The CERT-In Cybersecurity Directions 2022 mandate 6-hour breach reporting, 180-day log retention, ICT asset inventory maintenance, Virtual Asset Service Provider controls, and annual VAPT for all organisations operating in India. These directions apply to government, private sector, and intermediaries. The CERT-In compliance checklist India is non-negotiable — non-compliance attracts fines up to ₹1 Crore and criminal liability for responsible officers.
Fintechs handling payment data and digital financial services are within CERT-In's critical sector scope. The mandatory incident reporting, VAPT requirements, and log retention obligations are non-negotiable — infrastructure gaps in logging and monitoring directly expose the organisation to CERT-In enforcement.
Tap each control implemented in your environment — governance score updates live
We use cookies
InfraVeritas 360 uses essential cookies for security and session management, and optional cookies for analytics. We require your consent before setting non-essential cookies. Privacy Policy