6 hrs
Mandatory reporting window from detection
44
Incident types in CSITe portal drop-down
3
Most common portal submission rejection reasons
₹1Cr
Daily penalty for non-compliance with CERT-In directions

What Is CSITe and Why It Matters

CSITe — Cyber Swachhta Integrated Threat Exchange — is CERT-In's mandatory incident reporting portal. Under the April 2022 Directions (amended 2023), issued under Section 70B of the Information Technology Act 2000, every service provider, intermediary, data centre, government body, and body corporate operating in India must report cybersecurity incidents to CERT-In within 6 hours of detection.

CSITe is the only accepted channel for this reporting obligation. Email to CERT-In is not sufficient. Phone calls are not sufficient. Reporting to your sector regulator (RBI, SEBI, IRDAI) does not satisfy the CERT-In obligation. The portal at https://csite.cert-in.org.in is the exclusive filing mechanism — and you must be registered before an incident occurs.

🚨
Why this matters for BFSI: Non-compliance with CERT-In Directions carries a penalty of up to ₹1 crore per day under Section 70B(7) of the IT Act. For RBI-regulated entities, CERT-In non-compliance is also a trigger for supervisory action under the RBI Cybersecurity Framework. The combination of IT Act penalty plus regulatory enforcement makes CSITe compliance a board-level risk.