Information Technology Act, 2000

CERT-In vs NCIIPC: Roles, Powers and Differences Explained

The 2008 Amendment built India two cyber guardians in adjacent sections and gave them opposite jobs: CERT-In under s.70B answers incidents anywhere in Indian cyberspace, NCIIPC under s.70A prevents catastrophe in the narrow set of systems the nation cannot afford to lose. Each was studied in its own note, Topics 63 and 64; the comparison itself is a standing exam question, and this note, as asked, covers it separately: mandate, parentage, instruments, sectors, teeth, and the interplay when a critical system is struck.

1. The Two Agencies

Fire brigade and fortress engineer

Figure 1: Fire brigade and fortress engineer

  • CERT-In. The Indian Computer Emergency Response Team, appointed under s.70B by the Central Government and functioning under MeitY, is the national agency for cyber incident response: it collects, analyses and disseminates information on incidents, forecasts and alerts, takes emergency measures, coordinates response and issues guidelines and advisories, the s.70B(4) function list (Topic 64)
  • NCIIPC. The National Critical Information Infrastructure Protection Centre, designated in January 2014 under s.70A as the national nodal agency for critical information infrastructure protection, functions under the NTRO: it identifies CII, prescribes protection practices, audits and assists the critical sectors, and coordinates their defence (Topic 63)
  • Critical information infrastructure. The s.70 Explanation's definition governs both: a computer resource whose incapacitation or destruction shall have debilitating impact on national security, economy, public health or safety, the test that separates NCIIPC's narrow world from CERT-In's whole map; power, banking and finance, transport, telecom, government, and strategic and public enterprises are the recognised critical sectors.

2. The Comparison

Mandate against mandate

Figure 2: Mandate against mandate

  • Jurisdiction. CERT-In's writ runs over all of Indian cyberspace, every intermediary, enterprise, government body and user; NCIIPC's over the notified and identified CII only. An incident on an ordinary e-commerce site concerns CERT-In alone; the grid's control systems concern both.
  • Function. CERT-In is reactive and advisory, response, analysis, alerts, coordination, the fire brigade; NCIIPC is protective and preventive, hardening, practices, audit, the fortress engineer. Neither investigates crime: prosecution stays with the police under the offence chapter.
  • Instruments. CERT-In works through the 2013 Rules and the 2022 Directions, six-hour incident reporting, 180-day logs in India, clock synchronisation, five-year subscriber records for VPN, cloud and VASP providers; NCIIPC works through s.70 protected system notifications, the 2018 Information Security Practices Rules with their ISSC and CISO for protected systems, and sectoral guidelines and SOPs (Topics 63, 64)
  • Teeth. Non-compliance with CERT-In's directions or failure to furnish information is s.70B(7), one year or a crore of fine or both, cognizable only on CERT-In's complaint under s.70B(8); NCIIPC's shield is s.70 itself, unauthorised access or attempted access to a protected system drawing up to ten years, with the 2018 Rules' governance obligations behind it.
  • Transparency posture. CERT-In was placed in the RTI Act's Second Schedule in 2023, exempting it as an intelligence and security organisation subject to the corruption and human rights carve-outs; NCIIPC, an NTRO arm, sits in the exempt world by parentage, both reflecting the sensitivity of what they hold (Topic 64)

3. One Incident, Both Agencies

The interplay on a CII breach

Figure 3: The interplay on a CII breach

  • The seam in practice. A breach of a power utility engages both mandates at once: the six-hour report brings CERT-In's response machinery, analysis, alerts to the sector, remediation directions, while NCIIPC's protective framework, the practices, audits and hardening it prescribed, is what the incident tests, and the s.70 notification of the target's systems makes the intruder's access a ten-year offence.
  • With the offence chapter. The police investigation runs ss.66, 66F and 70 in parallel, CERT-In's technical findings feeding the forensic case, the three lenses, response, protection, prosecution, on one event (Topics 60, 86)
  • The design logic. Splitting the roles keeps response fast and universal while concentrating protective depth where failure is unaffordable, the same architecture, national CERT plus CII protector, that most cyber-mature states run.

⚠ Exam trap

Fix the four anchors before any comparison: CERT-In, s.70B, under MeitY, incident response for all of Indian cyberspace; NCIIPC, s.70A, under the NTRO, protection of critical information infrastructure only. Attach the instruments correctly, the six-hour clock and the 2022 Directions belong to CERT-In, protected system notifications and the 2018 Rules to the s.70 and 70A world, and the sanctions likewise, one year or one crore under s.70B(7) against ten years under s.70, remembering that s.70B(8) bars cognizance except on CERT-In's own complaint.

4. Frequently Asked Questions

What is the difference between CERT-In and NCIIPC?

CERT-In, appointed under Section 70B and functioning under MeitY, is the national incident response agency for the whole of Indian cyberspace: it collects and analyses incident information, issues forecasts, alerts and advisories, coordinates response and directs reporting, with the 2022 Directions' six-hour clock as its signature instrument. NCIIPC, designated under Section 70A and functioning under the NTRO, is the national nodal agency for protecting critical information infrastructure alone, identifying CII, prescribing and auditing security practices in the critical sectors, with the Section 70 protected system offence, ten years' imprisonment, guarding its domain.

Do CERT-In and NCIIPC overlap when critical infrastructure is attacked?

They operate together without merging: the six-hour report to CERT-In triggers national response, analysis and sectoral alerts, while the incident is measured against the protective practices NCIIPC prescribed for the CII, and any unauthorised access to a notified protected system is prosecuted under Section 70 by the police alongside Sections 66 and 66F. Response, protection and prosecution remain three distinct tracks on the same event.

5. Related Topics

  • Topic 63: Sections 70 and 70A. Protected systems and the NCIIPC in full.
  • Topic 64: Section 70B CERT-In. The response agency in full.