Goognu
HomeComplianceCERT-In requirements
Enterprise Cyber Security

CERT-In Compliance Services for Businesses in India

Meet the cyber security directions issued by the Indian Computer Emergency Response Team (CERT-In), including six-hour incident reporting, 180-day log retention and clock synchronisation.

Our certified consultants assess your readiness, close the gaps and set up the logging, reporting and response processes that CERT-In expects, so you are prepared before an incident happens.

ISO 27001
CREST
Cyber Essentials Plus
Schedule Security Audit
Direct Security Desk

Request Free Security Scoping

Confidential
Strictly Confidential • NDA Signed Prior to Engagement
6h
Incident reporting window
From noticing an incident
180 days
Minimum log retention
Within Indian jurisdiction
500+
Assessments delivered
24/7
Expert support
Overview

About CERT-In requirements

Why structured, proactive security testing is essential for your organization

Definition & Approach

Definition & Approach

CERT-In is India's national agency for cyber security incident response. Its directions under Section 70B of the Information Technology Act require service providers, intermediaries, data centres, body corporates and government organisations to report incidents quickly and keep specific logs. We assess how well you meet each requirement and help you put the missing pieces in place.

Key Highlights:
  • Gap analysis against the CERT-In directions
  • Logging, time synchronisation and retention review
  • Incident reporting and response readiness
Business Urgency

Business Urgency

Failing to report an incident or keep the required records can lead to legal action and penalties, as well as reputational damage. The six-hour reporting window leaves very little time to work out what to do, so the process must be ready in advance.

Defense-in-Depth Architecture

Holistic Protection Across Every Attack Surface

Our testing methodologies evaluate entry points, authentication mechanisms, network boundaries, and business logic.

Boundary Hardening
Firewalls, TLS & Endpoints
Identity & RBAC
Auth, Tokens & Privilege
Data Protection
PII, Databases & Encryption
Continuous Retest
Verification & Sign-off
Services & Scope

What our CERT-In compliance service covers

From logging and clocks to reporting and response, we cover what the directions require.

Gap analysis

CERT-In Gap Analysis & Readiness

Check your current practices against every applicable CERT-In direction and get a prioritised plan.

Key Vectors Tested:
Applicability and scope reviewDirection-by-direction gap reportPrioritised remediation roadmap
6-hour reporting

Incident Reporting Readiness

Build the process to identify reportable incidents and notify CERT-In within six hours.

Key Vectors Tested:
Reportable incident categoriesEscalation and approval workflowReporting templates and contact points
Logging

Log Management & Retention

Enable, centralise and protect the logs of your ICT systems and keep them for 180 days within India.

Key Vectors Tested:
Log coverage across systemsSecure storage within Indian jurisdictionIntegrity and access controls
NTP

Time Synchronisation

Synchronise system clocks to the specified Indian time sources so logs can be correlated reliably.

Point of Contact & Governance

Nominate a point of contact for CERT-In and set up the policies, roles and records you need.

Security Testing & Incident Response Drills

Test your defences with vulnerability and penetration testing, and rehearse your response with a tabletop exercise.

Why you need this

Why you need CERT-In compliance

Key Perspective 1
The CERT-In directions apply to a wide range of organisations that operate in India, including those serving Indian customers. Many only discover the requirements after an incident or a customer or regulator asks for evidence.
Key Perspective 2
Being ready means your team can report on time, produce the right logs and show you took reasonable steps to protect your systems and customers.
Why Manual Penetration Testing Matters

Going it alone vs Goognu guided

Enterprise Standard
Capability / FeatureDoing It AloneGoognu Guided Approach
Understanding which directions apply✕ Unclear and open to interpretationClear applicability assessment
Six-hour incident reporting process✕ Improvised during an incidentDocumented, tested and ready
Log coverage and retention✕ Gaps found too lateReviewed against the 180-day requirement
Technical security testing✕ NoYes, with vulnerability and penetration testing
Key Benefits

Key Benefits of Our Security Assessments

Actionable protection designed to enhance your operational resilience and regulatory standing

Report on time

A rehearsed process so you can meet the six-hour window with confidence.

Audit-ready logs

Complete, protected and correctly retained logs when you need them.

Clear accountability

Defined roles, contacts and records that show you take compliance seriously.

Security and compliance together

One team covers policy, logging and hands-on technical testing.

Our Process

Systematic Security Methodology

A five-step programme from applicability to ongoing readiness.

01
Phase 1

Scoping & Applicability

Confirm which CERT-In directions apply to your business and which systems are in scope.

Deliverable:Applicability and scope document
02
Phase 2

Gap Analysis

Assess your logging, time synchronisation, reporting and governance against the directions.

Deliverable:Gap analysis report
03
Phase 3

Remediation

Close the gaps with logging changes, policies, contacts and technical fixes.

Deliverable:Remediation plan and policy set
04
Phase 4

Testing & Drills

Run security testing and a tabletop exercise to rehearse six-hour incident reporting.

Deliverable:Test report and exercise report
05
Phase 5

Ongoing Readiness

Review regularly as directions, systems and suppliers change.

Deliverables

What You Receive Upon Completion

Clear, executive-level summaries paired with granular remediation guidance for your engineering teams

For Leadership

Executive briefing

A short, plain-English view of your CERT-In position, risks and priorities.

Standard Deliverable
For Security Teams

Incident reporting playbook

Step-by-step process, templates and contacts for reporting incidents within six hours.

Standard Deliverable
For Regulators and Customers

Compliance evidence pack

Gap analysis, log retention evidence and test results organised for review.

Standard Deliverable
Zero Obligation Scoping

Strengthen Your Security Posture Today

Don't wait for a high-profile security breach or compliance violation to expose vulnerabilities in your systems.

Goognu's certified security specialists deliver actionable, zero-false-positive assessments tailored to your environment. Contact our security team today for a confidential, no-obligation scoping session.

No commitment required
Response within 24 hours
Strict NDA protection
CREST & CEH certified
Frequently Asked Questions

CERT-In requirements FAQs

Common questions about scoping, methodologies, testing windows, and deliverable reports

The directions apply to service providers, intermediaries, data centres, body corporates and government organisations. Some requirements, such as extra record keeping, apply only to specific types of provider, so we start with an applicability review.

Have custom compliance or audit requirements?

Our team routinely tests against ISO 27001, SOC 2, PCI-DSS, Cyber Essentials Plus, and GDPR standards.

Consult with our security engineers