A practical breakdown of India's CERT-In cybersecurity directives and which categories of IT security products help organisations meet the requirements for endpoint, network, and cloud security.
The Indian Computer Emergency Response Team (CERT-In) has tightened cyber-incident reporting obligations significantly. This article maps each requirement to product categories that demonstrably help organisations meet the standard — and flags where compliance is procedural, not just technical.
What CERT-In requires today
6-hour incident reporting
Any cyber-incident in the listed categories (data breach, ransomware, defacement, identity theft, unauthorised access, DoS, supply-chain compromise, etc.) must be reported to CERT-In within six hours of being known. This applies to service providers, intermediaries, data centres, body corporates, and government organisations.
180-day log retention
All ICT systems must retain logs in India for a rolling 180 days, and make them available to CERT-In on request.
Synchronised time
System clocks must be synchronised to NPL or NIC NTP servers — material for forensics integrity.
KYC retention for specific operators
VPN service providers, data centres, cloud service providers, virtual asset service providers, and intermediaries face additional customer-record retention rules.
Product categories that anchor compliance
SIEM with 180-day hot/warm retention
You can't meet the 180-day rule with a 30-day SIEM tier and an expensive cold archive. Buyers need SIEMs sized for hot or warm retention across that window, with query performance that survives an actual CERT-In request. Splunk, IBM QRadar, Elastic Security, and Securonix are the typical conversation starters.
EDR / XDR with reliable detection-to-investigation pipelines
The 6-hour clock starts when the incident is known. EDR that surfaces malicious activity within minutes — and feeds the SIEM with the right context — is what makes the 6-hour reporting achievable. CrowdStrike, SentinelOne, Sophos XDR, and Trend Vision One sit in this tier.
NDR + flow telemetry
Network Detection & Response tools fill the gap when endpoints aren't the source of compromise (OT, IoT, contractor networks). Pair with NetFlow / IPFIX retention for the 180-day window.
Centralised log collection & tamper-evident storage
Logs from firewalls, proxies, identity systems, OT controllers, and SaaS apps all need to land in one place with integrity controls (hashing, immutable storage). Treat this as a separate buying conversation from the SIEM itself if your existing SIEM doesn't handle it gracefully.
Time synchronisation (NTP) configuration
Not a product — but a configuration audit. Most environments have one or two systems drifting off NPL/NIC sync; flagging this early in a CERT-In readiness review is high-leverage.
Incident-response runbook tooling
SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) help organisations actually meet the 6-hour clock by automating containment + the CERT-In submission. Critical for any operator above a certain threat-volume.
Where compliance is procedural, not technical
Products help, but four things are policy + process:
- Who at the organisation has the authority to submit a CERT-In incident report? Define this before you have to do it under pressure.
- What internal threshold escalates to "this is reportable"? Avoid debating thresholds during an actual incident.
- Where is the on-call rota documented and tested? 6 hours is short — and includes weekends.
- Do you have a pre-drafted incident-report template? Drafting from scratch under pressure costs hours you don't have.
Buying-conversation starters for the channel
- "How long is your current SIEM retention, and what tier of storage holds the data after 30 days?"
- "Where do logs from your edge firewalls and identity systems live today?"
- "If CERT-In requested a report tomorrow morning, what's your end-to-end timeline?"
- "When was your last incident-response runbook tabletop exercise?"
Any "we're not sure" answer is a deal opportunity. Foxelpie distributes the major SIEM, EDR/XDR, NDR, and SOAR vendors above — with CERT-In framework mappings ready to ship as part of the pre-sales pack.