Official tool guide
How to report a cyber security incident to CERT-In, and when you must do it within 6 hours
Companies, service providers and government bodies in India must report listed incidents to CERT-In within 6 hours. Who is covered, what to report, and how.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
CERT-In, the Indian Computer Emergency Response Team under the Ministry of Electronics and IT, is the national agency for responding to cyber security incidents. Under its directions of 28 April 2022, service providers, intermediaries, data centres, companies and government organisations must report specified incidents within 6 hours of noticing them or being told about them.
The duty covers any business, including sole proprietors and foreign companies serving Indian users. Individuals are not covered by the 6-hour rule, but CERT-In's reporting form has an option for individuals to report.
Use it when
- Ransomware, malware or unauthorised access on your organisation's systems.
- A data breach or data leak.
- Website defacement or intrusion, DoS or DDoS attacks, attacks on servers, network devices, payment systems, cloud or IoT.
- Phishing, spoofing or identity theft targeting your organisation; fake or malicious mobile apps; hijacked social media accounts.
- CERT-In's directions list 20 incident types in all.
Not the right tool when
- An individual who lost money to fraud: call 1930 and file on cybercrime.gov.in. CERT-In does not register criminal complaints.
- A vulnerability with no incident: reporting it is voluntary and has a separate route on CERT-In's site.
Keep this ready
- Your name, role, organisation, phone, email and address
- Type of incident, when it happened and when it was detected
- Affected systems: domain or URL, IP addresses, operating system, application, location, network or cloud provider
- A short description of what happened
- Logs. Covered organisations must keep ICT logs for 180 days, stored in India
Step by step
- Report within 6 hours of noticing the incident. If you do not have every detail yet, report what you have and send the rest later.
- Email incident@cert-in.org.in, or call the toll-free number 1800-11-4949 (fax 1800-11-6969).
- You can use CERT-In's incident reporting form, but it is not mandatory; the details can go in the email.
- Organisations should also have sent CERT-In their point of contact details (to info@cert-in.org.in) in advance.
- If personal data was involved, consider your other duties too: sector regulators and the Digital Personal Data Protection rules.
What happens next
- CERT-In analyses the report, coordinates with the organisations involved and helps with the response.
- It can ask for information and issue directions. Not complying with its directions can lead to action under the IT Act.
Know the limits
- The 6-hour clock starts when you notice the incident or are told about it, not when you finish investigating.
- The duty cannot be passed to a vendor by contract: any covered entity that notices an incident must report it.
- Directions also require clocks synchronised to NIC or NPL time servers, and some providers to keep customer records for five years.
Numbers to know
- CERT-In incident response (toll-free): 1800-11-4949
- Incident email: incident@cert-in.org.in
When you are ready, the official site
Open CERT-InRelated guides
- Data breach reporting in India: CERT-In's six-hour rule and the DPDP timeline explained
- What to do after a data breach notice, and how to check if your data was exposed