Progress

Current status
in force
25 Sep 2022in force
27 Jun 2022in grace period
27 Jun 2022adopted
28 Apr 2022adopted

Scope

Implementers
India
Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Government Branch
executive
Government Body
central government
Implementation Level
national

Timeline of events

25 Sep 2022
in force

Implemented CERT-In's Information Security Practices Directive including cybersecurity measures for MSMEs

On 25 September 2022, the Indian Computer Emergency Response Team (CERT-In) "relating to information security practices, procedure, prevention, response and reporting of cyber incidents" enters into force for Micro, Small & Medium Enterprises (MSMEs…

Event typeorder
Action typeimplementation
Government branchexecutive
Government bodycentral government
27 Jun 2022
in grace period

Entry into force with grace period of CERT-In's Information Security Practices Directive including cybersecurity measures

On 27 June 2022, the directive by the Indian Computer Emergency Response Team (CERT-In) "relating to information security practices, procedure, prevention, response and reporting of cyber incidents" enters into force. The directive introduces obliga…

Event typeorder
Action typein force with grace period
Government branchexecutive
Government bodycentral government
27 Jun 2022
adopted

Postponed implementation for MSMEs of CERT-In's Information Security Practices Directive including cybersecurity measures

On 27 June 2022, the Ministry of Electronics and Information Technology announced that the implementation of the Indian Computer Emergency Response Team (CERT-In) "relating to information security practices, procedure, prevention, response and repor…

Event typeorder
Action typepostponement
Government branchexecutive
Government bodycentral government
28 Apr 2022
adopted

Issued CERT-In Information Security Practices Directive including cybersecurity measures

On 28 April 2022, the Indian Computer Emergency Response Team (CERT-In) issued a directive introducing cybersecurity obligations. The directive includes obligations regarding the notification and mitigation of data breaches, data storage and user id…

Event typeorder
Action typeadoption
Government branchexecutive
Government bodycentral government