HOME / INSIGHTS / COMPLIANCE COMPLIANCE · 22 August 2026

Reading CERT-In's Latest Guidelines Without the Jargon

A practical breakdown of what changed, and what it requires from your incident-reporting workflow.

Reading CERT-In's Latest Guidelines Without the Jargon

CERT-In's directions get referenced constantly and read carefully rarely. Most of what changes in practice for a mid-sized organisation comes down to two things: how fast you have to report, and what records you now have to keep on hand.

The reporting clock is the part that catches teams off guard. It starts from when an incident is identified, not from when it's confirmed serious — which means your team needs a documented, low-friction path to escalate a suspicious log entry before anyone's sure it's actually a breach. Waiting for certainty before reporting is the single most common compliance gap we see in audits.

The second practical requirement is log retention. Systems need to retain relevant logs for a defined window, synced to a reliable time source. This sounds trivial until you check whether your servers are actually running NTP sync correctly — in our experience, roughly one in three isn't.

Our recommendation for any team reading the guidelines for the first time: don't start with the legal text. Start by mapping your current incident response process against the reporting timeline, find the gap, then work backward into what the guideline actually requires you to change.

Back to Insights