CERT-In
medium impact
effective
Demo reference · CERT/2026/06CERT-In Incident Reporting Timelines
Reporting timelines and log retention expectations for cyber incidents.
0
Issued
5 Jun 2026
Effective
5 Jun 2026
What changed
Reporting clocks and log retention duration are reaffirmed with sharper expectations on evidence availability.
Who is affected
Service providers, intermediaries, data centres and body corporates.
Why it matters
Missing the notification window converts a technical incident into a regulatory one.
What to do
Assign a named notification owner, pre-draft the notification template, and verify log retention configuration.
Boardroom risk
Regulatory escalation stemming from process failure rather than the incident itself.
Related controls
Incident response plan
Log retention
Regulatory notification
Source: official notification
Turn this into owned actions
ComplianceHQ maps regulatory change to controls, owners, evidence and deadlines automatically.
Talk to us