Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Cyber Security Governance, CERT-In and Regulatory Requirements
Updated 11 October 2026 · Fact-checked
Cyber security governance in India runs through CERT-In, which handles incident response under Section 70B, NCIIPC, which protects critical information infrastructure under Section 70A, and sectoral regulators like SEBI and RBI. Under the 2022 CERT-In directions, you report specified incidents within 6 hours. Answer by naming the body, the source of power and the duty.
Understand Cyber Security Governance, CERT-In and Regulatory Requirements
Cyber security governance means who sets the rules, who responds when something goes wrong, and who is accountable. In India no single body does all three. The Information Technology Act, 2000 creates the national bodies. Sector regulators add their own rules for the entities they supervise.
CERT-In (Indian Computer Emergency Response Team) is the national agency for incident response under Section 70B of the IT Act. It collects and analyses information on cyber incidents, issues alerts and advisories, coordinates response, and issues guidelines. Under Section 70B(6) it can call for information and give directions to service providers, intermediaries, data centres, body corporates and others. Failing to comply with such a direction or request is punishable under Section 70B(7) with imprisonment up to one year, or a fine up to ₹1 lakh, or both.
NCIIPC (National Critical Information Infrastructure Protection Centre) is the nodal agency for critical information infrastructure (CII) under Section 70A. CII is a computer resource whose destruction or incapacitation would have a debilitating impact on national security, the economy, public health or safety. Section 70 lets the appropriate Government declare such a resource a protected system by notification in the Official Gazette. Unauthorised access to a protected system is a serious offence with imprisonment that can extend to ten years and a fine.
Sectoral regulators layer extra duties on top. SEBI issues a Cyber Security and Cyber Resilience Framework (CSCRF) for its regulated entities such as stock exchanges, depositories, brokers and mutual funds. RBI issues cyber security and IT governance directions for banks and other regulated entities. These duties are in addition to CERT-In reporting, not a replacement for it.
The National Cyber Security Policy, 2013 is the policy backdrop. It was issued by the Government (then DeitY, now MeitY) with a vision of a secure and resilient cyberspace. It is a policy document, so it guides action but does not create offences or penalties by itself.
Key rules to remember
- CERT-In incident reporting window
- Report within 6 hours of noticing the incident or being notified of it
- From the CERT-In directions of 28 April 2022 under Section 70B(6). Applies to service providers, intermediaries, data centres, body corporates and Government organisations. Only incidents of the types listed in the directions must be reported.
- Log retention
- Keep logs of all ICT systems for a rolling 180 days, within Indian jurisdiction
- Logs must be produced to CERT-In when asked. The directions also require clocks to be synchronised to the NTP servers of NIC or NPL, or to sources traceable to them.
- Subscriber and KYC records
- Data centres, VPS, cloud and VPN providers: keep subscriber information for 5 years. Virtual asset service providers: keep KYC and transaction records for 5 years
- Retention runs for 5 years after the registration or relationship is cancelled or ends, as the directions provide.
- Point of contact
- Entity must designate a point of contact to interface with CERT-In
- Share the name and contact details with CERT-In. Keep them updated.
- CERT-In power and penalty
- Section 70B(6): call for information, give directions. Section 70B(7): non-compliance, up to 1 year, or fine up to ₹1,00,000, or both
- Quote the section when you answer a compliance question.
- NCIIPC and protected systems
- Section 70A: nodal agency for CII protection. Section 70: protected system declared by Gazette notification
- Unauthorised access to a protected system can attract imprisonment up to 10 years and a fine.
- SEBI CSCRF structure
- Govern, Identify, Protect, Detect, Respond, Recover
- CSCRF follows these cyber resilience goals for regulated entities. Check the circular for the exact timelines and category-wise applicability.
How to solve Cyber Security Governance, CERT-In and Regulatory Requirements questions
Use this order for any case-based or descriptive question on cyber security governance. It gives you provision, analysis and conclusion in the shape examiners reward.
- 1Identify the entity and its sector. Is it a body corporate, an intermediary, a data centre, a SEBI-regulated broker, a bank, or an operator of critical infrastructure?
- 2Identify the event. Is it a reportable incident type, a breach of a protected system, or a general control failure?
- 3Name the authority that applies: CERT-In for incident reporting, NCIIPC for CII and protected systems, SEBI or RBI for sector rules. More than one can apply together.
- 4State the source of power or duty: Section 70B, Section 70A, Section 70, the 2022 directions, or the sector circular.
- 5Apply the specific obligation to the facts: the 6-hour clock, 180-day logs, the point of contact, the sector regulator report.
- 6Check consequences: Section 70B(7) penalty, Section 70 offence, or regulatory action by SEBI or RBI.
- 7Conclude with clear advice and practical compliance points such as an incident response policy, a board-approved framework and log management.
Quickest way: Who, what, when, consequence
When to use it: Use this when you have about 10 minutes for a 10-mark question and need a tight, structured answer.
- Write the body and its section in the first line, for example CERT-In under Section 70B.
- Write the duty with its number: 6 hours, 180 days, 5 years.
- Link it to the facts in one or two sentences, with the time of noticing and the type of incident.
- Add the sector regulator duty if the entity is a SEBI or RBI regulated entity.
- Close with the consequence and one practical step.
Common mistakes in Cyber Security Governance, CERT-In and Regulatory Requirements
Saying the 6 hours run from the time the incident occurred.
Students remember the number but not the trigger.
Fix: Write that the clock runs from noticing the incident or being notified of it. Always mark the time of noticing in your answer.
Mixing up CERT-In and NCIIPC.
Both deal with incidents and both sit under Sections 70A and 70B.
Fix: CERT-In is the national agency for incident response and advisories (Section 70B). NCIIPC protects critical information infrastructure (Section 70A). Keep this one-line split in mind.
Saying a sector regulator's reporting replaces CERT-In reporting.
Students assume one report covers everything.
Fix: Treat them as parallel obligations. Report to CERT-In under the directions and to SEBI or RBI as their framework requires.
Treating the National Cyber Security Policy, 2013 as law with penalties.
It uses strong words like mission and objectives.
Fix: Describe it as a policy framework. Penalties come from the IT Act and from regulator directions.
Forgetting that log retention is 180 days within India, and giving a wrong period or place.
Several numbers (6 hours, 180 days, 5 years) get confused.
Fix: Make a three-line table in your head: 6 hours for reporting, 180 days for logs, 5 years for subscriber and KYC records.
Declaring any important system a protected system.
Students ignore the notification condition.
Fix: State that a protected system exists only when the appropriate Government declares it by Gazette notification under Section 70.
Worked examples
Example 1
Sundaram Securities Ltd, a SEBI-registered stockbroker in Chennai, notices at 10:30 am on Monday that ransomware has encrypted its order management servers. Advise on its reporting and compliance obligations.
Show the solution
- Provision: Sundaram Securities is a body corporate. The CERT-In directions of 28 April 2022 under Section 70B(6) apply to it. Ransomware and compromise of critical systems are incident types listed in the directions.
- Analysis of time: the clock starts when the company noticed the incident, which is 10:30 am Monday. Six hours later is 4:30 pm Monday. The report to CERT-In must be made by then.
- Sector duty: as a SEBI-regulated entity, it must also follow SEBI's cyber security and cyber resilience framework. That means reporting to SEBI and the exchanges as the framework requires and carrying out root cause analysis.
- Logs: it must have kept ICT logs for a rolling 180 days within India so that it can produce them to CERT-In and to SEBI.
- Practical points: activate the incident response plan, isolate affected systems, preserve logs and evidence, use the designated point of contact, inform the board and prepare for customer communication.
- Consequence: if it ignores a CERT-In direction, Section 70B(7) allows imprisonment up to one year, or a fine up to ₹1,00,000, or both. SEBI can also take regulatory action.
Answer: Sundaram Securities must report the incident to CERT-In by 4:30 pm on Monday, i.e. within 6 hours of noticing it. It must also report to SEBI under the cyber resilience framework, preserve 180 days of logs in India, and follow its incident response plan. Non-compliance with CERT-In's direction can attract the Section 70B(7) penalty.
Example 2
The Government wants to notify the central control systems of the Western Power Grid as a protected system. Explain the legal basis, the role of NCIIPC, and the effect of notification.
Show the solution
- Provision: Section 70 allows the appropriate Government to declare a computer resource that directly or indirectly affects the facility of critical information infrastructure to be a protected system, by notification in the Official Gazette.
- Condition: the resource must be critical. Critical information infrastructure is a computer resource whose destruction or incapacitation would have a debilitating impact on national security, the economy, public health or safety. A national power grid control system clearly fits.
- Role of NCIIPC: under Section 70A the Government designates it as the national nodal agency for the protection of CII. It works on identifying and protecting CII, issuing guidelines, sharing threat intelligence and coordinating with operators.
- Effect of notification: unauthorised access to the system becomes an offence under Section 70, with imprisonment up to ten years and a fine. The operator should also follow the security practices prescribed for protected systems.
- Link with CERT-In: a cyber incident at the grid must still be reported to CERT-In within 6 hours of noticing it, and the sector regulator may need to be informed too.
Answer: The system can be declared a protected system by a Gazette notification under Section 70 because it is critical information infrastructure. NCIIPC, the nodal agency under Section 70A, supports its protection. After notification, unauthorised access is a serious offence with imprisonment up to ten years and a fine, and incidents must still be reported to CERT-In within 6 hours.
Exam tips
- Open every answer with the body and the section: CERT-In under Section 70B, NCIIPC under Section 70A, protected system under Section 70.
- Give the exact numbers: 6 hours, 180 days, 5 years. Examiners check them.
- In case questions, calculate the deadline from the time of noticing and write the clock time in your answer.
- Name the sector regulator when the facts mention a broker, exchange, mutual fund or bank, and add that its duties run alongside CERT-In's.
- End with practical points such as the incident response plan, log management, the point of contact and board oversight. Those show drafting and compliance sense.
Practice questions from Cyber Security
- Employees of a Pune logistics firm receive an email that appears to come from the company's CEO, with a link to a page that imitates the cor…
- A Mumbai company's employee finds her files unreadable and a message demanding payment in cryptocurrency for a decryption key. Investigation…
- An attacker enters the string ' OR '1'='1 into the login field of a company's web portal and gains access without a valid password, because …
- Under the CERT-In Directions of 2022, for how long must logs of all ICT systems be maintained securely, within the Indian jurisdiction?
- A company detects ransomware encrypting files on one finance-department server connected to the corporate network. The incident team must ac…
Cyber Security Governance, CERT-In and Regulatory Requirements: frequently asked questions
What is the 6-hour rule in the CERT-In directions of 2022?
The directions of 28 April 2022 issued under Section 70B(6) require covered entities to report specified types of cyber incidents to CERT-In within 6 hours of noticing them or being notified. They apply to service providers, intermediaries, data centres, body corporates and Government organisations.
What is the difference between CERT-In and NCIIPC?
CERT-In is the national agency for cyber incident response, alerts and advisories under Section 70B. NCIIPC is the nodal agency for protecting critical information infrastructure under Section 70A. CERT-In handles incidents across the system, while NCIIPC focuses on critical sectors.
Do SEBI and RBI rules replace CERT-In reporting?
No. SEBI's cyber security and cyber resilience framework and RBI's cyber security and IT governance directions apply to their regulated entities as additional duties. Such an entity may have to report to both its regulator and CERT-In.
Is the National Cyber Security Policy, 2013 a law?
No. It is a policy document that sets out a vision of a secure and resilient cyberspace and the strategies to reach it. Offences and penalties come from the IT Act, 2000 and from regulator directions.