CERT-In · India

CERT-In’s 6-hour window starts
with an employee who reports.

The CERT-In Directions of 28 April 2022 require cyber incidents, including phishing attacks, to be reported to CERT-In within 6 hours of being noticed, and CERT-In’s 2025 and 2026 advisories go further, recommending regular phishing and social-engineering training for all employees with realistic simulations.

Binding rule
CERT-In Directions No. 20(3)/2022-CERT-In, 28 April 2022: report within 6 hours, keep logs for 180 days
Latest guidance
Advisory CIAD-2026-0020 (26 April 2026) recommends realistic phishing simulations, including AI-generated text, voice and video lures
Applies to
Service providers, intermediaries, data centres, body corporate and government organisations
KeenSec evidence
Report logs with timestamps and verdicts, simulation results, training records, policy acknowledgements

What CERT-In says about people

One rule, and a lot
of recent advice.

Only the 2022 Directions are binding.

DocumentDateWhat it says about people
Directions No. 20(3)/2022-CERT-In28 April 2022Identity theft, spoofing and phishing attacks are reportable incidents, to be reported within 6 hours of being noticed.
Advisory CIAD-2026-0020, Frontier AI driven cyber risks26 April 2026Regular phishing and social-engineering training for all employees, including realistic simulations of AI-generated text, voice and video lures.
Advisory CIAD-2025-0019, Essential measures for industry10 May 2025Train employees on phishing and social engineering, and simulate phishing attack exercises to improve awareness.
15 Elemental Cyber Defense Controls for MSMEs1 September 2025Awareness training at least twice a year for all employees and contractors, covering phishing and social engineering.
Comprehensive Cyber Security Audit Policy Guidelines25 July 2025Social-engineering tests of general staff in an audit must be anonymised, so no individual is identified or penalised.

From inbox to decision

How employee reports
reach your team faster.

  1. 01

    Employee reports

    One click on the Phishing Reporter, in the inbox they already use.

  2. 02

    Automated analysis

    Links, senders and locations are checked against multiple threat-intelligence and reputation sources.

  3. 03

    Team triages

    Your security team sees the report with its verdict and timestamps, and decides whether it is an incident.

  4. 04

    You decide and report

    If it is reportable, your team follows its own CERT-In process.

Expectation to record

The trail behind
every report.

REPORT LOGS

When it was reported.

Every Phishing Reporter submission with timestamps and reporter details.

ANALYSIS

What the checks found.

Automated verdicts built from multiple threat-intelligence and reputation sources.

SIMULATION RESULTS

Who reports under test.

Reporting rates and speed from realistic simulations, including AI-written lures, by team and channel.

TRAINING

Who knows what to report.

LMS completions and certificates, scheduled as often as your policy requires.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. CERT-In Directions No. 20(3)/2022-CERT-In under section 70B(6)28 April 2022 · binding
  2. FAQs on the Cyber Security Directions of 28.04.2022May 2022 · explanatory, not a legal document
  3. Advisory CIAD-2026-0020: Defending Against Frontier AI Driven Cyber Risks26 April 2026 · advisory
  4. Advisory CIAD-2026-0037: Emerging threats targeting Microsoft 3657 August 2026 · advisory, recommends awareness training on phishing and BEC
  5. Advisory CIAD-2025-0019: Essential Measures for Industry10 May 2025 · advisory
  6. 15 Elemental Cyber Defense Controls for MSMEs (CISG-2025-03)1 September 2025 · baseline recommendations
  7. Comprehensive Cyber Security Audit Policy Guidelines25 July 2025 · guidelines, section 15.2.2
  8. Blueprint for Defending against AI-Assisted Vulnerabilities Exploitation25 May 2026 · guidance, workforce awareness and deepfake awareness

Questions buyers ask

Frequently asked questions.

Does CERT-In require phishing simulation?

The binding 2022 Directions do not mention training. CERT-In’s advisories recommend it: the April 2026 advisory asks for regular phishing and social-engineering training for all employees, including realistic simulations of AI-generated text, voice and video lures.

Are phishing attacks reportable to CERT-In?

Yes. The Directions list identity theft, spoofing and phishing attacks among the incidents to report within 6 hours of noticing them. Deciding whether something is reportable, and reporting it, stays with your team.

How should staff be tested during a CERT-In audit?

The July 2025 audit guidelines say social-engineering tests of general staff within an audit must use anonymised or statistical techniques, target only employees in the agreed scope, and need written permission. That governs audit engagements; your own awareness programme follows your policy.

Does KeenSec make us compliant with the CERT-In Directions?

No tool makes you compliant on its own. KeenSec helps employees report suspicious messages quickly and gives your team analysed reports, but your organisation remains responsible for reporting to CERT-In.

Let’s connect the dots

Every report, analysed.
Every minute, counted.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo