You Have 6 Hours to Notify CERT-In After a Data Breach. Here's What the Law Requires
Most Indian companies discover a data breach the wrong way: a panicked call from IT at midnight, a journalist asking uncomfortable questions or a ransom note on the company server.
Then comes the second crisis the legal one.
Under Rule 12(1)(a) of the CERT-In Rules 2022, the moment a breach occurs, a six-hour countdown begins. Not six hours from when you find out. Not six hours from when your lawyers are briefed. Six hours from when the breach occurs.
Miss that window and the penalties are severe. More importantly, the chaos that follows an unmanaged breach regulatory scrutiny, customer loss, director liability becomes exponentially harder to contain.
This is what a legal-led incident response looks like. And this is exactly what we do at LLM Advocates.
The Three Legal Deadlines Every Indian Business Must Know
Before you can respond to a breach correctly, you need to understand what the law actually demands.
India's CERT-In Rules 2022 create a three-stage mandatory reporting framework. Each stage has binding obligations. None of them are optional.
Hour 0 to 6: Initial CERT-In Notification
This is the most punishing deadline in Indian cybersecurity law. Under Rule 12(1)(a), organisations must submit an initial notification to CERT-In within six hours of becoming aware of a cybersecurity incident. The notification does not need to be exhaustive but it must exist. Silence is not a strategy. Delay is not protected. This window is non-negotiable and carries significant penalties for non-compliance.
Hour 0 to 72: Extended Incident Report
Within 72 hours, a detailed extended report must be submitted to CERT-In. This report must cover the nature of the incident, which systems were affected, what categories of data were compromised and what preliminary remediation steps have been taken. This is where most companies who survived the six-hour window stumble because producing a structured, accurate report during active breach containment requires legal and technical coordination that most teams have never rehearsed.
Day 30: Final Detailed Report
By the 30-day mark, a comprehensive final incident report is due. This includes a root cause analysis, full scope assessment of the breach, documentation of all remediation actions completed and a forward-looking prevention plan. This report becomes part of the regulatory record. It can be referenced in future audits, enforcement actions or litigation. It must be both accurate and strategically prepared.
What Most Companies Get Wrong
Here is the uncomfortable truth most cybersecurity vendors will not tell you: a technical incident response and a legal incident response are not the same thing.
Your IT team can isolate the affected server. Your cybersecurity firm can scan for malware. But neither of them is thinking about what your CERT-In notification says, whether your internal communications create inadvertent admissions, how to preserve evidence in a way that is usable in court or what your contractual notification obligations are to customers and vendors.
Legal exposure from a data breach does not come only from the breach itself. It comes from what you say, what you document and what you fail to report in the hours immediately after it.
That is the gap a legal-led response is designed to close.
What LLM Advocates Does in the First 6 Hours
When a breach is reported to us, the clock is already running. Here is our integrated response flow.
Within the First Hour: Legal Triage and Breach Classification
We immediately assess whether the incident qualifies as a reportable cybersecurity incident under the CERT-In Rules. Not every system anomaly triggers mandatory reporting. Misclassifying an incident in either direction has consequences. We work alongside your technical team to establish the scope of what is known and what is unknown, and we document this assessment with timestamps from the start.
Hours 1 to 3: Evidence Preservation and Communication Lockdown
This step is where legal expertise becomes irreplaceable. We advise on which communications channels to use internally, how to instruct employees to avoid creating problematic written records and how to preserve forensic evidence in a manner that will withstand legal scrutiny later. We also begin identifying downstream notification obligations whether to customers, regulators beyond CERT-In or international counterparts if cross-border data flows are involved.
Hours 3 to 5: Drafting the Initial CERT-In Notification
The initial notification must be factually accurate but carefully framed. Oversharing at this stage can create admissions that are difficult to walk back. Undersharing invites regulatory scrutiny. We prepare the notification with precision stating what is confirmed, what is under investigation and what remediation is underway. Every word in this document matters.
Hour 5 to 6: Submission and Internal Briefing
The notification is submitted before the deadline, with full documentation of the submission timestamp. Simultaneously, we brief your leadership team on what has been disclosed, what the next 66 hours look like (toward the 72-hour extended report) and how to handle external inquiries from media, customers or business partners in the interim.
The 72-Hour and 30-Day Reports: Where the Legal Record Is Built
Surviving the first six hours is only the beginning.
The 72-hour extended report requires your organisation to have a coherent, defensible account of what happened. This is not the moment for guesswork or internally inconsistent statements. We work with your technical and forensic teams to build a report that is complete, accurate and legally reviewed before submission.
The 30-day final report is effectively a permanent regulatory document. It must demonstrate that your organisation took the breach seriously, responded systematically and has implemented measures to prevent recurrence. This report often becomes the foundation for any subsequent enforcement proceedings or civil litigation. Organisations that treat it as a compliance checkbox rather than a legal document frequently discover this the hard way.
Integrated Response Is Not Optional Anymore
India's data protection landscape is shifting fast. The Digital Personal Data Protection Act 2023 adds another layer of obligation for organisations handling personal data. Sector-specific regulators RBI, SEBI, IRDAI, TRAI have their own breach notification requirements that run parallel to CERT-In's framework.
A breach today is not just a cybersecurity event. It is a legal event with regulatory, contractual and reputational dimensions that unfold simultaneously across multiple timelines.
The organisations that emerge intact are the ones who treat incident response as a legal function from the moment the breach is detected. Not after the IT team has finished. Not after the press calls. From the moment the breach occurs.
The Clock Starts When the Breach Occurs
Not when you find out. Not when someone escalates it. Not when legal is finally looped in.
When. The. Breach. Occurs.
If you are reading this before a breach, you are in the best possible position because you can prepare. That means having a legal-led incident response protocol in place before you need it, with pre-agreed roles, pre-drafted notification templates and a direct line to legal counsel who understands the regulatory terrain.
If you are reading this during a breach: call us now.
LLM Advocates provides dedicated data breach incident response legal services for Indian businesses. Our team is available for immediate engagement when you need it most.
Call us now at LLMadvocates.com because every hour you wait is an hour closer to a missed deadline, a regulatory penalty and a legal record that works against you.