India's Cyber Security Framework: CERT-In, NCIIPC, and the Data Protection Regime
July 19, 20266 min read
The question reads: "Which of the following is NOT a function of CERT-In under the IT Act 2000?"
Most aspirants know CERT-In is the national cyber security agency. Fewer know its specific functions (Section 70B), the distinction between CERT-In and NCIIPC (one deals with general cyber incidents, the other with critical information infrastructure), or how the DPDP Act's breach notification obligation overlaps with CERT-In's mandatory reporting rules. The syllabus spans Internal Security, Science & Tech, and Polity.
Primary trap. Candidates confuse CERT-In with NCIIPC. CERT-In (Indian Computer Emergency Response Team) is the national nodal agency for cyber incident response (Section 70B, IT Act 2000). NCIIPC (National Critical Information Infrastructure Protection Centre) is the nodal agency for protecting "critical information infrastructure" (CII) — designated by the government under Section 70A. Both report to MeitY. CERT-In handles general cyber security; NCIIPC handles CII (power grids, banking, telecom, defence networks, transport systems). A question saying "CERT-In is responsible for protecting critical information infrastructure" is false — that is NCIIPC's mandate.
Most confused. The difference between "voluntary" and "mandatory" cyber incident reporting. CERT-In's 2022 Directions made 10 categories of cyber incidents mandatorily reportable within 6 hours of detection — including data breaches, ransomware attacks, denial of service attacks, and attacks on ICT systems. Previously, reporting was voluntary. The DPDP Act 2023 separately requires data fiduciaries to report data breaches to the Data Protection Board of India (proposed 72-hour timeline). Both obligations exist simultaneously — an organisation suffering a data breach must report to both CERT-In (within 6 hours) and the DPBI (within 72 hours, once the Board is established).
Key anchor. India's cyber security framework is built on three pillars: (a) Proactive — NCIIPC's vulnerability assessment and CII protection strategies; (b) Reactive — CERT-In's incident response, forensic analysis, and coordination; (c) Regulatory — IT Act 2000 (substantive law), IT Rules 2021 (intermediary guidelines), DPDP Act 2023 (data protection), and the proposed Digital India Act (expected to replace IT Act). The frameworks are complementary but overlapping — a single cyber incident can trigger obligations under all three.
Current affairs hook. The Digital India Act (Bill introduced 2026, Standing Committee review ongoing) will replace the IT Act 2000 as India's primary cyber law. It introduces: cybersecurity obligations for platforms beyond intermediary liability, a statutory Data Protection Board (merging DPBI with an appellate tribunal), and new categories of cyber offences (deepfake creation, algorithmic discrimination, non-consensual AI-generated content). The DIA is the single biggest reform in Indian cyber law since 2000.
Mains hinge. The tension between security and privacy. CERT-In's 2022 Directions mandated 6-hour breach reporting and expanded traceability requirements. The same Directions required VPN providers, cloud service providers, and data centres to store customer names, IP addresses, and usage logs for 5 years. The rules were challenged in the Supreme Court as violative of the Puttaswamy privacy framework. The Court is yet to decide. The question: is mandatory incident reporting proportionate, or does it create a surveillance infrastructure that infringes Article 21?
Core Concept
India's cyber security architecture operates at three tiers:
Tier 1 — CERT-In (Indian Computer Emergency Response Team): Established 2004 under IT Act Section 70B. Functions: (a) collection, analysis, and dissemination of information on cyber incidents; (b) forecast and warning on cyber security threats; (c) emergency measures for incident response; (d) coordination of incident response activities; (e) issue guidelines and advisories; (f) training and capacity building. CERT-In operates as the national nodal agency under MeitY. The 2022 Directions made cyber incident reporting mandatory for all service providers, intermediaries, data centres, and government bodies.
Tier 2 — NCIIPC (National Critical Information Infrastructure Protection Centre): Established 2014 under Section 70A of IT Act. Mandate: protection of "critical information infrastructure" — defined as computer resources whose incapacitation would impact national security, economic security, public health, or safety. CII sectors designated so far: power (grid, generation), banking (core banking, payment systems), telecom (core networks), defence (military networks), space (satellite control), transportation (air traffic, railways), health (critical hospital networks), and government (Aadhaar, GSTN, income tax systems). NCIIPC conducts vulnerability assessment, develops protection strategies, and coordinates with sectoral CERTs (sector-specific incident response teams).
Tier 3 — Regulatory and Legal Framework:
Law/Regulation
Scope
Key provisions for UPSC
IT Act 2000
Substantive cyber law — offences, penalties, intermediary liability
CERT-In vs NCIIPC: CERT-In = all cyber incidents (general); NCIIPC = CII only (targeted)
IT Act vs DPDP Act: IT Act = cyber crimes and intermediary liability; DPDP Act = personal data protection
Section 69A (IT Act) vs Section 17 (DPDP Act): Both give government exemption from legal obligations for national security — but under different statutes with different procedural safeguards
CERT-In Directions 2022 vs DPDP breach reporting: Both require breach notification but to different authorities (CERT-In within 6 hours, DPBI within proposed 72 hours) and for different types of incidents (CERT-In for any cyber incident, DPDP Act for personal data breach)
Key Facts
CERT-In established: 2004 (statutory status under IT Act 2004 amendment)
NCIIPC established: 2014 (Section 70A of IT Act)
Cyber incidents reported to CERT-In (2024): 15.5 lakh — 400% increase from 2022
CERT-In Directions 2022: 6-hour mandatory breach reporting for 10 categories of incidents
IT Act 2020 amendment: Increased penalties, introduced data breach provisions, expanded CERT-In powers
DPDP Act: Up to ₹250 crore penalty per violation; 7-year transition period
National Cyber Security Strategy 2025: Released by National Security Council Secretariat — 5 pillars (infrastructure, human capital, legal framework, international cooperation, indigenous technology)
Cyber Swachhta Kendra: CERT-In's botnet cleaning and malware analysis centre (2017)
Indian Cyber Crime Coordination Centre (I4C): MHA's multi-agency centre for cyber crime investigation (2020)
Global ranking: India ranks 5th in number of cyber attacks globally (after US, China, UK, Russia) — but ranks low in cyber security preparedness (Global Cybersecurity Index 2024: India at 14th, behind South Korea, Japan, Saudi Arabia)
Previous Year Questions
Year
Stage
What was tested
2025
Prelims
CERT-In — functions under Section 70B of IT Act
2025
Mains GS-3
"India's cyber security framework needs a unified regulator." Critically examine.
2024
Prelims
NCIIPC — meaning of Critical Information Infrastructure
2024
Mains GS-3
"The CERT-In Directions 2022 have created tension between cyber security and privacy." Discuss.
2023
Prelims
Section 69A — power to block content; Section 79 — safe harbour
2023
Mains GS-3
"Cyber attacks on critical information infrastructure pose a threat to national security." Discuss India's protection mechanisms.
2022
Prelims
Difference between CERT-In and NCIIPC
2022
Mains GS-3
"The increasing frequency of cyber attacks requires a comprehensive legal framework." Examine India's preparedness.
2021
Prelims
IT Act provisions — cyber terrorism (Section 66F)
Statement Elimination Guide
"CERT-In is the nodal agency for protecting Critical Information Infrastructure in India." False. NCIIPC is the nodal agency for CII protection. CERT-In is the national nodal agency for general cyber incident response. The two are complementary but have distinct mandates.
"Cyber incident reporting to CERT-In was made mandatory for the first time in 2020." False. Mandatory reporting was introduced through CERT-In Directions of 2022, not 2020. The Directions require reporting of 10 categories of incidents within 6 hours of detection, including ransomware, data breaches, denial of service, and attacks on ICT systems.
"The DPDP Act 2023 and the IT Act 2000 operate in parallel with overlapping data breach reporting obligations." Correct. The DPDP Act mandates breach notification to the Data Protection Board of India (proposed timeline: 72 hours). The IT Act (through CERT-In Directions) mandates breach notification to CERT-In (6 hours for designated incidents). An organisation can face both obligations simultaneously for the same incident.
"The NCIIPC has authority to issue blocking orders for any content that threatens cyber security." False. NCIIPC's authority under Section 70A is limited to CII protection strategies and vulnerability assessment. Content blocking is done under Section 69A of the IT Act by the Ministry of Electronics and IT, following a specific procedure with a review committee.
"India's National Cyber Security Strategy 2025 includes a pillar on international cooperation." Correct. The NSCS 2025 released by the National Security Council Secretariat has 5 pillars: infrastructure, human capital, legal framework, international cooperation (partnerships with US, Japan, UK, Israel, Quad nations), and indigenous technology (secure hardware, Indian cryptography standards).
Current Affairs Hook
The Digital India Act (DIA), introduced in Parliament in early 2026 and currently before the Standing Committee on Communications and IT, proposes the most significant reform of India's cyber law architecture since 2000. Key proposals: (a) DIA will replace the IT Act 2000 as the primary legislation — the IT Act will be repealed; (b) A unified regulatory framework merging the Data Protection Board of India (DPDP Act) and an appellate tribunal into a single Digital Protection Authority; (c) New cyber offence categories — deepfakes, algorithmic discrimination, non-consensual synthetic intimate images, AI-generated disinformation; (d) Platform accountability — safety-by-design obligations, mandatory transparency reports, and tiered obligations based on user base.
The 2025 National Cyber Security Strategy (NSCS) identified quantum computing as a "medium-term existential threat" to current encryption standards — India's cryptographic infrastructure (UPAI, Aadhaar, banking networks) needs post-quantum cryptography transition planning. NSCS also flagged State-sponsored cyber attacks (especially from China-linked APTs — Advanced Persistent Threats) as the top risk category.
The 2026 Budget allocated ₹6,982 crore to MeitY's cyber security programmes — a 30% increase over 2025-26 — with new allocations for a National Cyber Security Operations Centre (NC-SOC) and a Cyber Security R&D Fund for quantum-safe cryptography and AI-powered threat detection.
Interlinkages
Science & Tech (GS-3): Quantum computing threatens existing encryption standards — RSA, ECC, and AES are vulnerable to Shor's and Grover's algorithms. India's National Quantum Mission includes a post-quantum cryptography research track. CERT-In's 2025 advisory warned of "harvest now, decrypt later" attacks by State actors collecting encrypted data for future decryption.
Polity (GS-2): The Supreme Court's pending challenge to CERT-In Directions 2022 tests the proportionality framework from K.S. Puttaswamy (2017). The right to privacy under Article 21 and the state's power to mandate surveillance/data retention for national security must be balanced. The outcome will define the limits of cyber security regulation.
Defence (GS-3): India established the Defence Cyber Agency (DCyA) in 2019 under the Integrated Defence Staff to protect military networks and conduct offensive cyber operations. The DCyA coordinates with CERT-In and NCIIPC for CII protection in defence sector. The tri-service Defence Cyber Command (announced 2024) is under establishment.
International Relations (GS-2): India is a signatory to the Budapest Convention on Cybercrime (acceded 2022) — the first non-European country to join. India participates in the Quad Cyber Security Partnership, ASEAN-India cyber dialogue, and the UN Open-Ended Working Group on ICT security. Bilateral cyber dialogues with US (iCET framework), Japan, UK, and Israel are active.
Economy (GS-3): India's digital economy is projected at $1T by 2027. Cyber security spending is ₹60,000+ crore annually across government and private sectors. The government estimates a shortage of 2.5 lakh cyber security professionals in India — creating both vulnerability and a skilling opportunity under the Skill India mission.
Common Mistakes
"CERT-In and NCIIPC are the same entity." They are different. CERT-In (Section 70B) handles general cyber incident response. NCIIPC (Section 70A) handles protection of critical information infrastructure specifically. Both under MeitY but with separate mandates.
"The IT Act 2000 is India's only cyber law." No. The IT Act is the primary substantive cyber law, but it operates alongside the DPDP Act 2023 (data protection), IT Rules 2021 (intermediary guidelines), BNS 2023 (criminal provisions for cyber offences), sector-specific regulations (RBI, TRAI, SEBI), and the proposed DIA.
"All cyber incidents are reported to the police under the IT Act." No. Most cyber incidents are reported to CERT-In (the technical agency). Law enforcement agencies (police, CBI, I4C) handle investigation and prosecution. CERT-In coordinates technical response but does not investigate crimes. NCIIPC coordinates CII protection but does not prosecute.
"The DPDP Act's breach notification requirement has replaced CERT-In's mandatory reporting." False. Both obligations coexist. The DPDP Act requires breach reporting to the DPBI (proposed 72-hour timeline). CERT-In Directions require reporting of the same breach within 6 hours. Different timelines, different authorities, different legal bases.
"India's cyber security framework is fully mature and operational." False. Key gaps remain: no operational Data Protection Board of India (rules pending since 2023), no dedicated cyber security regulator (NSCS 2025 proposed one but not established), shortage of forensic capacity (CERT-In handles ~42,000 incidents per year but has only 12 forensic labs), and the proposed DIA is still under parliamentary scrutiny.
Revision Snapshot
India's cyber security framework has three tiers: CERT-In (Section 70B, IT Act — nodal agency for all cyber incidents, mandatory 6-hour reporting for 10 categories under 2022 Directions), NCIIPC (Section 70A — protection of 8 designated CII sectors), and the legal-regulatory framework (IT Act 2000, DPDP Act 2023, IT Rules 2021, proposed DIA). Key distinctions: CERT-In vs NCIIPC (general vs CII), IT Act vs DPDP Act (cyber crimes vs data protection), CERT-In Directions (6-hour reporting) vs DPDP breach notification (72-hour, to DPBI). The Digital India Act (2026) will replace the IT Act — introducing deepfake regulation, unified regulator, and platform safety obligations. The National Cyber Security Strategy 2025 (5 pillars) guides policy. The pending Supreme Court challenge to the CERT-In Directions tests privacy vs security under Article 21. India faces 15.5 lakh cyber incidents annually, has a workforce shortage of 2.5 lakh professionals, and spends ₹60,000+ crore on cyber security.
Source Notes
IT Act 2000 (as amended 2008): Sections 70A, 70B — NCIIPC and CERT-In
CERT-In Directions 2022 (No. 20(3)/2022-CERT-In): Mandatory incident reporting — full text
MeitY: Annual Cyber Incident Report 2024-25
National Security Council Secretariat: National Cyber Security Strategy 2025
Digital India Act 2026 (Bill introduced, Standing Committee review pending): Key provisions
PRS India: Legislative Analysis — Digital India Act 2026
K.S. Puttaswamy vs Union of India (2017) 10 SCC 1 — Right to Privacy judgment
Global Cybersecurity Index 2024 (ITU): India ranking and assessment
Indian Cyber Crime Coordination Centre (I4C): MHA — Achievements and Challenges (2025)
Budapest Convention on Cybercrime: India's accession and implications (2022)
Economic Survey 2025-26: Chapter on Digital Economy and Cyber Security