CERT-In Cybersecurity Guidelines: Compliance Roadmap for Indian MSMEs

Understanding the 6-hour incident reporting rule, NTP server synchronization, user log retention mandates, and SSL/data protection essentials for small businesses.

CERT-In Cybersecurity Guidelines: Compliance Roadmap for Indian MSMEs

The Cybersecurity Regulatory Reality in India

Cybersecurity is no longer solely the concern of large banks and IT conglomerates. With cyber attacks, ransomware extortion, and website defacements surging across India, the Indian Computer Emergency Response Team (CERT-In) under the Ministry of Electronics and Information Technology (MeitY) has enforced strict cybersecurity directives across all Indian businesses.

Failure to comply with mandatory security logging and incident disclosure directives carries legal penalties under Section 70B(7) of the Information Technology Act 2000. Below is a practical, developer-friendly compliance roadmap for small and medium enterprises.

Core CERT-In Directives Every Website Owner Must Implement

  • Mandatory 6-Hour Incident Reporting: Organizations must report security breaches, unauthorized server access, ransomware infections, and website defacements to CERT-In (incident@cert-in.org.in) within 6 hours of detection.
  • NTP Server Synchronization: All server system clocks must be synchronized to official Indian Standard Time (IST) via National Informatics Centre (NIC) or National Physical Laboratory (NPL) Network Time Protocol (NTP) servers.
  • 180-Day Secure Log Retention: Web servers (Apache/Nginx), firewalls, and database logs must be securely archived and retained within Indian sovereign jurisdiction for at least 180 consecutive days.
  • Strict Data Privacy & Encryption: Enforce HTTPS encryption with TLS 1.3, disable deprecated SSL ciphers, and implement automated Web Application Firewalls (WAF) to block malicious SQL injection and Cross-Site Scripting (XSS) vectors.

Practical Server Hardening Steps for MSMEs

  1. Install a commercial Web Application Firewall (WAF) to filter malicious bot attacks and automated credential stuffing.
  2. Disable remote root SSH logins and enforce SSH key authentication on non-standard ports.
  3. Schedule automated off-site backups with immutable retention policies to ensure rapid recovery from ransomware attempts.
  4. Audit all website forms and API endpoints to ensure user data is encrypted at rest and in transit compliant with both CERT-In and the DPDP Act.

Frequently Asked Questions

What is CERT-In and does it apply to small business websites in India? ▼
CERT-In (Indian Computer Emergency Response Team) is the national nodal agency for cybersecurity. Its cyber incident reporting and log retention directives apply to all corporate entities, service providers, and intermediaries in India.
What is the 6-hour incident reporting rule? ▼
Any organization experiencing a covered cybersecurity incident (such as ransomware, website defacement, server breach, or data leak) must mandatorily report the event to CERT-In within 6 hours of noticing it.
How long must Indian business web servers retain system logs? ▼
Under CERT-In directives, organizations must securely maintain server, access, and system logs within Indian jurisdiction for a rolling period of 180 days (6 months).

Need Expert Security Solutions?

Speak to our authorized team in Mumbai. Transparent pricing. Fully handled online process.

Chat on WhatsApp