor, you still need one. Arxiis helps you arrive at that audit with fewer open findings.
- Test often, not once a year: 26 security modules across 6 attack vectors, including ransomware, Active Directory, cloud, web applications, containers and credentials.
- Findings mapped to your rules: CVSS-scored and MITRE ATT&CK-mapped results, with compliance overlays for 11 frameworks including CERT-In, RBI, SEBI CSCRF and DPDP 2023.
- Data stays with you: fully on-premise deployment, so test data never leaves your environment, with an MIT-licensed open-source core.
- Reports in hours: a multi-agent AI crew handles OSINT, exploitation, lateral movement and reporting, so the pentest report arrives in hours instead of weeks.
Sources
- CERT-In, Ministry of Electronics and IT, "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet", No. 20(3)/2022-CERT-In, 28 April 2022. cert-in.org.in (PDF)
- CERT-In, "Frequently Asked Questions on Cyber Security Directions of 28.04.2022", May 2022. cert-in.org.in (PDF)
- CERT-In, "Extension of timelines for enforcement of Cyber Security Directions of 28.04.2022 for MSMEs and for implementation of mechanism for validation of subscribers/customers details", 27 June 2022. cert-in.org.in (PDF)
- Indian Kanoon, "Section 70B in The Information Technology Act, 2000" (sub-sections 4, 6, 7 and 8, original text). indiankanoon.org
- Trilegal, "Jan Vishwas (Amendment of Provisions) Act, 2023: key changes to the IT Act and Aadhaar Act", December 2023. trilegal.com (PDF)
- CERT-In, "Guidelines on Information Security Practices for Government Entities", June 2023. cert-in.org.in (PDF)
- Press Information Bureau, "Government Taking Measures to Strengthen National Preparedness Against Cybersecurity Threats", 26 March 2025. pib.gov.in
- CERT-In, "Comprehensive Cyber Security Audit Policy Guidelines", Version 1.0, 25 July 2025. cert-in.org.in (PDF)
- CERT-In, "Technical Guidelines on SBOM, QBOM and CBOM, AIBOM and HBOM", Version 2.0, 9 July 2025. cert-in.org.in (PDF)
- CERT-In, "Guidelines regarding AI-Accelerated Vulnerability Protection and Response Requirements for OEMs and Technology Providers", Version 1.0, 10 June 2026. cert-in.org.in (PDF)
- CERT-In, "Empanelled Information Security Auditing Organisations by CERT-In", live list, checked September 2026. cert-in.org.in (PDF)
- CERT-In, "Empanelment of Information Security Auditing Organisations: Terms and Conditions", checked September 2026. cert-in.org.in (PDF)
- CERT-In, "Guidelines for CERT-In Empanelled Information Security Auditing Organizations", Version 3.0, May 2018. cert-in.org.in (PDF)
- SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities", SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024. sebi.gov.in (PDF)
- National Stock Exchange of India, "Periodic submission of System, Cyber, and VAPT Audit by Application Service Provider (ASP)", NSE/INSP/74021, 30 April 2026. nseindia.com (PDF)
- Press Information Bureau, "CERT-In: India's Frontline Defender against Cyber Threats", 23 January 2026. pib.gov.in (PDF)
- Press Information Bureau (Ministry of Home Affairs, Lok Sabha reply), "Assistance to States to Tackle Cyber Incidents", 24 March 2026. pib.gov.in
- Press Information Bureau, "Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024 to 25", 26 July 2025. pib.gov.in
- MediaNama, "Lowdown: RBI issues new cybersecurity framework for commercial banks", 3 August 2026. medianama.com
- Press Information Bureau, "Digital Personal Data Protection (DPDP) Rules, 2025", 14 November 2025. pib.gov.in
- CrowdStrike, "2026 Global Threat Report", 2026. crowdstrike.com
- IBM India, "India Records Its Highest Average Cost of a Data Breach at INR 255 Million (INR 25.5 Crore) in 2026", 3 August 2026. in.newsroom.ibm.com