Beat the CERT-In 6-hour clock, every time
Comply ships the CERT-In directions as a first-class module — the 6-hour incident-reporting window, log retention and time synchronisation — mapped to DPDP and your global frameworks in one control set.
Typical readiness: 4–8 weeks to reporting-ready
What it is
CERT-In, the Indian Computer Emergency Response Team, issues directions under the Information Technology Act for cyber-incident reporting and security practice. The 2022 directions require reporting specified cyber incidents to CERT-In within 6 hours of becoming aware of them, retaining ICT system logs for a rolling period, synchronising system clocks to designated time servers, and maintaining specified records. They apply broadly across organisations operating in India.
Who needs it
Service providers, intermediaries, data centres, body corporates and government organisations operating in India — effectively most companies running IT systems in the country must be ready to report incidents and retain logs as the directions require.
Get CERT-In Directions-ready, then stay that way
Connect your stack, map controls once, and let continuous monitoring keep evidence fresh — across every framework you run.
6-hour incident reporting
Detect, log and run the reporting timeline to CERT-In inside the mandated 6-hour window, with templates and an evidence trail so nothing is missed under pressure.
Log retention
Track and evidence the rolling retention of ICT system logs the directions require, so you can prove records exist when a request arrives.
Clock synchronisation
Evidence that system clocks are synchronised to the designated time servers, one of the specific operational requirements in the directions.
One control set with DPDP
Run the CERT-In directions alongside India's DPDP Act and your global frameworks in one control set — the unified India-plus-global wedge global tools do not offer.
Continuous evidence
Pull live evidence from 30+ connectors with a no-code builder for custom systems, so retention, sync and security controls are always demonstrable.
Security practice baseline
Map your underlying security controls to the directions and to your other frameworks, so compliance is built on real, monitored controls.
The CERT-In clock, handled
A 6-hour reporting window is unforgiving — you cannot improvise it during an incident. Comply makes CERT-In compliance something you have already prepared for:
- Report specified incidents to CERT-In inside the 6-hour window with templates ready to go.
- Retain ICT system logs for the required rolling period, with evidence on demand.
- Synchronise system clocks to the designated time servers and prove it.
- Unify CERT-In, DPDP, RBI, SEBI and your global frameworks in one control set.
Because the CERT-In module shares Comply’s evidence engine, your incident-response controls serve DPDP’s breach clock and your global frameworks at the same time — one India-native programme.
CERT-In Directions questions, answered
The 2022 CERT-In directions require organisations to report specified cyber incidents to CERT-In within 6 hours of becoming aware of them. Comply runs the clock, captures the evidence and guides the report so the window is met even in the middle of an incident.
Yes — CERT-In is a first-class, India-native module in Comply, running in the same platform and control set as DPDP, RBI, SEBI and global frameworks. Global-only tools like Vanta and Drata do not cover CERT-In at all.
Both are specific CERT-In requirements, and Comply evidences both — rolling retention of ICT system logs and synchronisation of system clocks to the designated time servers — so you can demonstrate compliance, not just assert it.
CERT-In sits naturally alongside DPDP's breach obligations and your SOC 2 or ISO 27001 incident-response controls. Comply maps a single control set across all of them, so one incident programme serves every regime — an India-native advantage no global-only vendor matches.
The directions apply broadly to service providers, intermediaries, data centres, body corporates and government organisations operating in India. If you run IT systems in the country, you should be ready to report incidents and retain logs. Comply helps you scope and meet the obligations.
One platform, every framework
Comply maps a single control set across all of these — add a framework without adding work.
Start your CERT-In Directions program free
Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.
Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.