Governance, Risk & Compliance

Six hours is not a target. It is the rule.

The CERT-In Directions of 28 April 2022 are short, specific and unusually unforgiving. Most organisations can describe them. Very few can prove, on a Tuesday, that they would meet the six-hour clock on a Saturday night.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
6 hoursTo report, from noticing
180 daysRolling log retention
In IndiaWhere logs must live
s.70B(6)IT Act, 2000

What the Directions actually require

Issued under sub-section (6) of section 70B of the Information Technology Act, 2000, the Directions apply to service providers, intermediaries, data centres, body corporates and government organisations. They are not a framework to be adopted at your own pace; they are in force, and non-compliance is an offence under the Act.

Seven directions carry the weight. Clocks synchronised to NIC or NPL time sources. Cyber incidents reported to CERT-In **within six hours of noticing them**. A designated point of contact on file. ICT system logs maintained for a rolling 180 days **and held within Indian jurisdiction**. Extended record-keeping obligations for data centres, VPS, cloud and VPN providers, and for virtual asset service providers. And an Annexure listing the incident types that must be reported — which is longer, and broader, than most organisations assume.

The gap we find most often is not ignorance of the rule. It is that the six-hour clock starts at *noticing*, not at confirming — so an organisation whose process requires certainty before it reports has already designed itself into breach. The second most common gap is logs that meet the 180-day window but sit in a foreign cloud region, which satisfies neither half of the fourth direction.

Coverage

What we work on

Readiness against each direction, and the runtime that keeps it true afterwards.

The six-hour reporting path

A named person, a tested route to CERT-In, and a decision rule that triggers on noticing rather than on certainty. Rehearsed, because a path nobody has walked is not a path.

Incident recognition against Annexure-I

Whether your detection and triage can actually recognise the listed incident types in time for the clock to be met. This is where the requirement is won or lost.

180-day log retention, in jurisdiction

What is logged, for how long, where it physically sits, and whether it is protected from alteration. Both halves of the direction, evidenced from configuration rather than from policy.

Clock synchronisation

NTP to NIC or NPL across every server, appliance and log source. Unglamorous, and the reason correlated evidence either exists or does not.

Point of contact

Designated, filed with CERT-In, and kept current when the person changes role — the failure mode nobody plans for.

Extended record-keeping

For data centres, VPS, cloud and VPN providers, and for virtual asset service providers: the five-year subscriber and transaction records the fifth and sixth directions require.

Approach

How the engagement runs

Gap, fix, rehearse, evidence.

  1. 01 · Gap assessment

    Each direction assessed against what is actually in place, not against what the policy says. Output is a short list of real shortfalls.

  2. 02 · Close the gaps

    Logging, retention, jurisdiction, time sources and the reporting path — with the changes made rather than recommended.

  3. 03 · Rehearse the clock

    A tabletop against a realistic incident, timed. The question answered is whether six hours is achievable with the people who would actually be awake.

  4. 04 · Evidence and keep it

    The artefacts that show compliance, collected on a cycle in SemperWise One™ so the position holds between assessments.

In the platform

What SemperWise One carries for this framework.

Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.

8
Clauses in the library

Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.

2
Artefacts collected automatically

Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.

8
Control subjects it spans

Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.

How the framework divides up

  • 3 Records
  • 2 Reporting
  • 1 Operations
  • 1 Governance
  • 1 Logging

Evidence the platform gathers by itself

  • Audit trail continuity
  • Retention and erasure

Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.

Already hold another framework? Most of the subjects here are ones your existing programme already covers. SemperWise One works out which, clause by clause, and proposes them — it never marks anything verified on your behalf, because verified means evidenced, and the evidence has to be pointed at this framework deliberately.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Direction-by-direction gap report

Each of the seven, with the evidence reviewed and the shortfall stated plainly.

Incident reporting runbook

Who decides, who reports, by what route, and what goes in the report — rehearsed and timed.

Log retention and jurisdiction review

What is retained, for how long, and where it physically sits.

Continuous evidence

Log-retention and audit-trail artefacts collected on a cycle, dated, and filed against the direction they evidence.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You are an intermediary, service provider, data centre, cloud or VPN provider operating in India.
  • Your logs are retained for 180 days, but in a region outside India.
  • Nobody can say who would file a CERT-In report at 2am on a Sunday.
  • Your incident process requires confirmation before escalation — which means the clock has already run.
  • A customer or regulator has asked you to evidence CERT-In compliance.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

CERT-In Directions — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Is CERT-In compliance a certification?

No. There is no CERT-In compliance certificate to buy, and anybody offering one is selling something else. The Directions are law under section 70B of the IT Act; you either meet them or you do not. What can be evidenced is readiness, the controls in place and the artefacts that demonstrate them — and that is what we produce. CERT-In *empanelment* is a separate thing: it is a status held by auditing organisations, not a compliance mark for the entity being audited.

When exactly does the six-hour clock start?

On noticing the incident — not on confirming it, not on completing triage, and not on management sign-off. That distinction is the single most consequential detail in the Directions, and designing a process that needs certainty first is the most common way organisations put themselves in breach without realising.

Do the 180 days of logs really have to be in India?

The fourth direction requires ICT system logs to be maintained for a rolling 180 days and maintained within Indian jurisdiction. Retention alone is not sufficient; a 400-day archive in a foreign region does not satisfy it. We review where logs physically sit, in configuration rather than in contract.

Which incidents are reportable?

Annexure-I to the Directions lists the types, and the list is broader than most organisations expect — it extends well beyond breaches into areas such as targeted scanning, unauthorised access and attacks on infrastructure and connected devices. The practical work is making sure your detection and triage can recognise them quickly enough to matter.

Can SemperWise file the report for us?

No — the obligation is the entity's, and it is not delegable to a vendor. What we do is build and rehearse the path so the people who hold the obligation can meet it, and keep the evidence that shows they are able to.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.