Govt may extend deadline for Cert-In cyber rules by 3 months to help MSMEs

According to Cert-In's guidelines, all enterprises, intermediaries, data centres and govt organisation are required to report any data breach to the government within six hours of becoming aware of it

Credit card, security, cyber security
Photo: Shutterstock
BS Web Team New Delhi
2 min read Last Updated : Oct 12 2022 | 2:56 PM IST
The government of India is likely to extend the deadline for complying the Indian Computer Emergency Response Team (Cert-In) for the micro, small, and medium enterprises (MSMEs) as well as small and medium enterprises (SMEs) by three months, reported The Economic Times.

Minister of State for Electronics and IT Rajeev Chandrasekhar said to ET, “We are very clear. We will not make SMEs or MSMEs bear the burden of this additional compliance until they are ready.”

According to Cert-In’s guidelines dated April 28, all enterprises, intermediaries, data centres and government organisation are required to report any data breach to the government within six hours of becoming aware of it. 

Cert-In, in its guidelines, has also made it compulsory for the Virtual Private Network (VPN) service providers to maintain and hand it over to the government all the information they had collected as part of the KYC (know-your-customer) rules, as and when required. This directive has led to the exit of several VPN providers from India.

Earlier this year, the Minister of State for Electronics and IT said in a press conference that VPN service providers who are not willing to comply with the guidelines were free to leave. 

The ministry is, however, more flexible to the needs of the SMEs and has extended the compliance deadline for the second time.

According to sources in the IT ministry, while larger companies and VPN providers have complied with the directive, some SMEs and MSMEs are facing problems. A senior government official said that the ministry has been informed several times about the lack of cost-effective human resource in the country along with other requirements such maintaining data for three years which is also adding to their operational cost.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Cyber security lawcyber crimes IndiaIT ministryMSMEsSMEseconomy

Next Story