What are a company's obligations to report a cyber incident to CERT-In?
My company suffered a data breach and I want to know the legal timeline and obligations for reporting it to CERT-In. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.
What are a company's obligations to report a cyber incident to CERT-In? is governed in India primarily by Information Technology Act 2000, Section 70B, CERT-In Directions 2022, Direction 2, CERT-In Directions 2022, Direction 3 and CERT-In Directions 2022, Direction 4. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.
Section 70B of the Information Technology Act 2000 empowers CERT-In to collect and analyse information on cyber incidents and issue directions for prompt reporting.
Direction 2 of the CERT-In Directions 2022 lists twenty categories of incidents, including data breaches, ransomware attacks, and unauthorised access, that are mandatorily reportable.
Direction 3 requires such incidents to be reported to CERT-In within six hours of noticing them, a significantly shorter window than most global standards.
Direction 4 requires service providers, intermediaries, and data centres to maintain accurate logs of their ICT systems for one hundred and eighty days within India and provide them to CERT-In when sought.
Failure to comply with these directions can attract penal consequences under Section 70B(7) of the Information Technology Act 2000, including imprisonment up to one year or a fine up to one lakh rupees.
What to do next: 1) Identify whether the incident falls within the twenty categories requiring mandatory reporting; 2) Report to CERT-In within six hours using the prescribed format on cert-in.org.in; 3) Preserve system logs for one hundred and eighty days as required; 4) Notify affected individuals and regulators separately if personal data was compromised.
If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act 2000, Section 70B carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.