For IT teams For security leaders For channel partners For OEM vendors Solutions Partners Resources Support Contact
Compliance

CERT-In Guidelines 2024: What Products Ensure Compliance?

2026-06-08 · By Foxelpie Research Team

A practical breakdown of India's CERT-In cybersecurity directives and which categories of IT security products help organisations meet the requirements for endpoint, network, and cloud security.

The Indian Computer Emergency Response Team (CERT-In) has tightened cyber-incident reporting obligations significantly. This article maps each requirement to product categories that demonstrably help organisations meet the standard — and flags where compliance is procedural, not just technical.

What CERT-In requires today

6-hour incident reporting

Any cyber-incident in the listed categories (data breach, ransomware, defacement, identity theft, unauthorised access, DoS, supply-chain compromise, etc.) must be reported to CERT-In within six hours of being known. This applies to service providers, intermediaries, data centres, body corporates, and government organisations.

180-day log retention

All ICT systems must retain logs in India for a rolling 180 days, and make them available to CERT-In on request.

Synchronised time

System clocks must be synchronised to NPL or NIC NTP servers — material for forensics integrity.

KYC retention for specific operators

VPN service providers, data centres, cloud service providers, virtual asset service providers, and intermediaries face additional customer-record retention rules.

Product categories that anchor compliance

SIEM with 180-day hot/warm retention

You can't meet the 180-day rule with a 30-day SIEM tier and an expensive cold archive. Buyers need SIEMs sized for hot or warm retention across that window, with query performance that survives an actual CERT-In request. Splunk, IBM QRadar, Elastic Security, and Securonix are the typical conversation starters.

EDR / XDR with reliable detection-to-investigation pipelines

The 6-hour clock starts when the incident is known. EDR that surfaces malicious activity within minutes — and feeds the SIEM with the right context — is what makes the 6-hour reporting achievable. CrowdStrike, SentinelOne, Sophos XDR, and Trend Vision One sit in this tier.

NDR + flow telemetry

Network Detection & Response tools fill the gap when endpoints aren't the source of compromise (OT, IoT, contractor networks). Pair with NetFlow / IPFIX retention for the 180-day window.

Centralised log collection & tamper-evident storage

Logs from firewalls, proxies, identity systems, OT controllers, and SaaS apps all need to land in one place with integrity controls (hashing, immutable storage). Treat this as a separate buying conversation from the SIEM itself if your existing SIEM doesn't handle it gracefully.

Time synchronisation (NTP) configuration

Not a product — but a configuration audit. Most environments have one or two systems drifting off NPL/NIC sync; flagging this early in a CERT-In readiness review is high-leverage.

Incident-response runbook tooling

SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) help organisations actually meet the 6-hour clock by automating containment + the CERT-In submission. Critical for any operator above a certain threat-volume.

Where compliance is procedural, not technical

Products help, but four things are policy + process:

  1. Who at the organisation has the authority to submit a CERT-In incident report? Define this before you have to do it under pressure.
  2. What internal threshold escalates to "this is reportable"? Avoid debating thresholds during an actual incident.
  3. Where is the on-call rota documented and tested? 6 hours is short — and includes weekends.
  4. Do you have a pre-drafted incident-report template? Drafting from scratch under pressure costs hours you don't have.

Buying-conversation starters for the channel

  • "How long is your current SIEM retention, and what tier of storage holds the data after 30 days?"
  • "Where do logs from your edge firewalls and identity systems live today?"
  • "If CERT-In requested a report tomorrow morning, what's your end-to-end timeline?"
  • "When was your last incident-response runbook tabletop exercise?"

Any "we're not sure" answer is a deal opportunity. Foxelpie distributes the major SIEM, EDR/XDR, NDR, and SOAR vendors above — with CERT-In framework mappings ready to ship as part of the pre-sales pack.

← Back to all articles