Information Technology Act, 2000

Section 70B IT Act: CERT-In Complete Note

Section 70B makes the Indian Computer Emergency Response Team the national agency for responding to cyber incidents: it watches, warns, coordinates the response when systems burn, and, since 2022, compels the whole digital economy to report fires within six hours and keep the logs that show how they started. Topic 19 placed CERT-In in the national cybersecurity framework; this is the complete section note: appointment and structure, the statutory functions, the 2013 Rules, the s.70B(6) directions and the 2022 regime, the recast sanction and the cognizance bar, and the comparison with NCIIPC.

Appointment and structure of CERT-In

Figure 1: Appointment and structure of CERT-In

1. Appointment, Structure and the 2013 Rules

  • Appointment (s.70B(1)). The Central Government appoints, by notification, an agency called the Indian Computer Emergency Response Team to serve as the national agency for incident response. CERT-In had operated since 2004; the 2008 Amendment gave it this statutory seat.
  • Structure (s.70B(2), (3)). A Director General heads the agency, with such other officers and employees as prescribed; it functions under MeitY, and its budget and manner of functioning are provided for by the Rules.
  • The CERT-In Rules, 2013. The Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013 set out its policies: a 24x7 incident response help desk, advisories and vulnerability notes, and mandatory reporting of specified severe incidents, with voluntary reporting encouraged for the rest.
  • Cyber security incident. Defined in the Rules as any real or suspected adverse event that violates an explicit or implied security policy: unauthorised access, denial of service, malicious code, and the like.

2. The Statutory Functions

Section 70B(4), Information Technology Act, 2000

The Indian Computer Emergency Response Team shall serve as the national agency for performing the following functions in the area of cyber security: (a) collection, analysis and dissemination of information on cyber incidents; (b) forecast and alerts of cyber security incidents; (c) emergency measures for handling cyber security incidents; (d) coordination of cyber incidents response activities; (e) issue guidelines, advisories, vulnerability notes and whitepapers relating to information security practices, procedures, prevention, response and reporting of cyber incidents; (f) such other functions relating to cyber security as may be prescribed.

The six functions of Section 70B(4)

Figure 2: The six functions of Section 70B(4)

  • In practice. The functions translate into daily advisories and vulnerability notes, national alerts during campaigns such as ransomware waves, coordination of response when government or enterprise systems are hit, the Cyber Swachhta Kendra botnet cleaning centre, empanelment of security auditors whose certificates the SPDI Rules and sectoral regulators rely on, and drills and exercises across sectors.
  • Boundaries. CERT-In responds and advises; it does not investigate crime (the police do), does not run interception (s.69 agencies do), and hands the critical estate's protective planning to NCIIPC.

3. The Section 70B(6) Directions and the 2022 Regime

The 2022 Directions in outline

Figure 3: The 2022 Directions in outline

  • The power. For carrying out its functions, CERT-In may call for information and give directions to service providers, intermediaries, data centres, bodies corporate and any other person (s.70B(6)). This is the legal engine of the 2022 regime.
  • Six hour reporting. The Directions of 28 April 2022 require the cyber incidents listed in their annexure, about twenty types, from data breaches, ransomware and identity theft to attacks on critical infrastructure, IoT and payment systems, to be reported to CERT-In within six hours of noticing or being informed, among the tightest windows in the world.
  • Logs, clocks and records. Covered entities maintain ICT system logs for a rolling 180 days within India; synchronise clocks with NPL or NIC time sources; VPN, cloud and data centre providers keep validated subscriber and customer records for five years; and virtual asset businesses keep KYC and transaction records for five years.
  • Reception. The Directions took effect from June 2022, with relaxations for MSMEs and validated timelines for VPN records; several VPN providers withdrew their Indian servers rather than comply, and proportionality criticism continues, but the framework stands and feeds breach enforcement under the DPDP regime beside it (Topic 39)

4. Provider-Wise Obligations under the 2022 Directions

What each class of provider must keep

Figure 4: What each class of provider must keep

  • Data centre obligations. Register accurate subscriber and customer details and maintain the records for five years or longer after cancellation or withdrawal of the registration.
  • Virtual private server and cloud service provider obligations. The same validated records: names of subscribing customers, ownership pattern, addresses and contact numbers, period of hire, the IPs allotted and being used, and the purpose of hiring, besides the general 180-day log duty.
  • VPN service provider obligations. Validated subscriber records for five years even after the subscription is withdrawn, the requirement that led several VPN operators to remove their Indian servers.
  • Virtual asset service provider obligations. KYC information and records of all financial transactions for five years, aligning crypto exchanges, custodians and wallet providers with financial-sector record keeping.
  • Subscriber and customer records generally. The records must be validated, so anonymous or unverified registrations do not discharge the duty.

5. Sanction, Cognizance and CERT-In vs NCIIPC

Direction, default and the cognizance bar

Figure 5: Direction, default and the cognizance bar

  • The recast punishment. Failure to furnish the information called for, or to comply with a direction, was punishable with up to one year or fine up to ₹1 lakh. The Jan Vishwas Act, from 30 November 2023, kept the year but raised the fine to ₹1 crore (s.70B(7)), pricing non-compliance for platforms rather than clerks; it remains an offence, not a civil penalty (Topic 40)
  • The cognizance bar (s.70B(8)). No court shall take cognizance of the offence except on a complaint made by an officer authorised by CERT-In, which centralises prosecution and screens out private complaints.
  • RTI position. CERT-In was added to the Second Schedule of the RTI Act in 2023, exempting it as an intelligence and security organisation, subject to the corruption and human rights violation carve-out.

CERT-In and NCIIPC compared

Figure 6: CERT-In and NCIIPC compared

CERT-In incident reporting vs DPDP breach reporting

The two reporting regimes compared

Figure 7: The two reporting regimes compared

  • Two reports for one breach. A personal data breach at a covered entity triggers both duties once the DPDP core provisions commence: the six-hour report to CERT-In as a cyber security incident, and the intimation to the Data Protection Board and affected Data Principals with a detailed report within 72 hours (see Topic 39)
  • Different questions. CERT-In asks what happened to the systems and how to contain it; the Board asks what happened to the individuals and what they must be told. Compliance programmes therefore run the two clocks in parallel.

⚠ Exam trap

Keep the twins apart: CERT-In under s.70B, under MeitY, responds to incidents everywhere; NCIIPC under s.70A, under NTRO, protects critical information infrastructure. Quote the current figures: six hours to report, 180 day logs, five year records, and a default now costing up to one year or ₹1 crore or both, prosecutable only on CERT-In's own complaint under s.70B(8).

6. Frequently Asked Questions

What are the functions of CERT-In under Section 70B?

As the national agency for incident response: collection, analysis and dissemination of information on cyber incidents; forecasts and alerts; emergency measures for handling incidents; coordination of incident response; issuing guidelines, advisories, vulnerability notes and whitepapers; and other prescribed functions. It may call for information and issue directions under Section 70B(6), and non-compliance is punishable with up to one year or fine up to ₹1 crore or both, cognizable only on its authorised officer's complaint.

What do the CERT-In Directions of 2022 require?

Reporting of the listed cyber security incidents within six hours of noticing; maintenance of ICT logs for a rolling 180 days within India; synchronisation of system clocks with national time sources; five year retention of validated subscriber and customer records by VPN, cloud and data centre providers; five year KYC and transaction records for virtual asset businesses; and a designated point of contact with CERT-In.

7. Related Topics

  • Topic 63: Sections 70 and 70A. Protected systems and NCIIPC.
  • Topic 19: IT Act and Cybersecurity. The national framework around CERT-In.