Compliance — CERT-In Directions (India)
6-hour CERT-In incident reporting — automated from detection to notification
India's CERT-In Directions 2022 require reporting of 20 categories of cybersecurity incidents within 6 hours of detection. ManySignal detects all 20 categories, starts the countdown at detection, and generates the CERT-In notification form automatically — in AWS Mumbai with 180-day in-India log retention.
6 hours
CERT-In reporting window for all 20 reportable incident categories
20
Reportable incident categories under CERT-In Directions 2022
180 days
Mandatory ICT log retention within Indian jurisdiction
AWS Mumbai
India data residency — all logs stored within India
All 20 CERT-In reportable incident categories — ManySignal coverage
Targeted scanning and probing of critical networks
Compromise of critical systems, websites, or applications
Unauthorised access to IT systems and data
Defacement of websites or unauthorised changes to digital content
Malicious code attacks — ransomware, spyware, trojans
Attacks on servers — database, mail, DNS servers
Identity theft and credential leaks from platforms
Fraudulent mobile apps impersonating financial institutions
DoS and DDoS attacks
Data breaches and data leaks
Attacks on critical infrastructure — power, transport, telecom
Attacks on Internet of Things (IoT) devices
Attacks on BFSI sector, payment systems, and digital payment systems
DNS and BGP hijacking
Rogue/fake mobile apps on authorised app stores
Unauthorised access to social media accounts
Incidents related to electronic governance services
Attacks or incidents on cloud computing infrastructure
Supply chain attacks
Cyberattacks on AI or ML systems
CERT-In compliance status
ManySignal's India deployment is configured for CERT-In compliance: 180-day in-India log retention, 6-hour reporting workflow, and pre-populated CERT-In notification forms. Contact [email protected] for CERT-In deployment documentation.
CERT-In compliance — common questions
Which organisations are subject to the CERT-In 6-hour reporting requirement?
The CERT-In Directions 2022 apply to service providers, intermediaries, data centres, body corporates, and government organisations operating in India. The broad scope effectively covers all significant Indian enterprises and foreign entities with operations in India. ManySignal's India deployment in AWS Mumbai is configured to support CERT-In compliance for all Indian-regulated organisations.
What must be included in a CERT-In incident report?
The CERT-In report must include: organisation name and contact details, incident date/time, incident type (from the 20 categories), affected systems and impact, initial analysis, and actions taken. ManySignal's 6-hour countdown case management pre-populates all required fields from the incident record. The report is formatted for submission to CERT-In's reporting portal at https://www.cert-in.org.in/.
Does the CERT-In direction require log storage for 180 days in India?
Yes. CERT-In Directions 2022 require all service providers, intermediaries, and data centres to maintain ICT system logs within Indian jurisdiction for a rolling period of 180 days. ManySignal's India deployment (AWS Mumbai) provides 180-day hot log retention by default, with extended retention available. All logs are stored within India — no log data leaves the country under default configuration.
Does the CERT-In requirement for a point of contact apply to ManySignal customers?
The CERT-In Directions require organisations to designate a point of contact for CERT-In communication and coordinate with CERT-In during incident response. ManySignal's incident management module includes a CERT-In contact configuration — storing the designated PoC details and automatically including them in the 6-hour notification.
How does ManySignal support RBI Cyber Security Framework requirements alongside CERT-In?
RBI-regulated banks and NBFCs must comply with both CERT-In Directions and the RBI Cyber Security Framework. ManySignal's India deployment addresses both simultaneously: CERT-In 6-hour incident reporting is handled automatically, and the RBI CSF monitoring evidence (SOC monitoring capability, log management, incident classification) is collected continuously. See /compliance/rbi-cybersecurity for full RBI mapping.
Deploy CERT-In compliant monitoring in India
Connect your India-hosted systems, configure the 6-hour notification workflow, and have CERT-In reporting capability active from day one — all in AWS Mumbai.