← All Insights
Cybersecurity Law

The Six-Hour Rule: Why CERT-In's Reporting Window Is Reshaping Incident Response

Vishal Akshintala

CERT-In's 2022 directions require reporting of specified categories of cybersecurity incidents within six hours of becoming aware of them. For context, GDPR's comparable requirement is 72 hours — twelve times longer. That difference is not a minor procedural variation; it fundamentally changes what an adequate incident response plan has to be able to do in India versus most comparable jurisdictions.

A six-hour window effectively eliminates the option of a careful, fully-verified initial report. Most organizations' natural instinct during an incident is to investigate first and report once the facts are confirmed — a six-hour clock makes that instinct legally risky. The practical shift required is toward a two-stage reporting posture: a fast, necessarily incomplete initial report within the window, followed by supplementary filings as the investigation actually develops.

An incident response plan that assumes time to investigate before reporting is not a CERT-In-compliant plan, however sophisticated it looks on paper. The clock does not wait for certainty.

The organizational failure point is rarely the technical detection capability — most mid-sized companies can detect an incident reasonably quickly. It is the decision authority: who is empowered to file an initial CERT-In report with incomplete information, at 2am, without waiting for a full leadership sign-off chain that six hours simply does not accommodate. Plans that name a responsible team but not a specific person with standing authority to act on their own judgment routinely fail this test when it's actually tested.

The other quiet risk is over-reporting caution: some organizations, fearing the consequences of a late report, report every ambiguous event as a full incident, which creates its own credibility cost with CERT-In over time. Getting the six-hour threshold judgment right — genuinely reportable versus not yet clear — is itself a skill that needs practiced protocol, not improvisation under pressure.