CERT-In incident reporting directions: 6-hour rule for banks
The CERT-In incident reporting directions, issued on 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000 and effective from 28 June 2022, converted cyber incident reporting in India from a good practice into a statutory duty with a fixed deadline. For a bank, a payment aggregator, a co-operative bank or any body corporate running customer-facing systems, the obligation is simple to state and hard to execute: notice a reportable incident, and report it to CERT-In within six hours. Candidates preparing for the IIBF Prevention of Cyber Crime paper are regularly tested on this rule because it is precise, quotable and examinable — the window, the list of reportable incident types, the log retention period and the punishment clause are all fixed numbers that examiners love.
🛡️ What the CERT-In Directions Actually Require
CERT-In — the Indian Computer Emergency Response Team — is the national nodal agency for cyber security incident response, designated under Section 70B(1) of the IT Act, 2000. Section 70B(6) empowers it to call for information and give directions to service providers, intermediaries, data centres, body corporate and government organisations. The April 2022 directions are exercised under exactly that power, which is why they bind banks even though they are not an RBI instrument.
Four obligations sit at the core. First, mandatory reporting of specified cyber security incidents within six hours of noticing them or being brought to notice about them. Second, synchronisation of all ICT system clocks to the Network Time Protocol servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or to NTP servers traceable to these sources. Third, secure maintenance of ICT system logs for a rolling period of 180 days, and maintenance of those logs within Indian jurisdiction. Fourth, designation and registration of a point of contact with CERT-In who will interface with the agency on all such communications.
Two additional duties apply to specific categories rather than to every bank. Data centres, virtual private server providers, cloud service providers and VPN service providers must register and retain accurate subscriber and customer records — including names, addresses, contact details, period of hire and ownership pattern — for five years or longer as mandated, even after cancellation or withdrawal of the registration. Virtual asset service providers, exchange providers and custodian wallet providers must maintain KYC records and records of financial transactions for five years. A bank that buys cloud hosting should therefore treat these as vendor-diligence checkpoints. The foundation concepts here are covered in the computer insecurity chapter, which explains why logs and time stamps are the raw material of every investigation.
💡 Exam Tip: Remember the source of power — the directions flow from Section 70B(6), while the punishment for non-compliance flows from Section 70B(7). Questions often swap these two sub-sections.
⏱️ The Six-Hour Window and When the Clock Starts
The six-hour rule is the single most examined element of the directions. The window runs from the time the entity notices the incident, or from the time the incident is brought to its notice — whichever happens first. It does not run from the time the attack began, from the time forensic analysis concludes, or from the time senior management is briefed. This distinction matters in practice: a bank that discovers on a Monday that a card-data breach began three weeks earlier still has six hours from Monday's discovery, not a lapsed deadline.
Incidents may be reported to CERT-In by e-mail, telephone or fax, and through the incident reporting form published on the CERT-In website. The format and the current contact details are notified by CERT-In and may be updated from time to time, so a compliance team should verify the channel against the latest CERT-In publication rather than a stored template. An initial report within the window is what the direction requires; supplementary and forensic detail can follow as the investigation matures.
Operationally, six hours is a governance problem more than a technical one. Most banks fail it not because the SOC missed the alert but because the escalation chain needed three approvals before anyone was willing to file. The workable design is a pre-authorised trigger: the CISO or a designated deputy may file the initial report without further sign-off, and the legal review happens on the follow-up submission. Building that muscle is exactly what the incident management chapter describes as the detection-to-containment lifecycle, and it is also why tabletop exercises are graded on time-to-report and not only on time-to-recover. If you are revising attack typologies alongside this, the cyber crime methods chapter maps each method to the incident category it will be reported under.

📋 The Twenty Reportable Incident Types
Annexure I to the directions lists twenty types of cyber security incidents that must be mandatorily reported. Learning the list by theme rather than by rote is the efficient approach, because the exam usually asks whether a described scenario is reportable rather than asking for the list itself.
The network and access cluster covers targeted scanning or probing of critical networks and systems; compromise of critical systems or information; unauthorised access to IT systems or data; and website defacement or intrusion involving insertion of malicious code or links. The malicious code cluster covers virus, worm, Trojan, bot, spyware, ransomware and cryptominer attacks, and attacks on servers such as database, mail and DNS servers and on network devices such as routers.
The deception and availability cluster covers identity theft, spoofing and phishing attacks, and denial of service and distributed denial of service attacks. The infrastructure cluster covers attacks on critical infrastructure, SCADA and operational technology systems and wireless networks, and attacks on applications such as e-governance and e-commerce platforms. The data cluster names data breach and data leak as two separate reportable categories — a point candidates frequently miss.
The emerging technology cluster is the newest and the most heavily weighted in recent question papers: attacks on Internet of Things devices and associated systems; attacks or incidents affecting digital payment systems; attacks through malicious mobile applications; fake mobile applications; unauthorised access to social media accounts; attacks affecting cloud computing systems, servers, software and applications; attacks affecting systems related to big data, blockchain, virtual assets, virtual asset exchanges, custodian wallets, robotics, 3D and 4D printing, additive manufacturing and drones; and attacks affecting systems related to artificial intelligence and machine learning. For a bank, the digital payment systems entry and the fake mobile application entry are the two that fire most often in real life, which is why the same controls that stop ransomware attacks on banks also shorten the reporting timeline.
🗄️ Log Retention, NTP Sync and the Point of Contact
The 180-day log retention obligation is deceptively simple. Logs of all ICT systems must be maintained securely for a rolling period of 180 days and maintained within Indian jurisdiction. They must be produced to CERT-In when ordered or directed, whether in connection with an incident the entity reported or one CERT-In is investigating independently. The phrase "rolling" is important — this is a continuous 180-day trailing window, not a batch archive created after an incident. A bank that ships logs to an offshore SIEM tenancy without an Indian copy is non-compliant even if nothing has gone wrong.
Clock synchronisation is the least glamorous requirement and the one that quietly decides whether an investigation succeeds. If the firewall, the core banking application, the switch and the internet banking server each drift by a few minutes, the correlated timeline is fiction and the electronic record loses persuasive value. Synchronising to NIC or NPL NTP servers — or to NTP servers traceable to them — gives every log line a common, nationally traceable reference. Entities with ICT infrastructure spanning multiple geographies may use accurate and standard time sources other than NIC or NPL, provided their time source does not deviate from those references.
The point of contact requirement completes the loop. Each entity must designate a point of contact, register the details with CERT-In in the prescribed format, and communicate any change promptly. In a bank this is normally the CISO's office, and the registration should be a named role with an institutional mailbox rather than an individual's personal address, so that transfers and leave do not break the channel. The internal escalation matrix behind that mailbox is the same one used for preventing business email compromise fraud, where minutes also decide the outcome.
⚠️ Common Mistake: Candidates write that logs must be retained for 180 days "after an incident". They must be retained on a rolling 180-day basis at all times, incident or no incident.

🏦 CERT-In and RBI Reporting: Two Duties, Not One
A regulated bank does not choose between CERT-In and RBI — it reports to both, under separate mandates, on separate timelines and in separate formats. The RBI Cyber Security Framework for banks requires prompt reporting of unusual cyber security incidents to the Reserve Bank, and RBI has also built incident and fraud reporting expectations into its supervisory returns and master directions. Because RBI's reporting formats and timelines have been revised more than once, always confirm the current requirement against the latest RBI master direction or circular rather than relying on a coaching note.
The practical answer is a single internal trigger with multiple outbound channels. One classification decision, taken by the incident commander, should simultaneously start the CERT-In clock, the RBI notification, the card network notification where card data is involved, and the customer communication where personal data is affected. Where funds have moved, the law-enforcement route runs in parallel.
| Obligation | CERT-In (April 2022 Directions) | RBI (cyber security framework) | Statutory duty? |
|---|---|---|---|
| Legal source | Section 70B(6), IT Act 2000 | Section 35A, Banking Regulation Act 1949 | ✅ |
| Who must report | Service providers, intermediaries, data centres, body corporate, government organisations | Regulated entities — banks, NBFCs, payment operators | ✅ |
| Reporting window | 6 hours of noticing or being made aware | Prompt reporting as specified in the applicable RBI circular | ✅ |
| Scope of incidents | 20 types listed in Annexure I | All unusual cyber security incidents, successful or attempted | ✅ |
| Log retention | Rolling 180 days, within India | As prescribed in framework and IT governance directions | ✅ |
| Consequence of default | Section 70B(7) prosecution | Supervisory action and monetary penalty | ❌ (not criminal) |
Note also the anti-money-laundering overlap. A cyber incident that produces mule-account activity or unexplained beneficial ownership changes triggers the KYC-AML chain as well, and understanding beneficial ownership identification in KYC helps you see why cyber and compliance teams must share the same case file.

⚖️ Penalty under Section 70B(7) and a Compliance Checklist
Non-compliance carries a criminal, not merely regulatory, consequence. Section 70B(7) of the IT Act, 2000 provides that any service provider, intermediary, data centre, body corporate or person who fails to provide the information called for or to comply with a direction under Section 70B(6) shall be punishable with imprisonment for a term which may extend to one year, or with fine which may extend to one lakh rupees, or with both. The offence is not about the breach itself — it is about failing to report or failing to furnish information. That is why the exam answer to "what is the penalty for a data breach under the directions" is a trap: the penalty attaches to the reporting failure.
A workable readiness checklist has six lines. One, register the point of contact with CERT-In and refresh it whenever the role holder changes. Two, synchronise every ICT clock to NIC or NPL NTP or a traceable source, and monitor drift as a control. Three, retain 180 days of logs in India, with integrity protection so they survive a challenge to authenticity. Four, publish a one-page classification aid mapping observed symptoms to the twenty Annexure I categories so a night-shift analyst can decide without waking a lawyer. Five, pre-authorise the initial filing so no approval chain can consume the six hours. Six, rehearse it quarterly and measure time-to-report. Vendor contracts should push the same duties down to cloud and managed-service partners, since exposure to cryptocurrency related cyber crime often arrives through a third party rather than the bank's own perimeter.
📌 Remember: Six hours to report, twenty reportable incident types, 180 days of logs inside India, five years of KYC records for VASPs and cloud or VPN providers, and one year or one lakh rupees under Section 70B(7).
🧠 Practice MCQs: CERT-In Incident Reporting
Q1. Under the CERT-In directions of April 2022, a reportable cyber security incident must be reported within how many hours? (a) 2 hours (b) 6 hours (c) 24 hours (d) 72 hours
Answer: (b) — The window is six hours from noticing the incident or from being brought to notice about it.
Q2. The CERT-In directions require ICT system logs to be maintained securely for a rolling period of (a) 30 days (b) 90 days (c) 180 days (d) 365 days
Answer: (c) — A rolling 180 days, and the logs must be maintained within Indian jurisdiction.
Q3. Failure to comply with a direction issued under Section 70B(6) of the IT Act, 2000 is punishable under (a) Section 70B(7) (b) Section 66C (c) Section 43A (d) Section 72A
Answer: (a) — Section 70B(7) prescribes imprisonment up to one year or fine up to one lakh rupees, or both.
Q4. Entities covered by the directions must synchronise their ICT system clocks to the NTP servers of (a) BIS only (b) SEBI and IRDAI (c) any global NTP pool (d) NIC or NPL, or servers traceable to them
Answer: (d) — NIC or NPL NTP servers, or NTP servers traceable to these sources.
Q5. How many types of cyber security incidents are listed as mandatorily reportable in Annexure I to the directions? (a) 12 (b) 20 (c) 25 (d) 30
Answer: (b) — Twenty types, ranging from targeted scanning to attacks on artificial intelligence and machine learning systems.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
Do the CERT-In directions apply to co-operative banks and small NBFCs?
Yes. The directions apply to service providers, intermediaries, data centres, body corporate and government organisations without a size threshold. Any body corporate operating ICT systems is covered, so a small co-operative bank has the same six-hour duty as a large private bank.
Does reporting to RBI satisfy the CERT-In obligation?
No. The two obligations arise from different statutes and must be discharged separately. Reporting to the Reserve Bank does not discharge the duty under Section 70B(6), and reporting to CERT-In does not discharge the supervisory reporting expected by RBI.
What if the six-hour deadline passes before the facts are clear?
File within the window with what is known and mark the report as preliminary, then send supplementary information as the investigation progresses. The direction requires timely reporting, not a completed forensic conclusion, and a late but complete report is still a default.
Where does this topic appear in IIBF study material?
It sits with incident management and legal framework topics in the Prevention of Cyber Crime syllabus. You can revise the full set of related notes on the prevention of cyber crime tag hub before attempting a full-length mock.
🎯 Conclusion
The CERT-In directions turned incident reporting into a clock-driven statutory duty with a criminal sanction behind it. For the exam, fix the five numbers — six hours, twenty incident types, 180 days of logs in India, five years of KYC records for designated providers, and one year or one lakh rupees under Section 70B(7) — and be able to say which sub-section grants the power and which one punishes the default. For the job, the deciding factor is whether your escalation path can move from detection to filing without waiting on approvals. Test both together with the chapter-wise question banks in the CAIIB and certification course library, or jump straight into a timed paper on iibf.store mock tests and see whether the numbers stay with you under pressure.
Source and further reading: CERT-In and the Indian Institute of Banking & Finance.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading