CERT-In Compliance Services for Businesses in India
Meet the cyber security directions issued by the Indian Computer Emergency Response Team (CERT-In), including six-hour incident reporting, 180-day log retention and clock synchronisation.
Our certified consultants assess your readiness, close the gaps and set up the logging, reporting and response processes that CERT-In expects, so you are prepared before an incident happens.
Request Free Security Scoping
About CERT-In requirements
Why structured, proactive security testing is essential for your organization
Definition & Approach
CERT-In is India's national agency for cyber security incident response. Its directions under Section 70B of the Information Technology Act require service providers, intermediaries, data centres, body corporates and government organisations to report incidents quickly and keep specific logs. We assess how well you meet each requirement and help you put the missing pieces in place.
- Gap analysis against the CERT-In directions
- Logging, time synchronisation and retention review
- Incident reporting and response readiness
Business Urgency
Failing to report an incident or keep the required records can lead to legal action and penalties, as well as reputational damage. The six-hour reporting window leaves very little time to work out what to do, so the process must be ready in advance.
Holistic Protection Across Every Attack Surface
Our testing methodologies evaluate entry points, authentication mechanisms, network boundaries, and business logic.
What our CERT-In compliance service covers
From logging and clocks to reporting and response, we cover what the directions require.
CERT-In Gap Analysis & Readiness
Check your current practices against every applicable CERT-In direction and get a prioritised plan.
Incident Reporting Readiness
Build the process to identify reportable incidents and notify CERT-In within six hours.
Log Management & Retention
Enable, centralise and protect the logs of your ICT systems and keep them for 180 days within India.
Time Synchronisation
Synchronise system clocks to the specified Indian time sources so logs can be correlated reliably.
Point of Contact & Governance
Nominate a point of contact for CERT-In and set up the policies, roles and records you need.
Security Testing & Incident Response Drills
Test your defences with vulnerability and penetration testing, and rehearse your response with a tabletop exercise.
Why you need CERT-In compliance
Going it alone vs Goognu guided
| Capability / Feature | Doing It Alone | Goognu Guided Approach |
|---|---|---|
| Understanding which directions apply | ✕ Unclear and open to interpretation | Clear applicability assessment |
| Six-hour incident reporting process | ✕ Improvised during an incident | Documented, tested and ready |
| Log coverage and retention | ✕ Gaps found too late | Reviewed against the 180-day requirement |
| Technical security testing | ✕ No | Yes, with vulnerability and penetration testing |
Key Benefits of Our Security Assessments
Actionable protection designed to enhance your operational resilience and regulatory standing
Report on time
A rehearsed process so you can meet the six-hour window with confidence.
Audit-ready logs
Complete, protected and correctly retained logs when you need them.
Clear accountability
Defined roles, contacts and records that show you take compliance seriously.
Security and compliance together
One team covers policy, logging and hands-on technical testing.
Systematic Security Methodology
A five-step programme from applicability to ongoing readiness.
Scoping & Applicability
Confirm which CERT-In directions apply to your business and which systems are in scope.
Gap Analysis
Assess your logging, time synchronisation, reporting and governance against the directions.
Remediation
Close the gaps with logging changes, policies, contacts and technical fixes.
Testing & Drills
Run security testing and a tabletop exercise to rehearse six-hour incident reporting.
Ongoing Readiness
Review regularly as directions, systems and suppliers change.
What You Receive Upon Completion
Clear, executive-level summaries paired with granular remediation guidance for your engineering teams
Executive briefing
A short, plain-English view of your CERT-In position, risks and priorities.
Incident reporting playbook
Step-by-step process, templates and contacts for reporting incidents within six hours.
Compliance evidence pack
Gap analysis, log retention evidence and test results organised for review.
Strengthen Your Security Posture Today
Don't wait for a high-profile security breach or compliance violation to expose vulnerabilities in your systems.
Goognu's certified security specialists deliver actionable, zero-false-positive assessments tailored to your environment. Contact our security team today for a confidential, no-obligation scoping session.
CERT-In requirements FAQs
Common questions about scoping, methodologies, testing windows, and deliverable reports
Have custom compliance or audit requirements?
Our team routinely tests against ISO 27001, SOC 2, PCI-DSS, Cyber Essentials Plus, and GDPR standards.
Consult with our security engineers