The 6-hour clock doesn't care about your spreadsheets.
Indian regulators expect documented incident reporting, 180-day log retention, and KYC-grade audit trails. Run all three from one platform — with the evidence ready before submission opens.
6-hour reporting window
The CERT-In runbook, instrumented
Each step has owner, SLA, and evidence. Submission is generated from operational data, not reconstructed from email.
- T+0Step 1
Detect & classify event severity
- T+30mStep 2
Engage on-call, capture initial telemetry
- T+2hStep 3
Decision: reportable to CERT-In?
- T+4hStep 4
Draft submission per Annex II format
- T+6hStep 5
File via cyberswachhtakendra.gov.in
Annex II · Reportable categories
Six classes that trigger the timer
Detection rules pre-mapped. When a match fires, the workflow opens automatically with classification suggestions.
Compromise of critical systems / information
Direction iv(b)Unauthorized access to ICT infrastructure
Direction iv(c)Defacement of website / intrusion into website
Direction iv(d)Malicious code attacks (ransomware, etc.)
Direction iv(e)Distributed Denial of Service attacks
Direction iv(f)Log retention · 180 days minimum
Validated coverage, not just policy
Direction (v) requires 180-day rolling logs across multiple sources — and the ability to produce them on demand.
| Source | Retention | Required content | Status |
|---|---|---|---|
| Servers / hosts | 180 days | Auth, sudo, system events, kernel log | ● Verified |
| Firewalls / NIDS | 180 days | Allow/deny, threat verdicts, sessions | ● Verified |
| Authentication systems | 180 days | Logins, MFA, failed attempts, role changes | ● Verified |
| VPN / remote access | 180 days | Connect/disconnect, address mapping | ● Verified |
| Application logs | 180 days | User actions on regulated systems | ● Verified |
Verification is performed daily — integrations flag any source where retention drops below the 180-day floor.
When the timer starts, the package is ready
Run incident reporting, log retention, and audit trail evidence from one platform built for Indian regulators.