On April 28, 2022, CERT-In issued directions requiring organisations to report cybersecurity incidents within 6 hours of detection. Not 24 hours. Not 72 hours. Six hours. For most Indian organisations, that window is operationally impossible — not because they lack intent, but because they have not built the systems that make fast response possible.
The two notification obligations
Indian organisations now operate under two overlapping incident notification regimes. CERT-In's 2022 directions require 6-hour reporting of cybersecurity incidents to CERT-In — this is a cybersecurity obligation, not a privacy obligation. DPDP Rule 7 requires notification of personal data breaches to the Data Protection Board 'without undue delay', with draft guidance suggesting a 72-hour window, and immediate communication to affected data principals where there is significant risk of harm.
These are distinct obligations with distinct timelines. A ransomware attack on your infrastructure triggers the CERT-In 6-hour window even if no personal data is confirmed compromised. A personal data breach triggers the DPDP 72-hour window regardless of whether the root cause was a cybersecurity incident.
| Obligation | Trigger | Window | Notify |
|---|---|---|---|
| CERT-In 2022 | Cybersecurity incident | 6 hours from detection | CERT-In portal |
| DPDP Rule 7 | Personal data breach | 72 hours (draft) | Data Protection Board |
| DPDP Rule 7 | High-risk breach | Immediate | Affected data principals |
The detection gap
IBM's 2025 Cost of a Data Breach Report put the global average time to identify a breach at 287 days. The average time to contain it: another 80 days. Total exposure window: over a year. Against this reality, a 6-hour notification window is not a goal — it is an indictment of how most organisations currently operate.
The companies that can meet the 6-hour window are not companies with better security instincts. They are companies that built continuous monitoring, pre-classified their data assets, and documented their response procedures before the incident happened. Detection speed is a function of instrumentation, not urgency.
Organisations with pre-built incident response plans and tested procedures contained breaches 28 days faster on average, saving ₹85 crore per incident. (IBM Cost of a Data Breach Report, 2025)
What the 6-hour window actually requires you to have ready
- A current data inventory: You cannot report what data was compromised if you do not know what data you hold, where it sits, and who can access it. This inventory must exist before the incident.
- Designated Point of Contact: CERT-In requires a registered PoC who can submit the incident report. This person must be identifiable and reachable at any hour.
- Incident classification criteria: Your team must be able to decide within minutes whether an event is a reportable incident. This requires pre-defined criteria, not real-time legal consultation.
- Evidence collection capability: The report requires logs, timelines, affected systems, and initial impact assessment. These must be retrievable on demand, not reconstructed under pressure.
- Notification templates: Board notification and principal communication templates must be pre-drafted and legally reviewed. Writing them during the incident is not viable in a 6-hour window.
The four-phase response
- 1Detect and classify (0–1 hour): Automated monitoring flags the anomaly. On-call team classifies as reportable or non-reportable against pre-defined criteria. If reportable, incident commander engaged.
- 2Evidence collection (1–2 hours): Pull logs from affected systems. Identify data assets in scope using the pre-existing inventory. Document the attack vector, timeline, and initial containment actions.
- 3Report submission (2–4 hours): Submit CERT-In report via portal. Prepare DPB notification if personal data is confirmed in scope. Escalate to legal and communications.
- 4Principal notification (4–6 hours): Identify affected data principals using the data inventory. Send breach notifications where significant risk of harm is identified. Document all actions taken with timestamps.
Why inventory is the foundation of fast response
Every stage of the response cycle depends on knowing what data you hold. Which systems contain personal data? How many records? What categories — health, financial, government IDs? Who has access? Without a current inventory, your incident response team spends the first 4 hours of the response window answering these questions instead of acting on them.
The CERT-In 6-hour window was designed to create urgency. Its practical effect is to force organisations to invest in the pre-incident infrastructure that makes rapid response possible. The companies that have done that investment will meet the window. The companies that have not will be in violation before they have time to think about it.
Takeaway
Incident readiness is not about having a response plan in a drawer. It is about having instrumented systems, classified data, designated people, and tested procedures so that when an incident happens, the response is a process — not a panic. The 6-hour window is achievable. But only if you build for it before the clock starts.