ARM Innovations Logo
ARM Innovations
Regulatory Update 2025

New CERT-In Guidelines 2025: What Has Changed?

The cybersecurity landscape in India has witnessed its most significant evolution with the rollout of the CERT-In Guidelines 2025. Moving beyond historical 'checkbox compliance,' the new framework mandates deep resilience.

The 2025 updates introduce strict auditing rules for private organizations, setting a high standard for corporate compliance. Every company operating in India's digital space must now catalog and verify their security controls on a recurring schedule.

Crucially, the guidelines expand the types of incidents that must be reported to the national agency within the strict 6-hour timeline. Failure to report carries severe penalties, making proactive preparedness a top priority for corporate boards.

CERT-In guidelines 2025 overview graphic showing key compliance components

Key Pillars of Assessment

  • Annual Auditing

    Mandatory annual cybersecurity assessment by a CERT-In empanelled auditing firm.

  • Log Archival

    Maintaining local logs securely within India's jurisdiction for a minimum of 180 days.

  • 6-Hour Reporting

    Compulsory notification of listed cyber incidents to CERT-In within 6 hours of discovery.

  • Third-Party Audits

    Mandatory evaluation of all external dependencies, APIs, and supply chain vendors.

Inclusion of Emerging Tech (AI, IoT, ICS)

The 2025 audit scope has been dramatically expanded. Auditors must now evaluate AI models for prompt injection risks, secure the hardware-software bridges in IoT ecosystems, and assess operational technology networks in industrial settings.

Security logs must be preserved using secure, tamper-proof architectures. This ensures audit trails are clean, complete, and readily available in the event of a national security review or forensic incident investigation.

  • Model safety checks for machine learning deployment.
  • Secure boot validation and firmware updates for IoT systems.
  • Network segregation between business IT and industrial OT systems.
Data center visualizing immutable and encrypted log retention architecture

Proactive Audit Readiness

Wait-and-watch is no longer a viable strategy. India's digital ecosystem requires a rigorous defense posture. Partnering with certified security compliance experts ensures that your organization is not just audit-ready, but structurally secure.

Need Help Navigating?

Check out our dedicated CERT-In Security Audit services.

Explore Audit Services

Related Resources

Continue your research with these relevant guides and services.

+91 99104 22411WhatsApp