CERT-In and India's Cybersecurity Framework
CERT-In, the Indian Computer Emergency Response Team, is India's national agency for handling cyber security incidents such as hacking, data breaches and malware attacks. It works under the Ministry of Electronics and Information Technology (MeitY). Think of it as the country's "fire brigade" for cyber attacks: it raises the alarm, helps put out the fire and tells everyone how to stay safe. Around it sits a wider framework of laws, agencies and policies that together protect India's digital systems.
Why does it exist?
Today, banks, railways, power grids, hospitals and government services all run on computers and the internet. A single successful attack can stop trains, leak crores of citizens' data or empty bank accounts. Attacks also spread very fast and cross borders. So a country needs one central body that watches for threats round the clock, warns others quickly and coordinates the response. Without it, every organisation would fight alone and often too late.
Where did it come from?
CERT-In was set up by the Government of India in 2004. It got legal backing when the Information Technology (Amendment) Act, 2008 added Section 70B to the Information Technology Act, 2000. Section 70B names CERT-In as the national agency for incident response. The same 2008 amendment added Section 70A, which later led to a separate agency for the most critical systems. In April 2022, CERT-In issued its strongest set of rules so far on reporting cyber incidents.
What does CERT-In do?
Under Section 70B(4) of the IT Act, its functions include:
- Collecting, analysing and sharing information on cyber incidents
- Giving forecasts and alerts about cyber security threats
- Taking emergency measures to handle incidents
- Coordinating the response to cyber incidents
- Issuing guidelines, advisories and vulnerability notes (public warnings about security flaws in software)
Under Section 70B(6), CERT-In can ask organisations for information and give them binding directions.
The April 2022 directions
On 28 April 2022, CERT-In issued directions under Section 70B(6). They came into force on 28 June 2022. Key rules:
- 6-hour reporting: Organisations must report listed cyber incidents to CERT-In within 6 hours of noticing them.
- 180-day logs: Service providers, intermediaries, data centres, companies and government bodies must keep logs (records of system activity) of their ICT systems for 180 days, stored within India.
- Clock sync: Systems must sync their clocks with official time servers, so that events can be matched in an investigation.
- VPN, data centre and cloud providers: Must keep records of customer details for 5 years.
What happens if someone ignores CERT-In?
Under Section 70B(7), failing to give information or follow its directions can bring imprisonment up to one year, or a fine up to ₹1 crore, or both. The fine was earlier up to ₹1 lakh. The Jan Vishwas (Amendment of Provisions) Act, 2023 raised it, with effect from 30 November 2023.
The other key parts of India's framework
- NCIIPC (National Critical Information Infrastructure Protection Centre): Set up under Section 70A by a notification dated 16 January 2014. It works under the National Technical Research Organisation (NTRO). It protects Critical Information Infrastructure: systems like power grids, banking networks and telecom, whose failure would harm national security, the economy or public health.
- Section 70 (protected systems): The government can declare a computer system a "protected system". Unauthorised access to it is a serious crime.
- National Cyber Security Coordinator: Works in the National Security Council Secretariat and coordinates all agencies at the highest level.
- I4C (Indian Cyber Crime Coordination Centre): Set up by the Ministry of Home Affairs as a scheme in 2018. It helps police deal with cyber crime. Citizens can report cyber crime at cybercrime.gov.in and call the helpline 1930 for financial fraud.
- Cyber Swachhta Kendra: A botnet cleaning and malware analysis centre run by CERT-In, launched on 21 February 2017. It helps users find and remove malicious software.
- Sectoral CERTs: Some sectors have their own teams, for example CERT-Fin for the financial sector, which work with CERT-In.
- National Cyber Security Policy, 2013: India's first cyber security policy. Among other goals, it aimed to train 5 lakh cyber security professionals in five years.
Key punishments under the IT Act, 2000
- Section 43: Civil penalty (compensation) for damaging a computer or accessing it without permission.
- Section 66: Doing a Section 43 act dishonestly or fraudulently (hacking) is a crime: imprisonment up to 3 years or fine up to ₹5 lakh, or both.
- Section 66F: Cyber terrorism, added in 2008, punishable with imprisonment that may extend to life.
Link with data protection
The Digital Personal Data Protection Act, 2023 adds a separate duty. Organisations must protect personal data with reasonable security safeguards and must report personal data breaches to the Data Protection Board of India and to affected people. Under the DPDP Rules, 2025, notified on 14 November 2025, a detailed report must reach the Board within 72 hours.
The maximum penalty for failing to take reasonable security safeguards is ₹250 crore. So one breach may need reporting both to CERT-In (within 6 hours) and under the DPDP framework.
New guidance for AI systems
In July 2025, CERT-In released version 2 of its Technical Guidelines on SBOM, QBOM & CBOM, AIBOM, HBOM. An AIBOM (AI Bill of Materials) is a full list of the parts used to build, train and run an AI model, such as its data, model and software libraries. These guidelines are advisory, not mandatory, but they show CERT-In starting to address AI supply-chain risks.
Commonly confused concepts
- CERT-In vs NCIIPC: CERT-In (Section 70B, under MeitY) handles cyber incidents across all sectors. NCIIPC (Section 70A, under NTRO) focuses only on protecting critical information infrastructure.
- CERT-In vs I4C: CERT-In deals with the technical side of incidents (alerts, fixes, response). I4C (under the Home Ministry) helps police investigate and prosecute cyber crime.
- Cyber security vs data protection: Cyber security protects systems and networks from attack. Data protection (DPDP Act) protects people's personal information and their rights over it. A breach can violate both.
- 6-hour vs 72-hour reporting: 6 hours is CERT-In's deadline for reporting cyber incidents. 72 hours is the DPDP Rules' deadline for a detailed personal data breach report to the Data Protection Board.
Issues, criticism and the way forward
- Too many bodies: Cyber security is spread across MeitY, the Home Ministry, NTRO and the NSCS. Critics say this causes overlap and slow coordination. Many experts have called for a single updated national cyber security strategy.
- Strict timelines: Industry groups have said the 6-hour reporting window is too short compared with many other countries. The government's view is that quick reporting is vital to stop attacks spreading.
- Skills gap: India still lacks enough trained cyber security professionals, especially in government and smaller companies.
- Old law, new threats: The IT Act was written in 2000. It does not directly address AI agents that act on their own, deepfakes or AI-driven attacks. A replacement law (a proposed Digital India Act) has been discussed but not passed as of September 2026.
- International cooperation: Cyber attacks cross borders. India is not a party to the Budapest Convention on Cybercrime and prefers rules made under the United Nations.
- Way forward: a clear legal framework for AI-related incidents, better coordination among agencies, more sectoral CERTs, regular security audits of government databases and large investment in skills.
Concepts to Know
- Malware: Harmful software, like viruses or ransomware, designed to damage systems or steal data.
- Botnet: A network of infected computers secretly controlled by an attacker, often used to launch large attacks.
- Logs: Automatic records kept by computer systems showing who did what and when. Investigators use them to trace attacks.
- Intermediary: A company that carries or hosts other people's content, such as internet service providers, social media platforms and search engines.
- Critical Information Infrastructure: Computer systems whose failure would seriously hurt national security, the economy, public health or safety.
- CERT-In: set up in 2004; statutory national agency under Section 70B of the IT Act, 2000 (added by the IT Amendment Act, 2008); works under MeitY
- April 2022 directions: issued 28 April 2022, in force 28 June 2022; report incidents within 6 hours; keep logs for 180 days within India; VPN, data centre and cloud customer records for 5 years
- Section 70B(7) penalty: up to 1 year jail or fine up to ₹1 crore (raised from ₹1 lakh by the Jan Vishwas Act, 2023; effective 30 November 2023)
- NCIIPC: Section 70A; notified 16 January 2014; under NTRO
- I4C: Ministry of Home Affairs, 2018; helpline 1930; portal cybercrime.gov.in
- Cyber Swachhta Kendra: launched 21 February 2017
- Section 66F (cyber terrorism): up to life imprisonment
- DPDP Rules, 2025: notified 14 November 2025; 72-hour breach report to the Data Protection Board; max penalty ₹250 crore for failing security safeguards
- CERT-In AIBOM guidelines (version 2): July 2025
● Tracked since February 10, 2026 · last seen September 27, 2026 · updates as the daily brief publishes