Report an IncidentTalk to Sales

Cybersecurity Regulatory Bodies in India: CERT-In, Sectoral CSIRTs & Key Frameworks

Reviewed By: Nilesh Yadav
Updated on: September 17, 2026
Reading Time: 10 Min
Published: 
September 17, 2026

India’s cybersecurity oversight involves more than a single authority. CERT-In operates as the national agency for cyber incident response, while sector-specific and state-level CSIRTs address risks within defined environments. Alongside these bodies, regulators such as RBI, TRAI, SEBI, and IRDAI establish cybersecurity requirements for regulated organisations. This blog covers their roles, key CERT-In frameworks, 2025 publications and figures, and what these requirements mean for organisations operating in India.

Key Takeaways

  • CERT-In is India’s national cybersecurity incident-response agency: Operating under Section 70B of the Information Technology Act, 2000, CERT-In analyses cyber incidents, issues alerts and advisories, coordinates responses, and provides cybersecurity guidance.
  • CERT-In supports multiple national cybersecurity initiatives: Cyber Swachhta Kendra, NCCC, the Cyber Crisis Management Plan, and security assurance activities address different areas of cyber hygiene, threat coordination, crisis preparedness, and security auditing.
  • Sectoral and State CSIRTs extend incident-response capabilities: CSIRT-Fin and CSIRT-Power focus on the financial and power sectors, while State CSIRTs strengthen cybersecurity coordination and response at the state level.
  • Sector regulators impose additional cybersecurity requirements: RBI, TRAI, SEBI and IRDAI have sector-specific regulatory roles, meaning organisations may need to address CERT-In requirements alongside requirements applicable to their particular industry.
  • CERT-In’s 2025 activity included major cybersecurity publications and operational requirements: Its 2025 record included 29,44,248 cybersecurity incidents handled, alongside publications covering ransomware, BFSI threats, smart-city infrastructure, UAS security, quantum readiness, cybersecurity audits and MSME cyber defence controls.

What is CERT-In? Mandate Under Section 70B of the IT Act

The Indian Computer Emergency Response Team (CERT-In) is India’s national agency for responding to cybersecurity incidents. It operates under the Ministry of Electronics and Information Technology (MeitY) and is designated as the national agency under Section 70B of the Information Technology Act, 2000. Its mandate includes analysing cyber incidents, issuing alerts and advisories, coordinating incident response, and providing cybersecurity guidance.

CERT-In's 2025 Numbers

In 2025, CERT-In handled 29,44,248 cybersecurity incidents, while issuing 1,530 security alerts, 390 vulnerability notes and 65 advisories. It also conducted 32 technical training programmes, trained 20,799 participants, and carried out 18 domestic and five international cybersecurity drills or exercises during the year.

What Are the Core Functions of CERT-In?

CERT-In serves as India’s national agency for cybersecurity under Section 70B of the Information Technology Act, 2000. Its statutory functions cover the collection and analysis of cyber incident information, threat forecasting and alerts, emergency measures, incident response coordination, and the publication of cybersecurity guidance and advisories.

These functions can be understood through the following areas:

  • Cyber incident intelligence: Collects, analyses, and disseminates information on cybersecurity incidents.
  • Threat forecasting and alerts: Forecasts cybersecurity incidents and issues alerts about emerging threats and risks.
  • Emergency response: Takes emergency measures for handling cybersecurity incidents.
  • Response coordination: Coordinates cyber incident response activities among relevant stakeholders.
  • Security guidance: Issues guidelines, advisories, vulnerability notes and whitepapers covering information security practices, prevention, response and incident reporting.
  • Additional cybersecurity functions: Performs other cybersecurity functions that may be prescribed under the applicable legal framework. 

Strengthen Your 24/7 Security MonitoringGet continuous monitoring, alert triage and incident response support.

Explore our Managed SOC Service

What Frameworks and Initiatives Does CERT-In Run?

CERT-In supports India’s cybersecurity ecosystem through initiatives and frameworks covering cyber hygiene, cyber crisis management, security assurance and coordinated cybersecurity preparedness. These have different purposes and should not be presented as equivalent regulatory requirements.

1. Cyber Swachhta Kendra

Cyber Swachhta Kendra is CERT-In’s Botnet Cleaning and Malware Analysis Centre. It helps identify botnet infections and provides security tools and guidance to users for improving cyber hygiene and protecting devices from malware-related threats.

2. National Cyber Coordination Centre (NCCC), Implemented by CERT-In

The National Cyber Coordination Centre (NCCC) is a national-level mechanism for improving situational awareness of cybersecurity threats in cyberspace. CERT-In is responsible for implementing the NCCC, supporting coordinated efforts to understand and address cyber threats at the national level.

  1. Cyber Crisis Management Plan (CCMP)

The Cyber Crisis Management Plan (CCMP) is a framework for dealing with cyber-related incidents and cyber attacks. CERT-In leads its implementation across Central Government Ministries and Departments, states, and key organisations operating in Indian cyberspace. CERT-In has also developed a guidance framework to help entities prepare and implement their own CCMPs.

  1. Security Assurance Framework

CERT-In’s Security Assurance Framework includes information security audit services and the empanelment of security auditors for activities including vulnerability assessment and penetration testing. CERT-In also conducts episodic security audits of key organisations to help enhance their security posture.

What Are Sectoral and State CSIRTs in India?

Sectoral and State Computer Security Incident Response Teams (CSIRTs) extend cybersecurity incident response and coordination to specific sectors and state-level environments. CERT-In provides the guidelines and technical umbrella for establishing these teams, while sectoral CSIRTs such as CSIRT-Fin and CSIRT-Power focus on the cybersecurity needs of their respective sectors. The main CSIRTs covered in this framework include:

1. CSIRT-Fin

CSIRT-Fin is the sectoral CSIRT for India’s financial sector and functions under CERT-In. It provides incident prevention and response services, coordinates responses to cyber incidents across financial-sector entities, and supports security quality management and sector-wide cybersecurity efforts. 

2. CSIRT-Power

CSIRT-Power is the specialised CSIRT for the power sector. It was established at the Central Electricity Authority (CEA) and operates as an extended arm of CERT-In, with responsibilities including coordinating incident response, analysing sector-specific cyber threats, supporting cybersecurity preparedness, and assisting power-sector utilities with cybersecurity measures.

3. State CSIRTs

CERT-In provides guidelines and a framework for States and Union Territories to establish State CSIRTs, which are intended to strengthen cybersecurity incident response and coordination at the state level. CERT-In has been providing technical guidance to state governments for establishing and operationalising these teams. In 2026, MeitY also highlighted the establishment of formal State CSIRTs under CERT-In’s technical umbrella as part of strengthening state-level cybersecurity capabilities. 

As organisations work across different cybersecurity requirements and incident-response responsibilities, continuous security monitoring remains important for identifying and investigating threats. Eventus Security’s Managed SOC provides 24/7 monitoring, alert triage, threat investigation and response support, helping security teams maintain ongoing visibility and respond to incidents as they arise. 

Which Other Sector Regulators Set Cybersecurity Requirements in India?

CERT-In provides the national cybersecurity incident-response framework, while sector regulators establish additional requirements for organisations under their respective regulatory jurisdictions. The applicable requirements therefore depend on the sector and the type of entity.

  • Reserve Bank of India (RBI): RBI establishes cybersecurity and cyber-resilience requirements for regulated entities in the financial sector, covering areas such as governance, security controls, monitoring and incident response.
  • Telecom Regulatory Authority of India (TRAI): TRAI regulates the telecommunications sector and addresses security-related requirements through its applicable telecom regulations, recommendations, and regulatory frameworks.
  • Securities and Exchange Board of India (SEBI): SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) sets cybersecurity and cyber-resilience requirements for SEBI-regulated entities.
  • Insurance Regulatory and Development Authority of India (IRDAI): IRDAI establishes information and cybersecurity requirements for the insurance sector through its applicable information and cybersecurity guidelines.

What Were the Key CERT-In Publications in 2025?

CERT-In published several cybersecurity guidelines, reports, and technical guidance documents in 2025. The following publications are listed in CERT-In’s official records:

  • Cyber Security Guidelines for Smart City Infrastructure: Issued on 17 February 2025, these guidelines address cybersecurity considerations for smart city infrastructure.
  • India Ransomware Report 2024: Published on 25 March 2025, this report covers ransomware tactics, techniques, and trends observed in 2024 in Indian cyberspace.
  • Digital Threat Report 2024 for the BFSI Sector: Released on 7 April 2025, this report examines current and emerging cyber threats and defence strategies relevant to the banking, financial services and insurance sector.
  • Good Practices for Protecting Unmanned Aircraft Systems (UAS) Against Cyber Security Threats: Published on 18 April 2025, this guidance addresses cybersecurity practices for improving the cyber resilience of UAS.
  • Transitioning to Quantum Cyber Readiness: Released on 11 July 2025 in collaboration with SISA, this white paper provides a practical roadmap for organisations preparing for quantum-safe migration and quantum readiness.
  • Comprehensive Cyber Security Audit Policy Guidelines: Issued on 25 July 2025, these guidelines provide guidance for organisations being audited and for cybersecurity auditing organisations.
  • 15 Elemental Cyber Defense Controls for Micro, Small, and Medium Enterprises (MSMEs): Issued on 1 September 2025, this document provides 15 foundational cyber defence controls for MSMEs.

What Does CERT-In Compliance Mean for Your Organisation?

For organisations covered by CERT-In requirements, compliance involves being prepared to identify reportable cyber incidents, meet the prescribed reporting timeline, maintain required records, and address applicable cybersecurity audit requirements. These obligations make incident readiness and ongoing security assurance important parts of cybersecurity operations.

1. Six-Hour Incident Reporting

Organisations should have a defined process for identifying reportable incidents, escalating them internally, and notifying CERT-In within the prescribed timeframe. This requires clear responsibilities and an established reporting process that allows teams to act promptly when an incident is identified. Organisations can also review the requirements around CERT-In six-hour incident reporting when assessing their incident-response processes.

2. Cybersecurity Audit Requirements

Organisations should also maintain appropriate security controls, records and audit evidence to support applicable cybersecurity assessments. This makes CERT-In compliance and SOC audit guidelines relevant when assessing audit readiness and the security practices supporting regulatory compliance.

Need Support With Incident Response?
Get expert support for investigation, containment, and recovery.

Contact Eventus Security

How Can Eventus Security Support Cybersecurity Incident Readiness?

Regulatory requirements can make timely incident identification, investigation, and response an important part of an organisation’s cybersecurity operations. Eventus Security’s Incident Response Service supports organisations during security incidents through investigation, digital forensics, root-cause analysis, threat hunting, containment, remediation and recovery.

Eventus Security’s Key Incident Response Capabilities:

  • Incident Investigation: Eventus Security investigates security incidents to understand what happened, assess the impact, and support appropriate response actions.
  • Digital Forensics and Root-Cause Analysis: Forensic investigation and root-cause analysis help examine relevant evidence and determine how an incident occurred.
  • Threat Hunting and Compromise Assessment: Eventus Security supports proactive investigation to identify potential malicious activity and signs of compromise within an environment.
  • Containment and Remediation: Eventus Security offers containment and remediation activities to help limit the impact of confirmed security incidents.
  • Recovery Support: Eventus Security supports recovery activities following incident containment and remediation, helping organisations move towards restoring affected operations.

Contact Eventus Security to discuss your organisation’s incident response and cybersecurity readiness requirements.

FAQs

1. Who regulates cybersecurity in India?

Cybersecurity in India is overseen through multiple authorities rather than a single regulator. CERT-In is the national agency for cyber incident response, while sector regulators such as RBI, SEBI and IRDAI establish cybersecurity requirements for entities within their respective sectors.

2. Is CERT-In a statutory body?

CERT-In is a statutory authority under Section 70B of the Information Technology Act, 2000. The provision designates the Indian Computer Emergency Response Team as the national agency for performing specified functions relating to cybersecurity incident response.

3. Is NCCC part of CERT-In?

The National Cyber Coordination Centre (NCCC) is implemented by CERT-In. It is a national-level mechanism established to generate situational awareness about cybersecurity threats and support coordinated efforts to address threats in cyberspace.

4. What is Cyber Swachhta Kendra?

Cyber Swachhta Kendra is CERT-In’s Botnet Cleaning and Malware Analysis Centre. It helps identify botnet infections and provides tools and guidance to users for detecting and removing malware and improving cyber hygiene.

Mohd Kaif Idrisi
Mohd Kaif Idrisi is a cybersecurity and GRC professional with experience in information security governance, risk management, compliance, and internal and external audits. He is a Certified ISO 27001:2022 Lead Auditor with experience across ISO 27001, ISO 9001, ISO 27035, SOC 2 Type II, Saudi NCA ECC, Qatar NIA, GDPR, DPDP, and PDPA.

Report an Incident

Report an Incident - Blog

free consultation

Our team of expert is available 24x7 to help any organization experiencing an active breach.

More Topics

crossmenuchevron-down
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram