P J Networks · Compliance reference
CERT-In gave India a six-hour incident reporting window in 2022. What is less widely understood is that SEBI, IRDAI and the Department of Telecommunications have each since adopted the same six hours for their own sectors, and that the power sector runs a separate 24-hour clock on top.
This page maps every clock to its instrument, with the citation, so you can check it rather than take our word for it. Where our sources disagreed, we say so instead of picking a number.
The mapping
Every clock, and where it comes from
Five regulators, one recurring number. The column that matters most commercially is the last but one: several of these regimes expressly permit the monitoring function to be outsourced.
| Regulator | Clock | What triggers it | Outsourcing permitted? | Monitoring / retention required |
|---|---|---|---|---|
| CERT-InDirections under s.70B(6), IT Act 2000 | 6 hours | From noticing the incident or being brought to notice of it — not from confirming it. 20 incident types listed at Annexure I.Direction No. 20(3)/2022, issued 28 April 2022, in force from late June 2022 | Not specified | 180-day rolling ICT logs, retained within Indian jurisdiction |
| SEBICyber Security & Cyber Resilience Framework (CSCRF) | 6 hours | Annexure-O adopts the CERT-In window. Five entity tiers from MII down to self-certification.SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024 | Yes — own/group SOC, the Market SOC, or any third-party managed SOC; small-size and self-certification REs are directed onto the Market SOC | SOC required. ISO 27001 scope covering the SOC (including an outsourced provider’s) is mandatory for market infrastructure institutions; recommended, not mandatory, for Qualified REs since 28 Aug 2025 |
| DoTTelecommunications (Telecom Cyber Security) Rules, 2024 | 6 hours + 24 hours for details | Reported to the Central Government, not CERT-In. Rule 2(e) counts an event with real or potential risk.G.S.R. 720(E), 21 November 2024, in force from that date | Yes — Rule 4(4)(h) permits a SOC run “by itself or in collaboration with other telecommunication entities” | SOC mandated by rule; Chief Telecommunication Security Officer must be an Indian citizen and resident |
| IRDAIInformation & Cyber Security Guidelines | 6 hours | Clause 3.5(3) of Policy 2.10 — report to CERT-In with a copy to IRDAI.IRDAI/GA&HR/GDL/MISC/88/04/2023, 24 April 2023 | Not addressed either way | “24×7 SOC team” required; annual independent assurance audit |
| CEA (power)Cyber Security in Power Sector Guidelines, 2021 | 24 hours sabotage reporting | Article 12 — to CERT-In, the sectoral CERT and NCIIPC. “The CISO shall be held liable for non-reporting.”File No. CEA-CH-13-12/4/2021-IT Division, 7 October 2021 | Not specified | 24×7×365 Information Security Division under a CISO; IT and OT anomaly detection; OT audit every 6 months |
| NCIIPCIT (Information Security Practices and Procedures for Protected System) Rules, 2018 | No fixed clock | The duty is timely reporting through an NCIIPC-agreed process. There is no six-hour NCIIPC rule — see below.Rules of 2018, under s.70 of the IT Act | Not specified | Rule 3 mandates both a C-SOC and a NOC. s.70 penalties reach 10 years’ imprisonment |
| RBICyber Security Framework in Banks | See Annex-3 | The framework requires prompt incident reporting on the Annex-3 template. My sources disagreed on the exact window, so no figure is published here — read Annex-3 directly.RBI/2015-16/418 | Not specified | Annex-2 sets out the C-SOC, including RBI’s own L1/L2/L3 analyst tier model |
| DPDPDigital Personal Data Protection Act 2023 & Rules 2025 | Without delay + 72 hours for detail — not in force until approx. 13 May 2027 | A personal-data breach is notified to the Data Protection Board and to affected individuals.Rules notified November 2025; substantive obligations from 13 May 2027 | n/a | ₹250 crore for failure of reasonable security safeguards; ₹200 crore for failure to notify |
Scroll the table sideways on a narrow screen —>
Citations are given so you can verify each one at source. Instruments change; this page was written in July 2026. If you are making a filing decision, read the instrument.
Getting it wrong
Four things people repeat that are not true
Most of the published guidance on this topic is a paraphrase of a paraphrase. These are the errors we see most often, including in vendor marketing.
“NCIIPC also has a 6-hour rule”
It does not. The 2018 Protected System Rules require timely reporting through an agreed process and set no numeric deadline. The six hours belongs to CERT-In, and people import it into NCIIPC by assumption.
“The clock starts when we confirm the breach”
CERT-In’s wording is noticing the incident or being brought to notice of it. Investigation time sits inside the six hours, not before it. DoT goes further — an event with potential risk already counts.
“CEA’s 2024 cyber security regulations apply to us”
As far as can be verified, those remain a draft issued for comment. The binding instrument for the power sector is still the 2021 Guidelines. Plan for the draft; comply with the 2021 document.
“CERT-In only applies above a turnover threshold”
No turnover threshold appears in the Directions. They reach intermediaries, body corporates, data centres, VPS, cloud and VPN providers and government bodies alike. This claim circulates widely and is wrong.
Telecom reports go to DoT, not CERT-In
Rule 7 of the 2024 Telecom Cyber Security Rules directs reports to the Central Government. A telecom entity that files only with CERT-In has not discharged the rule.
Outsourcing the SOC is expressly allowed
SEBI permits a managed or group SOC, and DoT permits a SOC run in collaboration with other entities. The obligation is that monitoring happens and reporting lands on time — not that you employ the analysts.
What this means operationally
Six hours is a detection problem before it is a paperwork problem
The clock runs from the moment you notice. So the organisations that miss it are rarely the ones that filed late — they are the ones that found out on day nine, from someone else.
We are ISO/IEC 27001:2022 certified, and our SOC operations sit inside the certified scope. That distinction matters: SEBI’s CSCRF requires that where a regulated entity outsources its SOC, the provider holds the certification for those services — not merely somewhere in the business. Ask any provider for the certificate and read the scope statement rather than the logo. Ours is available on request.
Hitting the window needs three things in place before anything happens: monitoring that actually notices, logs centralised and retained long enough to reconstruct what occurred, and a named point of contact already filed with CERT-In. That is what our 24×7 SOC and NOC exist to provide, with retention configured to the 180 days CERT-In requires, held in India.
Detection that starts the clock honestly
You cannot report what you never saw. Monitoring across network, security and, where relevant, camera estates — see the platform.
Reconstruction in minutes
An incident timeline assembled from correlated logs, which is what a six-hour report needs and what a pile of raw syslog is not.
Retention that satisfies the rule
180-day rolling ICT logs held within Indian jurisdiction, and configurable beyond that where your sector demands more.
Evidence the auditor accepts
Reporting mapped to CERT-In, RBI, SEBI and DPDP obligations rather than assembled after the fact.

Questions we get asked
Incident reporting in India, answered
How long do I have to report a cyber incident in India?
Six hours is the number that governs most of the economy. CERT-In’s Direction 20(3)/2022 requires reporting within six hours of noticing an incident, and SEBI’s CSCRF, IRDAI’s guidelines and DoT’s Telecom Cyber Security Rules each adopt the same six-hour window for their sectors. The power sector adds a separate 24-hour clock for sabotage under the CEA’s 2021 guidelines, and a personal-data breach under the DPDP Act must be notified without delay with full detail inside 72 hours — though that rule does not commence until roughly May 2027.
Does the six hours start when we confirm the incident?
No, and this is the most expensive misreading of the rule. CERT-In’s language is “within 6 hours of noticing such incidents or being brought to notice about such incidents”. Triage and investigation happen inside the window, not before it starts. DoT’s rules are wider still: Rule 2(e) defines an incident as an event with real or potential risk, so a suspicion can start the clock.
Who do we report to?
It depends on the sector, and getting this wrong is a common failure. Most organisations report to CERT-In. SEBI regulated entities report per Annexure-O of the CSCRF. Insurers and intermediaries report to CERT-In with a copy to IRDAI. Telecom entities report to the Central Government under Rule 7 — filing only with CERT-In does not discharge that rule. Power utilities report sabotage to CERT-In, the sectoral CERT and NCIIPC. A personal-data breach also goes to the Data Protection Board.
Can we outsource the monitoring that these rules require?
In the two regimes that address it directly, yes. SEBI’s CSCRF mandates a SOC for almost every regulated entity and then offers three models: the entity’s own or group SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification REs are directed onto the Market SOC. DoT’s Rule 4(4)(h) permits a SOC operated “by itself or in collaboration with other telecommunication entities”. IRDAI and the CEA require the function without addressing who staffs it. One caveat for SEBI entities, stated precisely: the CSCRF FAQ of June 2025 requires ISO 27001 scope to cover the SOC including where it is outsourced, but a technical clarification of 28 August 2025 made certification recommended rather than mandatory for Qualified REs, leaving it mandatory for market infrastructure institutions. Either way, ask your provider for the certificate and check the scope statement, not just the logo.
Do our logs have to stay in India?
For CERT-In purposes, yes. The Directions require ICT system logs to be maintained for a rolling 180 days within Indian jurisdiction. That is a residency requirement on the data. It is worth separating from a claim you will hear often — that your analysts must also sit in India. That is not a legal requirement. SEBI’s framework goes the other way, exempting IT and cyber-security data sent to a global or international SOC from data-localisation, subject to annual IT Committee review and Board approval. Log residency is law; analyst geography is an operational choice.
What happens if we miss the deadline?
CERT-In non-compliance is actionable under section 70B(7) of the IT Act 2000. Under the DPDP Act, failure of reasonable security safeguards attracts penalties up to ₹250 crore and failure to notify a breach up to ₹200 crore. In the power sector the CEA guidelines state plainly that the CISO is held liable for non-reporting. For protected systems, section 70 of the IT Act carries imprisonment of up to ten years.
What do we actually need in place to hit six hours?
Three things, and the first is the one people skip. You need monitoring that notices — because the clock runs from noticing, an incident nobody sees is not a clock you have paused. You need an incident timeline you can reconstruct quickly, which in practice means centralised logs with enough retention. And you need a named person and a filed point of contact, because CERT-In requires a designated PoC and six hours is not the moment to work out who signs. We build all three; see our SOC services and compliance services.
Is P J Networks able to file on our behalf?
We prepare and support it. Our SOC produces the incident reconstruction and the evidence pack the report depends on, and we work to your escalation matrix so the right person at your organisation signs and files within the window. The regulatory obligation stays with you — no service provider can absorb it — but the part that usually causes the miss, which is not having the facts in time, is the part we remove.
Next step
Could you file within six hours today?
Not “do you have a policy” — could you actually notice, reconstruct and file, tonight, at 2 a.m., on a Sunday. We will assess that honestly against your current monitoring and tell you where the gap is.
P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com



