Overview
Section 70B, the 2022 Directions and the wider framework
CERT-In, the Indian Computer Emergency Response Team, is India's national agency for cyber security incident response under Section 70B of the Information Technology Act, 2000, working within a wider institutional architecture.
CERT-In, the Indian Computer Emergency Response Team, is India's national agency for responding to cyber security incidents. It is an office of the Ministry of Electronics and Information Technology (MeitY), was formed in 2004, and draws its statutory power from Section 70B of the Information Technology Act, 2000, a section inserted by the IT (Amendment) Act, 2008. Its core work is to collect and analyse information on cyber incidents, issue alerts and forecasts, take emergency measures and coordinate the national response. In April 2022 it issued binding Directions that, among other things, require organisations to report specified cyber incidents within six hours. CERT-In sits within a wider architecture that includes the NCIIPC for critical information infrastructure, the Indian Cyber Crime Coordination Centre under the Home Ministry, the National Cyber Security Policy 2013 and the Cyber Swachhta Kendra.
What CERT-In Is: India's National Cyber Security Incident Agency
The national computer emergency response team under MeitY
CERT-In, the Indian Computer Emergency Response Team, is the national agency that India relies on to respond to cyber security incidents. It is an office of the Ministry of Electronics and Information Technology, was formed in 2004, and operates a round-the-clock incident-response desk. When a serious attack strikes a department, a bank or a company, CERT-In is the body expected to receive the report, analyse the threat, warn others and coordinate recovery.
It is worth stating clearly what CERT-In does and does not do. It is a technical and coordinating agency, not a police force and not a regulator of content. It issues alerts, advisories and vulnerability notes, runs awareness and capacity-building work, and conducts cyber-security drills, but the investigation and prosecution of cybercrime sit with the police and the Home Ministry's machinery. Understanding this division of labour is the key to placing CERT-In correctly within the wider security architecture.
CERT-In was set up because a modern state cannot leave cyber defence to individual departments acting alone. A coordinated national response needs one body that watches the whole landscape, shares warnings quickly and speaks for the country abroad. CERT-In plays that nodal role, working with similar teams in other nations and with India's own sectoral response teams. The figure below sets out its headline facts.
Why Cyber Security and CERT-In Are in the News
A digitising India, rising attacks and the 2022 Directions
Why it matters now is that India's exposure to cyber risk is rising as fast as its digital footprint. Public services, online payments, critical utilities and private data have all moved into cyberspace, and with them the incentive for attackers. According to figures published by the Press Information Bureau, the incidents handled by CERT-In rose from about 10.29 lakh in 2022 to about 22.68 lakh in 2024.
CERT-In itself returned to prominence through its April 2022 Directions, which imposed binding obligations on a wide range of organisations, most visibly a duty to report specified cyber incidents within six hours. The Directions drew both support, as a way to build a clearer national picture of attacks, and criticism from parts of industry and from privacy commentators. That debate is one reason the topic is live for the exam.
Understanding the Significance of CERT-In for India's Security
Detection, early warning and coordinated national response
What is the significance of CERT-In lies first in detection and early warning. By gathering reports of attacks from across the country and analysing them, CERT-In can spot a new malware strain or a wave of intrusions early and warn potential targets before they are hit. This early-warning role turns scattered, isolated incidents into a shared picture that the whole system can act on, which is the heart of effective cyber defence.
Its second significance is coordination. A serious attack rarely respects departmental lines; it can spread across banks, utilities and government systems at once. CERT-In gives India a single point that can pull together the response, share what is known and prevent each victim from fighting alone. By coordinating with sectoral teams, with the NCIIPC for critical systems and with the Home Ministry on cybercrime, it knits a fragmented landscape into something closer to a national defence.
Its third significance is resilience and trust. India's growth increasingly depends on citizens and businesses trusting digital systems with their money and data. By raising the security of those systems, publishing advisories and cleaning infected machines, CERT-In helps protect that trust. A credible national response agency is, in this sense, part of the foundation on which the digital economy and digital governance rest.
The Statutory Basis: Section 70B of the IT Act and CERT-In's Functions
Section 70B of the Information Technology Act, 2000
CERT-In's authority rests on Section 70B of the Information Technology Act, 2000. The section was inserted by the IT (Amendment) Act, 2008, and it appoints CERT-In as the national agency for incident response. Giving the agency a statutory footing matters: its warnings, requests for information and directions carry the force of law rather than mere advice, and organisations have a legal duty to cooperate. This is what separates it from a purely advisory body.
The section also lists CERT-In's functions. It is to collect, analyse and disseminate information on cyber incidents; to issue forecasts and alerts about cyber security incidents; to take emergency measures for handling such incidents; to coordinate cyber-incident response activities; and to issue guidelines, advisories and vulnerability notes on information security practices. These functions, read together, describe a national watch-and-warn agency that both sees threats coming and helps the country respond when they arrive.
Crucially, Section 70B also empowers CERT-In to call for information and to give directions to service providers, intermediaries, data centres and corporate bodies, and it backs these powers with penalties for non-compliance. It is this power to issue binding directions that CERT-In used in 2022. The figure below summarises the statutory functions, and the table that follows sets out the section in compact form.
| Element | Provision | What it means |
|---|---|---|
| Legal basis | Section 70B, IT Act 2000 (inserted by the 2008 amendment) | Appoints CERT-In as the national agency for cyber incident response |
| Parent ministry | Ministry of Electronics and Information Technology | CERT-In is an office under MeitY |
| Core functions | Collect, analyse, alert, respond, coordinate | A national watch, warn and response agency |
| Binding power | May call for information and issue directions | Backed by penalties for non-compliance |
Reading the rows together shows the logic: a statutory mandate, a clear parent ministry, a defined set of functions and real enforcement teeth. It is this combination, and not just technical skill, that lets CERT-In act as the country's nodal cyber agency.
The 2022 CERT-In Directions and the Debate Around Them
Six-hour reporting, log retention and provider KYC
In April 2022 CERT-In used its Section 70B power to issue binding Directions on information-security practices. Their best-known requirement is that organisations must report specified types of cyber incident to CERT-In within six hours of noticing them or being made aware of them. The aim, as the government explains it, is to give CERT-In a faster and fuller national picture of attacks so that warnings can go out and patterns can be spotted while a campaign is still unfolding.
The Directions go beyond reporting. They require organisations to synchronise their system clocks to government time servers, and to maintain logs of their ICT systems for a rolling period of 180 days within India, so the trail of an attack can be reconstructed. For data centres, virtual private server providers, VPN providers and cloud providers, they require retention of validated subscriber details for five years, and they impose KYC norms on virtual-asset providers.
Taken together, these obligations are meant to close the visibility gaps that let attacks go unreported and untraced. The government's case is that a fragmented picture, in which many incidents are quietly handled and never shared, leaves the whole system blind. By forcing prompt reporting and durable logs, the Directions try to convert that silence into shared intelligence. The figure below sets out the core requirements.
The case for the Directions and the concerns raised, in measured terms
The Directions also drew criticism, and a balanced account must present it fairly. Parts of industry argued that a six-hour window is tight by international standards, where longer windows such as 72 hours are common, and that the breadth of incidents to report and the logging burden would be costly for smaller firms. Privacy commentators raised concerns about the five-year retention of subscriber data and the obligations placed on VPN providers.
The government's response, set out in CERT-In's own FAQs, was that the obligations are proportionate to the threat, that reporting is focused on serious incidents, and that the rules bring India closer to an accountable national reporting system. CERT-In also extended some timelines to ease compliance. The honest position is that this is a genuine policy debate: a real security gain in visibility weighed against real costs and privacy concerns.
The Wider Institutional Architecture Around CERT-In
NCIIPC and the protection of critical information infrastructure (Section 70A)
CERT-In does not work alone. The National Critical Information Infrastructure Protection Centre (NCIIPC) protects India's most sensitive digital systems. It was created under Section 70A of the IT Act by a notification in 2014 and is a unit of the National Technical Research Organisation. Its task is to protect Critical Information Infrastructure, which the Act defines as computer resources whose loss would have a debilitating impact on national security, the economy, public health or safety.
In practice NCIIPC identifies systems in sectors such as power, banking, telecom, transport and defence as critical, designates them as protected systems, and issues threat intelligence, advisories and guidelines to the organisations that run them. Where CERT-In watches over the whole national landscape, NCIIPC concentrates on the highest-stakes systems, the ones a hostile state or terrorist actor would most want to disable. The two are complementary layers of the same defence, not duplicates.
The Indian Cyber Crime Coordination Centre, the reporting portal and 1930
On the law-enforcement side sits the Indian Cyber Crime Coordination Centre (I4C), an attached office of the Ministry of Home Affairs set up to tackle cybercrime in a coordinated way. Its scheme was approved in 2018 and it was inaugurated in 2020. Where CERT-In deals with the technical handling of incidents, I4C focuses on the crime dimension, helping states and police forces investigate online fraud, harassment and other offences, and building tools and training for them.
I4C also runs the citizen-facing machinery of cybercrime response. The National Cybercrime Reporting Portal (cybercrime.gov.in), launched in 2019, lets the public report cybercrimes at any hour, with a special focus on offences against women and children. The toll-free helpline 1930 was set up so that victims of online financial fraud can raise an alarm quickly enough for money to be frozen before it is withdrawn. Together the portal and the helpline turn policy into a service ordinary citizens can use.
The National Cyber Security Policy 2013 and the Cyber Swachhta Kendra
The architecture also rests on a guiding policy. The National Cyber Security Policy, 2013, issued by MeitY, set out a vision of a secure and resilient cyberspace for citizens, businesses and government. Among its objectives was building a workforce of around five lakh skilled professionals over five years, alongside goals on protecting information and strengthening institutions. The policy is now widely seen as dated, and the case for a refreshed strategy is a standing demand.
At the household level sits the Cyber Swachhta Kendra, the Botnet Cleaning and Malware Analysis Centre. Launched in 2017 and operated by CERT-In under Section 70B, it detects computers and devices in India infected by botnets and malware, works with Internet Service Providers to notify the affected users, and offers free tools to clean infected systems. It is the part of the architecture that reaches ordinary users directly. The figure below maps these institutions together.
The Rising Cyber-Threat Landscape Facing India
Ransomware, critical-infrastructure attacks, supply-chain risk and phishing
The architecture exists to counter a fast-changing set of threats, and understanding them is essential for the exam. The first is ransomware, in which attackers encrypt an organisation's data and demand payment to release it, freezing hospitals, firms and even public services. The second is attacks on critical infrastructure, the power grids, banking systems, telecom networks and transport controls whose disruption can ripple across the economy and into everyday life, which is precisely why NCIIPC exists.
A third and growing threat is the supply-chain attack, in which adversaries compromise a trusted piece of software or a vendor and use it as a backdoor into many victims at once, turning the tools organisations depend on into a route of entry. A fourth, and the most common, is phishing and online financial fraud, in which deceptive messages trick people into surrendering passwords or money. To these are added state-sponsored intrusions and, increasingly, attacks aided by artificial intelligence.
These threats matter for internal security because so much of national life now runs on networks. An attack on a power utility, a payment system or a defence network is no mere technical nuisance; it can affect public order, economic stability and national security directly. This is why cyber security is a core element of internal security, and why the communication networks that carry the nation's data are themselves a security concern. The figure below sets out the main threats.
Challenges and the Road Ahead for India's Cyber Security
Capacity, coordination, the Directions debate and a missing overarching law
Several challenges temper this architecture. The first is capacity: cyber security demands a large pool of trained specialists, and the shortfall against the workforce the 2013 policy envisaged is real, leaving agencies and firms stretched. The second is coordination across a crowded field. CERT-In, NCIIPC, the I4C, sectoral teams, the police and the armed forces all have roles, and ensuring they work as one rather than in silos is a continuing administrative task that gaps can still slip through.
A third challenge is the unresolved balance the 2022 Directions exposed, between the security value of prompt mandatory reporting and the costs and privacy concerns it raises, which a stable framework must settle. A fourth, and most structural, is the absence of a single overarching cyber security law. India's provisions are spread across the IT Act, sectoral rules and the new data-protection law, and many argue a consolidated statute would give clearer direction.
The way forward that emerges is therefore fairly clear in outline. It involves a refreshed national cyber security strategy to replace the ageing 2013 policy, a serious investment in skilling and indigenous security capability, tighter coordination among the many agencies, and consideration of a dedicated cyber security law to give the architecture a firmer legal spine. Strengthening international cooperation and public awareness rounds out an agenda that treats cyber security as a permanent, evolving part of national security.
Cyber Security in Context: Data Protection, Digital India and National Security
How CERT-In connects to data protection, Digital India and internal security
Contemporary linkages place CERT-In within a dense web of India's digital and security policy. It connects to data protection, since the Digital Personal Data Protection Act, 2023 and CERT-In's incident-reporting regime both bear on how breaches of personal data are handled, the two together shaping accountability when data is compromised. It connects to Digital India, because the more services move online, the larger the surface that CERT-In and the wider architecture must defend.
It also connects to the broader idea of internal security. The UPSC syllabus treats communication networks and cyber security as part of internal security precisely because attacks on networks can threaten public order, the economy and the state itself. CERT-In, NCIIPC and the I4C are, in this sense, internal-security institutions for the digital age, sitting alongside the older machinery of policing. The threads below are worth holding in working memory:
- Data protection: The Digital Personal Data Protection Act, 2023, which governs personal data and interacts with CERT-In’s incident-reporting and breach regime.
- Digital India and digital public infrastructure: The drive that expands the digital surface CERT-In and NCIIPC must secure.
- Critical information infrastructure: The highest-stakes systems protected by NCIIPC under Section 70A of the IT Act.
- Cybercrime machinery: The I4C, the reporting portal and helpline 1930 under the Home Ministry, the law-enforcement face of cyber security.
Taken together, these linkages show that cyber security is not a niche technical subject but a cross-cutting concern that runs through India's economy, its governance and its national security, with CERT-In as the operational heart of the country's defence.
UPSC Relevance and Exam Focus
Where CERT-In and cyber security fit in the UPSC-CSE syllabus
This topic maps most directly to General Studies Paper III: the role of communication networks in internal security, the basics of cyber security, and challenges to internal security through communication networks. It also touches the role of media and social networking sites and the broader theme of security challenges and their management, themes that recur across the internal-security part of the syllabus and that examiners return to often.
For Prelims, hold the high-yield facts: CERT-In is the national agency under Section 70B of the IT Act 2000, an office of MeitY formed in 2004; NCIIPC protects critical information infrastructure under Section 70A; the I4C and the portal cybercrime.gov.in with helpline 1930 sit under the Home Ministry; the National Cyber Security Policy dates to 2013; and the Cyber Swachhta Kendra is the botnet-cleaning centre run by CERT-In. Knowing which body sits under which ministry is the classic trap.
For Mains, the recurring framing is to set out the cyber-threat landscape and assess India's security framework against it, weighing the strengths of CERT-In and the wider architecture against the challenges of capacity, coordination and a missing overarching law. A strong answer treats cyber security as a core internal-security concern, describes the institutions accurately, handles the 2022 Directions debate in measured terms, and closes with a credible way forward.
Recurring linked concepts an aspirant should keep in working memory:
- Section 70B and Section 70A: The statutory basis of CERT-In and the NCIIPC respectively under the IT Act, 2000.
- Critical information infrastructure: Systems whose disruption would debilitate national security, the economy or public safety.
- National Cyber Security Policy 2013: The guiding policy, now widely seen as due for refresh into a new strategy.
- Cybercrime versus cyber incident response: The I4C and police on one side, CERT-In and NCIIPC on the other.
A common Prelims trap is to place CERT-In or NCIIPC under the wrong ministry, or to confuse the two; hold that CERT-In and NCIIPC are technical bodies on the MeitY and NTRO side, while the I4C and the cybercrime portal sit under the Home Ministry.
A common Mains trap is to list institutions without analysis. The exam value lies in a balanced judgment: the genuine strengths of the architecture, the real challenges of capacity and coordination, the measured debate over the 2022 Directions, and a credible way forward built around a refreshed strategy and a possible dedicated law.
Previous Year UPSC-CSE Questions By the end you will be able to draft model answers for the following UPSC questions. Each question carries a collapsible framework showing how to approach it in the exam.
- UPSC Mains 2017 GS-IIIDiscuss the potential threats posed by cyber attacks and the security framework India has in place to prevent and respond to them.
How to structure the answer in the exam
Body (sub-themes to develop):
- The threat landscape: ransomware, attacks on critical infrastructure such as power, banking, telecom and transport, supply-chain attacks, phishing and online financial fraud, and state-sponsored and AI-aided intrusions, with the rising scale of incidents handled by CERT-In.
- The core of the framework: CERT-In as the national agency under Section 70B of the IT Act 2000, with its functions of collecting and analysing incident information, issuing alerts and forecasts, taking emergency measures and coordinating the response, and its 2022 Directions on six-hour reporting and logging.
- Critical-infrastructure protection: NCIIPC under Section 70A protecting Critical Information Infrastructure in sectors such as power, banking, telecom and defence as protected systems.
- The cybercrime and citizen-facing machinery: the Indian Cyber Crime Coordination Centre under the Home Ministry, the National Cybercrime Reporting Portal and helpline 1930, plus the National Cyber Security Policy 2013 and the Cyber Swachhta Kendra for botnet cleaning.
- The assessment: strengths of the layered framework weighed against the challenges of capacity, coordination across many agencies, the debate over the 2022 Directions, and the absence of a single overarching cyber security law.
Sources and Further Reading
- Ministry of Electronics and Information Technology: CERT-In
- India Code: The Information Technology Act, 2000 (updated text, including Section 70A and Section 70B)
- Press Information Bureau: CERT-In issues directions on prevention, response and reporting of cyber incidents
- Press Information Bureau: CERT-In releases FAQs on the Cyber Security Directions of 28.04.2022
- National Critical Information Infrastructure Protection Centre (NCIIPC)
- Ministry of Home Affairs: Indian Cybercrime Coordination Centre (I4C)
- Indian Cybercrime Coordination Centre: National Cybercrime Reporting Portal
- Ministry of Electronics and Information Technology: National Cyber Security Policy, 2013
- Cyber Swachhta Kendra: Botnet Cleaning and Malware Analysis Centre
- Press Information Bureau: CERT-In, India's Frontline Defender against Cyber Threats
- Wikipedia: Indian Computer Emergency Response Team
Editorial Disclaimer
This briefing is for UPSC preparation. Verify the facts and provisions against the official MeitY, CERT-In, PIB and India Code sources before relying on them.
