Skip to main content
Finin2minBatch 08 · Source checked 14 Aug 2026
Cyber Security & ResilienceUpdated 5 October 2026

CERT-In Incident Response for a Government-Connected Vendor: Notification, Evidence and Coordination Checklist

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

India-first finance, audit and risk workflow with primary-source anchors.

2-minute summary

Current position

For a Government-connected vendor incident, current CERT-In directions remain the operational reporting anchor. The affected organisation and vendor should assess reportability promptly, preserve evidence and coordinate with the Government service owner; a contractual SLA cannot extend a shorter statutory reporting clock.

Control and decision map

#Control / decision step
1Maintain an incident contact matrix for vendor, customer CISO, legal, regulator and CERT-In.
2Preserve system, firewall, identity and application logs before rebuilding affected assets.
3Classify whether the incident falls within CERT-In reportable categories and record the decision time.
4Send an initial customer incident notice with known facts, service impact and containment status.
5Coordinate authority reporting without waiting for a perfect root-cause report.
6Track remediation, evidence return and post-incident contractual actions to closure.

Evidence pack

Worked example

A cloud vendor detects unauthorised admin access at 10:00 AM affecting a citizen-service API. At 11:00 AM it has containment evidence but not the full forensic cause. The incident team should not wait until the next day for a polished report; it escalates to the Government customer, assesses CERT-In reporting and preserves logs while the investigation continues.

Common mistakes

  1. Waiting for a final forensic report before escalating.
  2. Assuming the vendor alone owns all reporting duties.
  3. Rebuilding servers before preserving volatile evidence.
  4. Using a contract SLA longer than statutory reporting windows as the only deadline.

Frequently asked questions

Is every vendor incident reportable to CERT-In?

No. Assess the incident against the current directions and categories.

Can incomplete information be reported?

CERT-In guidance permits reporting information available at the time and supplementing details later.

What should the contract require?

Prompt notice, log preservation, cooperation, root-cause evidence and authority-support obligations.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, contract, facts and professional judgement before acting.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.