ISO 27001 & MSME
• WhatsApp

CERT-In Directions Readiness

CERT-In Compliance & Cyber Incident Readiness

The CERT-In directions of April 2022 require organisations to report specified cyber incidents within six hours, keep ICT logs for 180 days within India and synchronise clocks with approved time sources. We make sure your systems and team can actually do this.

  • Mutual NDA before scoping
  • Non-destructive testing
  • Free retest after fixes

What this covers

  • CERT-In Readiness

Typical timeline

Most assessments take 5–15 working days; critical findings are reported within 24 hours.

Who it is for

Who our CERT-In Compliance service is for

Compliance here is operational: logs must exist, be retained and be searchable; someone must be able to recognise a reportable incident at 2 a.m.; and reporting must reach the right channel. We set up the logging, processes and drills that make it work.

Discuss your requirement
  • 01

    Service providers, intermediaries and data centres covered by the directions

  • 02

    Corporates and SaaS companies serving regulated clients

  • 03

    Companies whose clients ask for CERT-In compliance evidence

  • 04

    IT teams without centralised logging or incident procedures

Capabilities

What is included in CERT-In Compliance

Applicability & gap review

Assessment of which requirements apply to you and where current practice falls short.

Log retention setup

Centralised collection and 180-day retention of ICT system logs within India, with integrity controls.

Time synchronisation

NTP configuration across servers and devices with approved time sources.

Incident reporting process

Criteria for reportable incidents, a six-hour reporting workflow and a designated point of contact.

Incident response playbooks

Step-by-step playbooks for ransomware, data breach, account compromise and website defacement.

Tabletop drills

Simulated incidents that test whether your team can detect, escalate and report on time.

How we work

A clear, step-by-step delivery process

You always know what happens next, who is responsible and what you will receive at each stage.

Typical timeline

Most assessments take 5–15 working days; critical findings are reported within 24 hours.

  1. 01

    Scoping & NDA

    Assets, roles, test windows and rules of engagement are agreed in writing.

  2. 02

    Reconnaissance

    We map the attack surface: endpoints, parameters, integrations and exposed services.

  3. 03

    Manual testing

    Hands-on exploitation of logic, access control and injection flaws, backed by tooling.

  4. 04

    Reporting

    CVSS-scored findings with proof, business impact and step-by-step fixes.

  5. 05

    Retest & closure

    Fixes are verified and a closure report is issued for auditors and clients.

Deliverables

What you receive

  • Applicability and gap report
  • Logging and retention architecture
  • Incident classification and reporting SOP
  • Point-of-contact and escalation matrix
  • Incident response playbooks
  • Drill report with improvements

Frameworks & tools

Tools we work with

CERT-In Directions (April 2022)WazuhElastic / OpenSearchGraylogNTP (NIC / NPL sources)Microsoft SentinelAWS CloudTrailIncident response playbooks

We recommend tools based on your scale, budget and existing systems, not on what is fashionable. Every choice is explained in the proposal.

Engagement models

Choose how we work together

One-time assessment

A scoped test with a severity-rated report, developer walkthrough and one free retest after you fix the findings.

Most chosen

Compliance programme

Gap assessment, policy and control implementation, evidence collection and audit support across a fixed timeline.

Continuous security

Quarterly testing, release-based retests and on-call advisory for teams that ship often.

How pricing works: Security work is priced on scope: number of applications, APIs, user roles, IPs or cloud accounts. You get a fixed quote after a short scoping call. Company audits start at ₹25,000.

Get a quote

FAQs

CERT-In Compliance: frequently asked questions

What do the CERT-In directions require?

Key requirements include reporting specified cyber incidents to CERT-In within six hours of noticing them, maintaining ICT system logs for a rolling 180 days within India, synchronising clocks with NTP servers of NIC or NPL or traceable sources, and designating a point of contact.

Which incidents must be reported within six hours?

The directions list incident types such as targeted scanning of critical systems, compromise of systems or data, identity theft, ransomware, data breaches and attacks on applications or servers. We help you build clear criteria so your team knows when the clock starts.

Is this an empanelled CERT-In audit?

No. This service is readiness and implementation support. If your regulator requires an audit by a CERT-In empanelled auditor, we prepare your systems and evidence so that audit goes smoothly.

Do logs really have to stay in India?

The directions require logs to be maintained within Indian jurisdiction. We design retention with India-region cloud storage or on-premise systems to meet this.

Reply within one business day

Request a proposal for CERT-In Compliance

Share a few details. A senior specialist reviews them and schedules a call to discuss scope, timeline and cost, with no obligation.

  • Written scope and fixed quote
  • NDA signed before you share sensitive details
  • Direct access to the people doing the work

By submitting you agree to be contacted about this enquiry. We never share your details.

EthicsComputer assistant
EthicsComputer Assistant
Online • Fast Response
Instant Scoping
Talk to Lead Architect
WhatsApp Chat
Direct Architect Scoping // Step 1 of 2

Request Fast Quote & Architecture SLA

Receive preliminary project architecture, pricing tiers, and timeline estimates within 15 minutes under strict NDA.

100% Mutual NDA Protected Step 1 of 2 (15 seconds)