Applicability & gap review
Assessment of which requirements apply to you and where current practice falls short.
CERT-In Directions Readiness
The CERT-In directions of April 2022 require organisations to report specified cyber incidents within six hours, keep ICT logs for 180 days within India and synchronise clocks with approved time sources. We make sure your systems and team can actually do this.
What this covers
Typical timeline
Most assessments take 5–15 working days; critical findings are reported within 24 hours.
Who it is for
Compliance here is operational: logs must exist, be retained and be searchable; someone must be able to recognise a reportable incident at 2 a.m.; and reporting must reach the right channel. We set up the logging, processes and drills that make it work.
Discuss your requirementService providers, intermediaries and data centres covered by the directions
Corporates and SaaS companies serving regulated clients
Companies whose clients ask for CERT-In compliance evidence
IT teams without centralised logging or incident procedures
Capabilities
Assessment of which requirements apply to you and where current practice falls short.
Centralised collection and 180-day retention of ICT system logs within India, with integrity controls.
NTP configuration across servers and devices with approved time sources.
Criteria for reportable incidents, a six-hour reporting workflow and a designated point of contact.
Step-by-step playbooks for ransomware, data breach, account compromise and website defacement.
Simulated incidents that test whether your team can detect, escalate and report on time.
How we work
You always know what happens next, who is responsible and what you will receive at each stage.
Typical timeline
Most assessments take 5–15 working days; critical findings are reported within 24 hours.
Assets, roles, test windows and rules of engagement are agreed in writing.
We map the attack surface: endpoints, parameters, integrations and exposed services.
Hands-on exploitation of logic, access control and injection flaws, backed by tooling.
CVSS-scored findings with proof, business impact and step-by-step fixes.
Fixes are verified and a closure report is issued for auditors and clients.
Deliverables
Frameworks & tools
We recommend tools based on your scale, budget and existing systems, not on what is fashionable. Every choice is explained in the proposal.
Engagement models
A scoped test with a severity-rated report, developer walkthrough and one free retest after you fix the findings.
Gap assessment, policy and control implementation, evidence collection and audit support across a fixed timeline.
Quarterly testing, release-based retests and on-call advisory for teams that ship often.
How pricing works: Security work is priced on scope: number of applications, APIs, user roles, IPs or cloud accounts. You get a fixed quote after a short scoping call. Company audits start at ₹25,000.
Get a quoteFAQs
Key requirements include reporting specified cyber incidents to CERT-In within six hours of noticing them, maintaining ICT system logs for a rolling 180 days within India, synchronising clocks with NTP servers of NIC or NPL or traceable sources, and designating a point of contact.
The directions list incident types such as targeted scanning of critical systems, compromise of systems or data, identity theft, ransomware, data breaches and attacks on applications or servers. We help you build clear criteria so your team knows when the clock starts.
No. This service is readiness and implementation support. If your regulator requires an audit by a CERT-In empanelled auditor, we prepare your systems and evidence so that audit goes smoothly.
The directions require logs to be maintained within Indian jurisdiction. We design retention with India-region cloud storage or on-premise systems to meet this.
Keep exploring
Hacked, hit by ransomware or facing a data leak? Our responders contain the attack, find the root cause…
ExploreGet ready for ISO/IEC 27001:2022 certification: gap analysis, risk assessment, policies, Annex A controls…
ExploreSLA-backed managed IT with 15-minute critical response, patching, backups and remote plus onsite support in…
ExplorePrepare for India's Digital Personal Data Protection Act: data mapping, consent and notices, security…
ExploreOn-site meetings across Delhi NCR and Haryana from our Rohtak office; remote delivery across India.
Reply within one business day
Share a few details. A senior specialist reviews them and schedules a call to discuss scope, timeline and cost, with no obligation.
Receive preliminary project architecture, pricing tiers, and timeline estimates within 15 minutes under strict NDA.