10 distinct application pages. The established Finin2min hub remains the canonical source/law layer.
For **India Recorded 29.44 Lakh Cyber Security Incidents in 2025**, first fix **incident classification** and the governing date. Reconcile **threat-intelligence correlation** to the **SIEM/EDR log**, then complete the operational step only when **notification/escalation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **CERT-In Incident Response for a Government-Connected Vendor**, first fix **containment and service continuity** and the governing date. Reconcile **vulnerability remediation** to the **CERT-In/advisory record**, then complete the operational step only when **recovery evidence** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **National Cyber Coordination Centre Threat Intelligence**, first fix **threat-intelligence correlation** and the governing date. Reconcile **notification/escalation** to the **vulnerability report**, then complete the operational step only when **incident classification** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **NCIIPC Critical Information Infrastructure Alerts**, first fix **vulnerability remediation** and the governing date. Reconcile **recovery evidence** to the **vendor/system evidence**, then complete the operational step only when **containment and service continuity** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Cyber Swachhta Kendra for Corporate Devices**, first fix **notification/escalation** and the governing date. Reconcile **incident classification** to the **recovery and post-incident report**, then complete the operational step only when **threat-intelligence correlation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Sectoral CSIRT Coordination After a Cyber Incident**, first fix **recovery evidence** and the governing date. Reconcile **containment and service continuity** to the **incident timeline**, then complete the operational step only when **vulnerability remediation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Cyber Incident Playbook for Citizen-Facing Digital Platforms**, first fix **incident classification** and the governing date. Reconcile **threat-intelligence correlation** to the **SIEM/EDR log**, then complete the operational step only when **notification/escalation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Vulnerability Assessment for Public-Facing Portals**, first fix **containment and service continuity** and the governing date. Reconcile **vulnerability remediation** to the **CERT-In/advisory record**, then complete the operational step only when **recovery evidence** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Cyber Security Incident Trend from 15.93 Lakh to 29.44 Lakh**, first fix **threat-intelligence correlation** and the governing date. Reconcile **notification/escalation** to the **vulnerability report**, then complete the operational step only when **incident classification** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/currentFor **Third-Party Cyber Incident Affecting a Government Service**, first fix **vulnerability remediation** and the governing date. Reconcile **recovery evidence** to the **vendor/system evidence**, then complete the operational step only when **containment and service continuity** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.
P0 — latest/current