India's expanding digital economy makes robust cyber incident response indispensable. CERT-In, as the national nodal agency under the Ministry of Electronics and Information Technology, anchors the country's institutional architecture for cyber threat management.
CERT-In derives its authority from the Information Technology (Amendment) Act, 2008, which formally designated it as the national nodal agency for responding to computer security incidents. Its core functions include collecting, analysing, and disseminating information on cyber threats, issuing alerts, and coordinating incident response across sectors.
CERT-In's 2022 directives significantly widened the compliance perimeter by requiring service providers, including VPN operators, cloud providers, and data centres, to maintain user logs for 180 days — not 90 days. These directives also mandated mandatory reporting of cyber incidents within six hours, a notably stringent timeline by global standards.
CERT-In operates in coordination with sector-specific CERTs — such as those for finance and power — and interfaces with international counterparts. This layered architecture enables both vertical depth and horizontal coverage across critical information infrastructure.
Implementation gaps persist: many small and medium enterprises lack the technical capacity to comply with reporting timelines, and several VPN providers relocated servers offshore following the 2022 directives, raising questions about enforcement jurisdiction and data sovereignty.
CERT-In's evolving regulatory posture reflects the tension between security imperatives and operational feasibility. Strengthening its capacity, clarifying jurisdictional reach, and incentivising compliance will determine whether India's cyber governance framework remains effective and credible.
GS Answer Coach grades your Mains answer on structure, substance, and conclusion — in under a minute.
Essay Coach · GS Answer Coach · Cutoff Planner · 500+ Mains PYQs — free to sign up.