M ManySignal

Guide · ManySignal

CERT-In Compliance Guide for Indian Enterprises

CERT-In's April 2022 directions mandate specific cybersecurity incident reporting, logging, and time synchronisation requirements for all entities operating in India. Non-compliance can result in fines up to ₹1 crore and/or imprisonment for officers in default. This guide covers the specific CERT-In obligations for security operations teams and how ManySignal supports compliance.

DI David Iwu — Staff Engineer, ManySignal
13 min read Published Jul 9, 2026 Download PDF
01

CERT-In direction obligations for security operations

The CERT-In directions (issued under Section 70B(6) of the IT Act, 2000) impose four primary obligations on covered entities: (1) mandatory reporting of 20 categories of cyber incidents to CERT-In within 6 hours of becoming aware, (2) ICT infrastructure log retention for 180 days within India, (3) synchronisation of all ICT system clocks with the Indian Standard Time (IST) server of the NIC, and (4) designation of a Point of Contact for CERT-In coordination.

The 6-hour reporting window is the most operationally demanding requirement. It means the detection-to-triage-to-escalation pipeline must complete in under 3 hours for a confirmed incident, leaving 3 hours for report preparation and submission. Without automated triage, this window is extremely difficult to meet consistently.

02

20 reportable incident categories

The 20 categories include targeted scanning, compromise of critical systems, unauthorised access, defacement, malware propagation, attacks on internet applications, data breach, data leak, attacks on critical infrastructure, attacks on IoT devices, attacks on financial systems, social engineering campaigns, and ransomware. Each category maps to one or more MITRE ATT&CK techniques that ManySignal's detection catalogue covers.

Map each of the 20 categories to the ManySignal detections that would surface it: ransomware maps to T1486 (Data Encrypted for Impact); unauthorised access maps to T1078 (Valid Accounts) and T1110 (Brute Force); data breach maps to T1567 (Exfiltration Over Web Service) and T1048. This mapping document is required evidence for CERT-In compliance.

  • All 20 CERT-In incident categories mapped to active ManySignal detections
  • 6-hour reporting SLA documented in Incident Response Procedure
  • CERT-In Point of Contact designated and registered
  • ICT log retention configured for 180 days within India
  • NIC IST time synchronisation confirmed for all log sources
03

6-hour reporting SLA

Meeting the 6-hour reporting SLA requires: detection (under 5 minutes with ManySignal's streaming detections), triage and confirmation (under 30 minutes with agentic triage), human confirmation and escalation (under 30 minutes with approve-gated workflow), and report preparation (under 60 minutes with the investigate agent's preliminary report). Total: under 2 hours for a confirmed incident, leaving 4 hours of buffer.

Document the SLA explicitly in the Incident Response Procedure. Practice it in tabletop exercises using scenarios from the 20 CERT-In categories. The CERT-In directions do not provide relief for technical failures — the obligation runs from the moment the entity 'becomes aware', which includes constructive awareness from monitoring systems.

04

Log retention and data residency

CERT-In requires logs to be retained for 180 days and stored within India. ManySignal's data residency configuration supports India-region storage. Confirm with your account team that the India data residency option is active before onboarding log sources. The 180-day retention must be for all ICT infrastructure — not just security-relevant systems.

The directions also prohibit VPNs that do not retain logs for 180 days or that allow anonymous use. If your organisation provides VPN services, ensure the VPN log source is connected to ManySignal and retained appropriately.

05

CERT-In incident reporting workflow

When ManySignal creates a case that matches a CERT-In reportable category, the case is automatically tagged with the CERT-In category label and escalated to the designated Point of Contact. The investigate agent generates a preliminary incident report in the CERT-In reporting format — incident type, time of detection, systems affected, nature of information involved, and remediation steps taken.

The final CERT-In report is submitted via the CERT-In portal. The ManySignal case timeline export serves as the supporting evidence package. Retain the submission confirmation and the case export together for 180 days as evidence of timely reporting.

Key takeaways

  • CERT-In mandates 6-hour incident reporting, 180-day log retention in India, and NIC IST clock synchronisation.
  • The 6-hour window requires detection under 5 minutes, triage under 30 minutes, and report under 60 minutes.
  • Map all 20 CERT-In incident categories to active ManySignal detections — this mapping is required evidence.
  • Data residency: confirm India-region storage is active before onboarding log sources.
  • Practice the 6-hour SLA in tabletops; constructive awareness starts the clock regardless of internal delays.
  • Case timeline export is the supporting evidence package for CERT-In incident reports.

Further reading

Frequently asked questions

What is CERT-In Compliance Guide for Indian Enterprises in an agentic SOC?

CERT-In Compliance Guide for Indian Enterprises is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle cert-in compliance guide for indian enterprises?

ManySignal grounds cert-in compliance guide for indian enterprises in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for cert-in compliance guide for indian enterprises?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.