Confirm scope
Confirm this incident falls under a CERT-In reportable category (e.g. data breach, ransomware, unauthorised access, DDoS) before drafting your report.
Notify internally
Alert your CISO/incident owner and compliance contact now — don't wait until the report is fully drafted.
Preserve evidence
Capture logs and system state before remediation steps potentially overwrite evidence.
File the report
Submit to CERT-In via incident@cert-in.org.in or the CERT-In portal, including the details specified in the Directions.