← Back to Blogs
August 10, 2026

CERT-In Directions and the IT Rules: A Practical Compliance Checklist

Two regulatory instruments quietly shape day-to-day IT operations for a large share of Indian enterprises: the CERT-In cybersecurity directions and the IT Rules (Intermediary Guidelines and Digital Media Ethics Code). Both are frequently misunderstood as “security best practice” guidance when in fact they carry specific, auditable obligations.

CERT-In Directions: The Operational Core

  • Incident reporting: Specified categories of cybersecurity incidents must be reported to CERT-In within a defined window — a much tighter timeline than most organizations’ informal incident-response habits assume.
  • Time synchronization: ICT systems are expected to synchronize clocks with designated time sources, a small but frequently overlooked requirement that matters enormously for incident forensics.
  • Log retention: Organizations are expected to enable logs of their ICT systems and maintain them securely for a defined retention period, within Indian jurisdiction.
  • Point of contact: Designating a named point of contact for coordination with CERT-In is a basic but often-missed administrative step.

IT Rules: Due Diligence for Intermediaries and Platforms

Organizations that qualify as intermediaries — and the definition is broader than most people assume, covering many SaaS and platform businesses — carry due-diligence obligations under the IT Rules: publishing terms of service and privacy policy, responding to takedown and grievance requests within specified timeframes, appointing a Grievance Officer, and for larger platforms, additional obligations around traceability and proactive content monitoring in specific categories.

“We’re not really an intermediary” is one of the most common and most risky assumptions we hear in audit conversations. The definition turns on function, not on how a company describes itself — if your platform hosts or transmits third-party content or communications, the due-diligence obligations are worth checking against, not assuming away.

A Practical Checklist

  • Confirm your incident classification and reporting workflow meets CERT-In’s defined timelines, with a named internal owner, not just a policy document.
  • Verify system clocks are synchronized to an approved time source across production infrastructure.
  • Audit log retention configuration against the required retention period and confirm logs are stored within the required jurisdiction.
  • Assess whether your product qualifies as an intermediary under the IT Rules, and if so, confirm your Grievance Officer, terms of service, and takedown-response workflow are in place and current.
  • Run this checklist as a recurring internal audit item, not a one-time onboarding task.

ITPMS conducts independent CERT-In and IT Rules readiness reviews for enterprises and government vendors, translating these obligations into a concrete, evidence-based checklist your team can operate against — without selling you the logging or monitoring tools you might ultimately need.

Ready to protect your IT investment?

Stay ahead of compliance deadlines and procurement pitfalls. Let ITPMS be your independent shield.