Country guide

Rail cyber security regulations in India

India's rail cyber security work needs to account for national incident-reporting directions as well as railway-specific operational and administrative requirements. CERT-In's directions apply across defined categories of organisations, rather than only to rail. A project should establish who operates each system, who holds its logs and who is responsible for reporting a qualifying incident.

Official sources checked

Who needs to consider these requirements?

An Indian railway deployment may involve government systems, a corporate supplier and remote support services. Assess the responsibilities of each entity rather than expecting the operator's incident process to cover every supplier automatically. The technical design should support evidence collection and rapid escalation across the train, depot and supporting service environments.

Key regulations and frameworks

CERT-In directions under section 70B

Binding directions — assess entity and incident scope

CERT-In's April 2022 directions cover service providers, intermediaries, data centres, bodies corporate and government organisations. They require reporting specified cyber incidents within six hours of noticing them or being informed of them, and secure retention of ICT-system logs for a rolling 180 days within Indian jurisdiction. Read the directions and accompanying FAQs together to determine the relevant incident categories and implementation details.

Official source: CERT-In directions under section 70B

Reporting with incomplete initial information

Official CERT-In clarification

CERT-In's FAQ explains that an entity can report the information available initially and provide additional information later within a reasonable time. For a railway incident, the operational lesson is to establish a rapid escalation path without waiting for a complete forensic investigation. The FAQ also provides context for the types of incident that meet the reporting criteria.

Official source: Reporting with incomplete initial information

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Assign reporting responsibility and an out-of-hours contact for each participating organisation. Test whether a supplier's escalation time leaves enough time for the relevant entity to report.
  2. Check where train, depot and remote-access logs are stored, whether their clocks align and whether they can be retrieved during an outage. Resolve retention and location requirements before handover.
  3. Agree with the railway which additional project security instructions apply. Rehearse a short initial incident report followed by evidence updates, while keeping operational recovery under the operator's control.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.