Home/Blog/CERT-In Incident Reporting Rules Explained: Which Cyber Incidents Are Mandatory to Report?
Compliance

CERT-In Incident Reporting Rules Explained: Which Cyber Incidents Are Mandatory to Report?

CERT-In's 2022 directions require reporting certain cyber incidents within 6 hours of detection — here's exactly which incidents are covered and who counts as a reporting entity.

Hardik Patel
Hardik PatelSep 4, 2026 · 7 min
Cover image: CERT-In Incident Reporting Rules Explained: Which Cyber Incidents Are Mandatory to Report?

💡 In Simple Terms (For Beginners)

CERT-In is India's national cyber emergency response team. Its 2022 rules require many businesses to report certain types of cyberattacks — like data breaches or ransomware — to the government within 6 hours of finding out about them.

Summary
  • CERT-In's April 2022 directions list specific mandatory-reporting incident types, not every cyber incident in general.
  • The 6-hour clock starts from when your organisation becomes aware of the incident, not when it actually occurred.
  • Reports go to CERT-In directly (cert-in.org.in), separately from any DPDP Act breach notification obligations.

COMPLIANCE · September 4, 2026 · 7 min read · By Hardik Patel

Which cyber incidents are mandatory to report to CERT-In within 6 hours? CERT-In's April 2022 directions list specific incident categories — not every security event — that a covered entity must report within 6 hours of becoming aware of them, and most Indian businesses have never actually read the full list.

Which Incidents Are Actually Mandatory

CERT-In's mandatory list includes targeted scanning of critical systems, unauthorised access to IT systems or data, defacement of a website, malicious code spread (including ransomware), attacks on IoT and OT systems, data breaches, and denial-of-service attacks, among other listed categories.

The list is specific and enumerated — a minor internal policy violation or a routine phishing email that was blocked before causing harm generally falls outside it, while an actual data breach, ransomware infection, or successful unauthorised access falls squarely inside it. The distinction that trips businesses up most often is between an attempted attack (usually not mandatory) and a successful or partially successful one (usually mandatory).

Who Counts as a Reporting Entity

CERT-In's directions apply broadly to service providers, intermediaries, data centres, body corporates, and government organisations operating in India — a far wider net than just "IT companies" or "telecom operators." Most businesses that operate a website, app, or hold customer data in India fall within scope.

This overlaps with, but is legally distinct from, the newer Telecommunication Identifier User Entity category under the Telecom Cyber Security Rules — a business can be a CERT-In reporting entity, a TIUE, both, or neither, and each carries its own separate reporting obligation.

How the 6-Hour Clock Actually Works

The 6-hour reporting window starts from the moment your organisation becomes aware of the incident, not from when the incident actually began — which means detection speed directly determines how much of your 6 hours is left to actually investigate and report.

This is why a slow internal escalation process is a genuine compliance risk on its own, independent of how well an organisation otherwise handles the technical side of an incident. A business that takes 4 hours just to escalate internally has effectively cut its own compliance window to 2 hours.

How to Actually Report to CERT-In

Reports go directly to CERT-In through the channels listed at cert-in.org.in (email, phone, or the incident reporting form), and should include a factual, timestamped account of what's known so far — a report doesn't need to be complete or conclusive within 6 hours, it needs to be filed within 6 hours.

Having a pre-drafted internal template for this exact report — who fills it in, what fields it needs, who approves sending it — removes the delay of figuring out the reporting format itself during an active incident.

Key Takeaways

  • CERT-In's mandatory list is specific and enumerated — not every security event qualifies, but successful breaches and ransomware clearly do.
  • The reporting entity definition is broad — most businesses with a website, app, or Indian customer data are likely in scope.
  • The 6-hour clock starts at awareness, not at the actual incident time — fast internal escalation directly protects your compliance window.
  • A pre-drafted reporting template removes avoidable delay during an actual incident.

Frequently Asked Questions

Q: Is every phishing email a mandatory CERT-In report?

A: No — a phishing email that was blocked or ignored generally isn't mandatory to report. A successful compromise resulting from one, such as credential theft or malware execution, typically is.

Q: Does CERT-In reporting replace DPDP Act breach notification?

A: No, they're separate obligations that can both apply to the same incident — a personal data breach may need to be reported to CERT-In and separately assessed against DPDP Act notification requirements.

Q: What happens if a business misses the 6-hour window?

A: Non-compliance can carry penalties under the IT Act framework CERT-In operates within — but beyond formal penalties, a late or missing report also removes the chance for CERT-In to provide timely guidance during an active incident.

How iTechFixr Can Help

We help businesses build the detection-to-reporting pipeline that actually functions inside a 6-hour window — not just a policy document that describes one. If you're not sure whether your business is a CERT-In reporting entity, that classification check is a good place to start.

Share this post:

Not sure where you stand? Check your DPDP readiness free (2 minutes).

Hardik Patel
Hardik Patel
CEH v12 onwards certified cybersecurity trainer & consultant, iTechFixr Infotech LLP. 7+ years in offensive security and VAPT.

Need Help With This?

Talk to Hardik directly about your organisation's cybersecurity needs — get a tailored response within 24 hours.