Compliance Node Overview
India CERT-In's 2022 Cybersecurity Directions impose a mandatory 6-hour incident reporting requirement for 20 categories of cybersecurity incidents - among the shortest reporting windows globally - require VPN providers, cloud service providers, and data centres to retain detailed subscriber and customer data for 5 years, and mandate NTP clock synchronisation and 180-day log retention across all covered organisations operating ICT systems in India.
Pillar: Cybersecurity · Authority: Indian Computer Emergency Response Team (CERT-In) - Ministry of Electronics and Information Technology · Version: 1.0.0 · Last updated:
Primary source: https://www.cert-in.org.in
SHA-256 integrity: 7e2159a131f9a754138acaea3f90ba5235ce737e43ff17cc3120c6724e900f73
Primary Citations — 6 traced to source
- CERT-In Cybersecurity Directions 2022 - issued by the Indian Computer Emergency Response Team under the Information Technology Act 2000 on April 28, 2022, effective June 28, 2022 - mandating 6-hour incident reporting for 20 incident categories, 5-year subscriber data retention for VPN and cloud providers, 180-day log retention, and NTP clock synchronisation
- Indian Computer Emergency Response Team (CERT-In) - national nodal cybersecurity agency designated under the Information Technology Act 2000 - operates under the Ministry of Electronics and Information Technology - issues binding directions, technical guidelines, and advisories on cybersecurity incidents and response
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.