{
  "node_id": "in-cert-in-directions-2022",
  "title": "India CERT-In Cybersecurity Directions 2022",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "India CERT-In's 2022 Cybersecurity Directions impose a mandatory 6-hour incident reporting requirement for 20 categories of cybersecurity incidents - among the shortest reporting windows globally - require VPN providers, cloud service providers, and data centres to retain detailed subscriber and customer data for 5 years, and mandate NTP clock synchronisation and 180-day log retention across all covered organisations operating ICT systems in India.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/in-cert-in-directions-2022.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "in-it-act-2000"
  ],
  "primary_citations_count": 6
}