July 30, 2026 · Alastor InfoSec Team
CERT-IN Compliance 2026: The 6-Hour Rule, 180-Day Log Mandate, and Annual Audit — What Indian Businesses Must Have in Place Now
India's cybersecurity enforcement landscape changed quietly but significantly in 2026. CERT-In's Directions, originally issued in April 2022, have been on the books for over three years — but enforcement posture has matured. Industry observers and legal practitioners report a clear shift from informal advisory notices to formal non-compliance proceedings, particularly where evidence shows an entity knew about a security incident and failed to act within the mandated timelines. If your organisation has been treating CERT-IN compliance as a checkbox exercise, H2 2026 is the moment that assumption becomes dangerous.
This post walks through the three operational pillars of CERT-IN compliance that organisations most frequently get wrong: the six-hour incident reporting window, the 180-day log retention mandate, and the newly enforced annual third-party cybersecurity audit requirement.
The 6-Hour Incident Reporting Rule: What It Actually Requires
The headline number is well-known — any cybersecurity incident must be reported to CERT-In within six hours of being detected. What is less understood is the scope of what counts as a reportable incident. The Directions cover a broad range of events including data breaches, unauthorised access, phishing attacks, ransomware, identity theft, malicious code activity, and attacks on critical infrastructure components.
The six-hour clock starts from the moment the incident is detected, not the moment it is confirmed. This distinction matters enormously in practice. Security teams often want to conduct preliminary triage before reporting — but a significant incident that is identified at 10pm and not reported until the following morning is almost certainly a compliance violation, regardless of whether root cause analysis was complete.
What CERT-In requires in the initial report is not a full post-mortem. It needs the nature of the incident, the date and time of detection, the systems or data affected, and the initial scope of impact. A short, accurate six-hour report followed by an updated submission is far better than a delayed comprehensive one.
Organisations without a documented, tested six-hour response plan face the most exposure. The plan must include: defined detection triggers that elevate an event to a notifiable incident, a designated reporting owner who can reach CERT-In's portal outside business hours, pre-approved initial report templates, and escalation chains that bypass normal approval delays. Running a tabletop exercise against a simulated breach scenario is the fastest way to identify where your current process will fail under time pressure.
The 180-Day Log Retention Mandate
Every organisation subject to the CERT-IN Directions must maintain logs of all ICT systems for a rolling 180-day period. Those logs must be stored within Indian jurisdiction, and must be made available to CERT-In on request. This is not optional, and it applies to all entities — not just critical infrastructure operators or large enterprises.
In practice, we see two common failure modes. The first is organisations that maintain logs but for only 30 or 90 days, typically because storage costs drive shorter retention windows. The second is organisations that retain logs for 180 days but store them in cloud regions outside India, violating the data localisation requirement.
What logs must you retain? The Directions are deliberately broad. At a minimum, this includes server access logs, network device logs (firewalls, routers, VPN gateways), authentication system logs, application logs for internet-facing services, and cloud management plane logs. DNS query logs and email gateway logs are increasingly expected by investigators conducting post-incident analysis.
Log integrity matters as much as retention period. Logs that can be tampered with after the fact offer limited forensic value. Immutable logging — write-once storage, cryptographic hashing of log batches, or append-only log streams — is increasingly the expected standard. If your logs can be deleted or modified by a compromised admin account, they will not survive scrutiny in an enforcement proceeding.
Alastor Shield's continuous compliance monitoring includes log coverage assessments, flagging gaps in retention periods, storage jurisdiction, and integrity controls across your infrastructure. If you are unsure whether your current logging posture meets the 180-day requirement, reach out to our team for an assessment.
The Annual Third-Party Cybersecurity Audit Requirement
As of July 25, 2025, every public and private enterprise subject to the CERT-IN Directions must undergo an annual third-party cybersecurity audit with scope aligned to ISO/IEC 27001. This is the least operationalised requirement in most organisations we speak to, primarily because it only became fully enforced in the second half of 2025.
What does the audit need to cover? At minimum: access control and identity management, network security architecture, vulnerability and patch management processes, incident response capability, data handling and encryption practices, and third-party or vendor risk management. The ISO 27001 alignment means auditors are expected to assess your controls against the Annex A control set, even if you are not formally certified to the standard.
There are a few important practical considerations. First, the audit must be conducted by a third party — internal audits do not satisfy the requirement. Second, the auditor should have demonstrable cybersecurity expertise, not just a generalist IT audit background. Third, the audit report should result in documented remediation actions, because regulators reviewing an audit report with material findings and no remediation plan will draw their own conclusions.
The good news for organisations that have invested in ISO 27001 is that an existing certification substantially reduces the scope and cost of the CERT-IN annual audit. Certified organisations typically need a delta assessment against the Directions' specific requirements rather than a full ground-up review.
Penalties and the H2 2026 Enforcement Reality
Non-compliance with the CERT-IN Directions carries penalties including imprisonment of up to one year and fines of up to one lakh rupees. While the monetary penalty is modest by global standards, the reputational and operational consequences of a formal enforcement action — including potential public disclosure — are significant. For regulated entities in banking, insurance, or healthcare, CERT-IN enforcement findings can trigger secondary regulatory scrutiny from the RBI, IRDAI, or NHA.
The more immediate concern for most organisations is not penalty quantum but operational readiness. A six-hour reporting window is extremely short. 180 days of immutable, India-resident logs requires deliberate infrastructure investment. An annual third-party audit requires budget allocation and scheduling that cannot happen reactively.
Bringing It Together With DPDPA
CERT-IN compliance does not exist in isolation. For organisations also working toward DPDPA compliance (and every organisation handling digital personal data in India should be), there is meaningful overlap. DPDPA Phase 3, effective May 2027, mandates 72-hour breach notification to the Data Protection Board — a requirement that layers on top of CERT-IN's six-hour report. Organisations need a unified incident response process that satisfies both mandates simultaneously, not two separate tracks.
Alastor Shield maps CERT-IN controls alongside DPDPA, ISO 27001, and SOC 2 obligations into a single dashboard, so your team is not maintaining parallel compliance programmes. Enforster AI continuously scans your infrastructure for the vulnerability classes most likely to generate a reportable incident, reducing detection-to-response time. To understand how your current posture maps to these requirements, contact us at [email protected] or visit Alastor Shield.
The window for treating CERT-IN compliance as a theoretical obligation has closed — in H2 2026, enforcement proceedings are a real operational risk for organisations that cannot demonstrate a six-hour-capable incident response process, 180-day India-resident logs, and a completed annual third-party audit.