Quick Answer: Indian businesses operate under four layers of cybersecurity regulation at once: the IT Act 2000, CERT-In’s mandatory 6-hour incident reporting rule (already fully enforceable, penalty up to ₹1 crore), the DPDP Act 2023 (only partially in force – full compliance isn’t required until May 13, 2027), and sector-specific rules from RBI, IRDAI, or SEBI for regulated industries. The rule most businesses get wrong first: assuming DPDP is fully binding today, when CERT-In’s 6-hour window is the one already carrying real penalties.

India’s cybersecurity regulation isn’t one law. It’s a stack: a foundational IT Act, a mandatory incident-reporting regime from CERT-In, a data protection law that’s only partially in force, and a set of sector-specific rules for banks, insurers, and market intermediaries. Most businesses only discover which rules apply to them after an incident forces the question. This is a working map of what’s actually in force today, what’s coming, and what non-compliance costs.

The IT Act 2000: the foundation everything else sits on

The Information Technology Act, 2000 is India’s core cyber law. It criminalizes computer-related offenses, gives legal recognition to digital signatures and electronic records, and sets out intermediary liability rules that shape how platforms, hosting providers, and IT vendors handle user data.

Two provisions matter most for businesses:

  • Section 70A established the National Critical Information Infrastructure Protection Centre (NCIIPC) in 2014, the nodal agency for protecting infrastructure the government designates as critical.
  • Section 70B is the legal basis for CERT-In’s directive powers, including the incident-reporting rules below.

The Jan Vishwas (Amendment of Provisions) Act, 2023 raised several IT Act penalties, effective November 30, 2023 – including the CERT-In non-compliance fine, up from ₹1 lakh to ₹1 crore.

CERT-In’s 6-hour reporting rule

The single most operationally disruptive rule in Indian cybersecurity law is CERT-In’s Cyber Security Directions, issued April 28, 2022 and effective June 27, 2022 (with a short grace period for MSMEs).

The core mandate: report specified categories of cyber incidents to CERT-In within 6 hours of noticing them or being notified of them. The clock starts on awareness, not on completing an investigation – a meaningful difference from breach-notification laws elsewhere that give 72 hours.

Who this applies to: service providers, intermediaries, data centers, body corporates, and government organizations – in practice, most mid-size and large Indian businesses running any online-facing infrastructure.

What counts as reportable spans data breaches, ransomware, DDoS attacks, unauthorized access, website defacement, and cloud intrusions, among other categories CERT-In enumerates in its directions.

Non-compliance penalty: up to ₹1 crore and up to 1 year imprisonment under Section 70B, following the 2023 increase.

For most businesses, the practical requirement is an incident response process that can detect, triage, and file a CERT-In report inside 6 hours – which usually means the process has to exist before an incident, not get built during one.

DPDP Act 2023: in force, but not fully

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection law – but it’s being phased in, and businesses often assume it’s fully binding when it isn’t yet.

Where things actually stand in 2026

  • The DPDP Rules, 2025 were notified in November 2025, bringing certain provisions into immediate effect – mainly the Act’s definitions and the establishment of the Data Protection Board of India.
  • Consent manager registration obligations take effect in November 2026.
  • Full substantive compliance – data fiduciary obligations, notice and consent protocols, data principal rights, security safeguards, cross-border transfer rules – isn’t required until May 13, 2027.

That gap matters for planning. A business that waits until 2027 to start building consent flows and breach-notification processes will be building them under deadline pressure. The provisions that are already active (Board authority, definitions) also mean early enforcement infrastructure exists even before the substantive obligations bind.

Breach notification, once fully in force: an initial intimation to the Data Protection Board “without delay,” followed by a detailed report within 72 hours (or longer if the Board permits an extension). Affected individuals (data principals) must also be notified without delay.

Penalties (Schedule to the Act, Section 33) run into the hundreds of crores for the most serious failures – among the highest data-protection penalty ceilings in the world:

ViolationMaximum penalty
Failure to implement reasonable security safeguards₹250 crore
Failure to notify the Board or affected individuals of a breach₹200 crore
Violations involving children’s personal data₹200 crore
Significant Data Fiduciary failing mandatory audit obligations₹150 crore
Data Principal misusing rights or filing false complaints₹10,000

Sector-specific rules: RBI, IRDAI, SEBI

If a business operates in banking, insurance, or capital markets, general IT Act and DPDP obligations sit underneath a second, stricter layer of sector regulation.

RegulatorFrameworkApplies to
RBIMaster Direction on Information Technology Governance, Risk, Controls and Assurance Practices (Nov 2023)Scheduled commercial banks, small finance banks, payments banks, NBFCs, credit information companies
RBIIT Framework for the NBFC Sector (2017)NBFCs, with compliance depth scaled to asset size
IRDAIInformation and Cyber Security Guidelines, 2023Insurers – requires CERT-In notification within 6 hours and full incident detail to IRDAI within 24 hours
SEBICybersecurity and Cyber Resilience Framework (CSCRF), August 2024Stock exchanges, clearing corporations, depositories, portfolio managers, investment advisers, KYC registration agencies – a five-tier model spanning 19 entity categories

The pattern across all three: faster reporting windows than CERT-In’s baseline, more detailed audit and governance requirements, and direct regulator oversight on top of the general cyber-law stack.

NCIIPC and critical infrastructure

The National Critical Information Infrastructure Protection Centre, established under Section 70A of the IT Act, is the nodal agency for protecting computer resources the government designates as critical – infrastructure where disruption would have a debilitating impact on national security, economy, or public health and safety. Sectors typically discussed in this context include power, banking and financial services, telecom, transport, and government systems.

Most mid-size businesses won’t fall under NCIIPC’s direct jurisdiction. Vendors and IT partners serving organizations in these sectors should expect their clients to pass down NCIIPC-influenced security requirements contractually, even without being directly regulated themselves.

What this actually means for a mid-size Indian business

  1. Build the 6-hour CERT-In reporting capability now. This is already fully in force and carries real penalties. It’s also the rule most businesses underestimate operationally.
  2. Don’t wait until 2027 for DPDP readiness. The compliance deadline is phased, but consent flows, data mapping, and breach-response processes take longer to build than most timelines assume.
  3. Check for sector overlap. A fintech, insurtech, or company serving BFSI clients is very likely under RBI, IRDAI, or SEBI rules in addition to the general stack – and those carry tighter deadlines.
  4. Treat vendor and IT-partner selection as a compliance decision. Whoever manages your infrastructure inherits your reporting obligations in practice, even if not in law.

Frequently Asked Questions

Is the DPDP Act 2023 fully in force right now?

No. The DPDP Rules were notified in November 2025, which activated the Act’s definitions and established the Data Protection Board. Consent manager registration follows in November 2026. Full substantive obligations for businesses – consent, breach notification, data principal rights – don’t take effect until May 13, 2027.

What has to be reported to CERT-In, and how fast?

Specified categories of cyber incidents – including data breaches, ransomware, DDoS attacks, unauthorized access, and website defacement – must be reported within 6 hours of the incident being noticed or reported to the organization, under CERT-In’s April 2022 Cyber Security Directions.

What’s the penalty for missing the CERT-In 6-hour deadline?

Up to ₹1 crore and up to 1 year imprisonment under Section 70B of the IT Act, following the penalty increase from the Jan Vishwas Act, 2023 (effective November 30, 2023). The original penalty was ₹1 lakh.

Do DPDP Act penalties apply per incident or as a flat cap?

The Schedule to the Act sets maximum penalties per category of violation – up to ₹250 crore for failing to implement reasonable security safeguards, up to ₹200 crore for breach notification failures or violations involving children’s data, and up to ₹150 crore for a Significant Data Fiduciary failing audit obligations.

My business isn’t a bank or insurer – do RBI or IRDAI rules still apply?

Only if directly regulated by those bodies. But if a business serves BFSI clients as a vendor or technology partner, those clients typically pass down equivalent security and reporting requirements contractually, even without direct regulatory jurisdiction.

What is NCIIPC, and does it apply to most businesses?

NCIIPC is the national agency protecting critical information infrastructure – sectors like power, banking, telecom, and government systems – under Section 70A of the IT Act. Most mid-size businesses aren’t directly regulated by NCIIPC, but IT vendors serving critical-sector clients should expect NCIIPC-influenced requirements passed down contractually.

What’s the single most urgent compliance gap most Indian businesses have today?

An incident response process fast enough to meet CERT-In’s 6-hour reporting window. It’s already fully enforceable, unlike DPDP’s phased-in obligations, and most breach-response plans are built around 24-72 hour timelines borrowed from other jurisdictions’ laws.

WinInfoSoft is ISO 27001 and CMMI Level 3 certified, and works with businesses across BFSI, manufacturing, and technology on compliance-aligned IT infrastructure and security. Reach out to talk through where your current setup stands against these requirements.