Cybercrime Response Playbook: NCRP, FIR and BSA Section 63 Evidence

Compliance Playbook Cybersecurity 28 Jul 2026 Status: in-force
Statutory deadline
CERT-In report within 6 hours of noticing (Section 70B(6), IT Act 2000); intermediary preservation minimum 180 days on lawful request (Rule 3(1)(j), IT Rules 2021); Section 63(4) BSA certificate must accompany the electronic record at each instance of tendering for admission
TL;DR

After an Indian cyber incident, the CERT-In six-hour report is only the regulatory leg. The prosecution leg runs on three intake routes — the National Cyber Crime Reporting Portal at cybercrime.gov.in, the 1930 financial-fraud helpline, and a direct FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 — and on a Section 63(4) certificate under the Bharatiya Sakshya Adhiniyam, 2023 for every log, export or screenshot tendered as secondary electronic evidence. Intermediaries must preserve requested data for at least 180 days under Rule 3(1)(j) of the IT Rules, 2021. Since 1 July 2024 all three criminal codes are the 2023 Sanhitas.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
8 min read
Continue with Veritect

Ship Cybersecurity compliance with a board-ready playbook.

Try Veritect free Book a demo

TL;DR for founders

Your CERT-In report is due in 6 hours. Your case is won or lost in the first 72. The regulatory report under Section 70B(6) of the Information Technology Act, 2000 does not register an FIR, does not freeze the fraudster's bank account and does not preserve a single log for trial. Three separate things do: the 1930 helpline (beneficiary-account hold in 24-72 hours), an FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023, and a Section 63(4) certificate under the Bharatiya Sakshya Adhiniyam, 2023 signed by the right custodian for every log you intend to rely on. Get the third one wrong and everything else was wasted effort.

Indian cybercrime response runs on two tracks that most incident-response plans collapse into one. This playbook covers the prosecution track — victim intake, FIR, preservation, and courtroom admissibility. It deliberately starts where Veritect's CERT-In six-hour incident-reporting SOP ends, and assumes offences dated on or after 1 July 2024, when the Bharatiya Nyaya Sanhita, 2023 ('BNS'), Bharatiya Nagarik Suraksha Sanhita, 2023 ('BNSS') and Bharatiya Sakshya Adhiniyam, 2023 ('BSA') replaced the Indian Penal Code 1860, the Code of Criminal Procedure 1973 and the Indian Evidence Act 1872.

Step 1 — Triage the intake route in the first hour

India gives a victim three concurrent routes, and the choice is a speed decision, not a legal one.

Route Use when Realistic clock
1930 helpline (Citizen Financial Cyber Fraud Reporting and Management System) Live financial loss with a traceable beneficiary account Bank hold / lien request in 24-72 hours
NCRPcybercrime.gov.in Impersonation, harassment, defamation, low-value cheating State cyber-cell contact typically within 7-14 days
Direct FIR at a cyber police station Ransomware on critical systems, cyber-terrorism (Section 66F, IT Act 2000), CSAM, large-scale breach Same day, if you insist correctly

NCRP has two intake tracks — "Report Women/Child Related Crime", which permits anonymous filing, and "Report Other Cybercrime". Registration needs name, email and mobile OTP; uploads are capped at 5 MB per file with multiple uploads allowed. The complaint auto-routes to the jurisdictional state cyber cell by the complainant's pincode and generates an Acknowledgement Number. Keep that number — it is the reference for every escalation.

Step 2 — Get an FIR, not a Non-Cognizable Report

Under Section 173 BNSS, information about a cognizable offence must be reduced to writing. Refusal is itself actionable: escalate to the Superintendent of Police under Section 175(3) BNSS, then to the Magistrate. The FIR copy is free under Section 173(2) BNSS.

Two practical points decide this step. First, insist on an FIR rather than a Non-Cognizable Report wherever Sections 66, 66C, 66D or 66F of the IT Act 2000, or BNS Sections 318 (cheating), 319 (cheating by personation), 336 (forgery, expressly covering false electronic records) or 351 (criminal intimidation) are attracted. Second, Section 202 BNSS gives jurisdiction to any court within whose limits the electronic communication was sent or received — so a victim can usually file at home rather than at the fraudster's location. Where the offence carries seven years or more, Section 176(3) BNSS makes forensic examination mandatory, which is a lever worth citing at the counter.

Step 3 — Preserve before you investigate

The integrity of every downstream exhibit is set here, before any analyst touches anything.

  • Do not power on a seized device. Booting alters access timestamps and swap files, and hands the defence a ready-made integrity argument.
  • Image bit-for-bit through a write-blocker, and record the blocker's serial number in the seizure memo.
  • Hash with SHA-256 as primary. MD5 is a secondary cross-check only; SHA-1 is deprecated. Hash both source and image, and re-compute at every custody transfer.
  • For live systems that cannot be imaged — production databases, cloud workloads — perform live acquisition with contemporaneous hashing, and document why imaging was impossible.

The Bureau of Police Research and Development SOP for Collection of Electronic Evidence is the reference standard; it requires both the source and the export to be hashed and the hashes recorded in the seizure memo. Note also that Section 105 BNSS requires the search and seizure and the list of items to be recorded by audio-video means — usually a mobile phone — and forwarded to the Magistrate without delay. Its absence is a live cross-examination point.

💡 Not sure which of the three clocks your incident has already started? The Veritect Legal AI platform holds the CERT-In Directions of 28 April 2022, the IT Rules 2021 preservation provisions and the BNSS 2023 investigation chapter side by side, so you can see which obligation is running and who owes what to whom. Explore Veritect Legal AI →

Step 4 — The Section 63 BSA certificate: the step that decides the case

Section 61 BSA saves electronic records from being rejected merely because they are electronic. Section 63 BSA then governs admissibility, carrying forward the architecture of the repealed Section 65B of the Evidence Act 1872 with substantive parity — which is why Anvar and Arjun Panditrao still govern.

The certificate under Section 63(4) BSA must accompany the electronic record at each instance where it is submitted for admission — the statute's own words. It must identify the record and describe how it was produced, give the particulars of the device involved, and be signed by a person in charge of the device or the management of the relevant activities, together with an expert.

Four drafting rules follow:

  1. Signature by the right person. The custodian of the system that produced the record — not the investigating officer, unless the IO also administers that log.
  2. Include the SHA-256 hash even though Section 63 does not expressly demand it. It is the audit signature courts treat as the integrity gold standard.
  3. State proper operation of the computer through the relevant period, or that any malfunction did not affect accuracy.
  4. File it with the record, not at the appellate stage. Arjun Panditrao Khotkar (2020) 7 SCC 1 expressly overruled Shafhi Mohammad (2018) 2 SCC 801 and left only a narrow window — a reasoned application showing genuine prior efforts — for a belated certificate.

Step 5 — Preservation and production from third parties

Two instruments do this work. Section 94 BNSS (successor to Section 91 CrPC) is the summons to produce a document or thing, addressed to intermediaries, banks and telcos. Rule 3(1)(j) of the IT Rules, 2021 obliges an intermediary receiving an order from a lawfully authorised agency to preserve the information for at least 180 days, or longer if specified.

Route the request to the intermediary's published Grievance / Nodal Officer under Rules 3(2) and 4 of the IT Rules 2021 — copying the Sahyog portal (sahyog.i4c.gov.in), which since the Rule 3(1)(d) amendment of 15 November 2025 is the administrative anchor for takedown and coordination. Sending the notice to a marketing or registered-office address buys the accused a procedural-compliance argument. Identify the target with specificity: handle, phone number, IP address with timestamp and time zone, transaction ID. Insist on a separate Section 63(4) BSA certificate from the intermediary's custodian on the date of production — a certificate you sign for their log is worthless.

Step 6 — Cross-border evidence

Send the 18 U.S.C. § 2703(f) preservation request to the overseas provider immediately — 90 days, extensible by 90 — and only then file the MLAT request through MHA's Internal Security-II Division, with the Department of Legal Affairs as Central Authority. India has roughly 45 active MLATs; content data typically returns in 6 to 18 months. India is not a party to the Budapest Convention on Cybercrime; the UN Convention against Cybercrime, adopted by UNGA Resolution A/RES/79/243 of 24 December 2024, will eventually change the routing but has not yet done so.

Step 7 — Chain of custody

No statute codifies chain of custody; courts read it into Sections 63 and 64 BSA. Every transfer — seizure to lab, lab to IO, IO to prosecutor, prosecutor to court — needs a dated, signed entry naming transferor and transferee, the purpose, the exhibit identifier, the recomputed hash and the tamper-seal number. Keep the register for a minimum of 10 years; appellate courts routinely recall it. If a copy is made for analysis, hash the copy at the moment of copying.

Step 8 — Court production

At tendering, the custodian witness proves the Section 63(4) certificate and identifies the device; the forensic examiner proves hash identity between source and image. Section 530 BNSS permits the trial, including witness examination, to run in electronic mode. Expect the defence to test, in order: the Section 105 BNSS audio-video record of the seizure, the hash continuity, and the identity and standing of the certificate signatory.

Founder checklist

  • Name the certificate signatory per log source, today. For every system you would rely on in court — SIEM, application logs, payment gateway, email — record who the responsible custodian is and keep it current when they leave.
  • Put 1930 in the runbook above CERT-In for money-out incidents. The six-hour regulatory clock does not freeze anyone's account; the helpline does.
  • Ban screenshot-only evidence. Preserve native .eml / .msg and platform chat exports, hash them SHA-256, then screenshot as a supplement.
  • Pre-agree a forensic examiner and a write-blocker process before an incident, not during one.
  • Diarise both 180-day clocks — Rule 3(1)(j) preservation and CERT-In Direction (iv) log retention — as concurrent, not alternative.

Frequently Asked Questions

Q1: Does the CERT-In report start a criminal case?

No. The six-hour notification under Section 70B(6) of the IT Act 2000 is a regulatory report to the national incident-response agency. Failure to comply with a CERT-In direction attracts imprisonment up to one year or a fine up to Rs 1 crore or both under Section 70B(7) — the figure substituted for "one lakh" by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023. But it registers no FIR and preserves no evidence.

Q2: Our vendor holds the logs. Whose certificate is needed?

The vendor's. The certificate must come from a person in a responsible official position in relation to the operation of the device that produced the record. Build the obligation into the contract now — an audit-and-evidence clause requiring the processor to furnish a Section 63(4) BSA certificate on request, with a named signatory role.

Q3: What if the police refuse to register the FIR?

Escalate under Section 175(3) BNSS to the Superintendent of Police in writing, and then to the Magistrate. Keep the NCRP Acknowledgement Number, the written refusal or the diary entry, and the date. Refusal to register a cognizable-offence FIR is itself actionable.

Q4: How long do we keep exhibits?

The original device stays in sealed custody until final disposal of the trial and exhaustion of appeals — realistically 5 to 10 years. Forensic images live on an air-gapped store in two copies, master and working, both hashed at creation and re-hashed at each archival anniversary.

Q5: Does the Enforcement Directorate get involved?

Where the predicate offence is scheduled under the Prevention of Money-Laundering Act, 2002 — cyber-terrorism under Section 66F IT Act and IT Act Sections 72 / 72A among them — Section 3 read with Section 4 PMLA attaches, carrying rigorous imprisonment of three to seven years, with provisional attachment of proceeds under Section 5. That converts a short cyber-FIR into a long financial investigation with confiscation consequences.

Q6: Do pre-July-2024 incidents follow different rules?

Offences dated before 1 July 2024 continue under the IPC, CrPC and Evidence Act under savings provisions. But the Section 65B certificate jurisprudence is identical in substance to what a Section 63 BSA court demands, so the drafting workflow above applies unchanged.


Beyond this brief Preview

Veritect Legal AI holds the full operative chain behind this workflow: the Bharatiya Sakshya Adhiniyam 2023 Sections 61-63 with the Anvar and Arjun Panditrao line; the BNSS 2023 investigation, search-and-seizure and jurisdiction provisions; the IT Act 2000 offence grid and Section 70B; the IT Rules 2021 as amended through the February 2026 synthetic-media amendment; and the CERT-In Directions of 28 April 2022.

Practitioner-level content available on Veritect Legal AI:

  • Section 63(4) BSA certificate template with hash and device-particulars fields
  • Custodian-designation matrix mapping each log source to its certifying officer
  • Rule 3(1)(j) preservation-notice format and Sahyog routing note
  • Chain-of-custody register schema with hash-recomputation checkpoints
  • Parallel-clock calendar: CERT-In 6 hours, Rule 3(1)(j) 180 days, Direction (iv) 180 days

Access Veritect Legal AI →


Primary Sources

Primary source

Title: National Cyber Crime Reporting Portal (NCRP) and the Indian Cybercrime Coordination Centre (I4C) intake framework
Issuer: Ministry of Home Affairs / Indian Cybercrime Coordination Centre (I4C)
Effective: 2024-07-01

Frequently asked

Does filing a CERT-In incident report also start a criminal case?

No. The six-hour report under Section 70B(6) of the Information Technology Act, 2000 read with the CERT-In Directions of 28 April 2022 is a regulatory notification to the national incident-response agency. It does not register an FIR, does not freeze a mule account and does not preserve evidence for trial. A criminal case starts only on an FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023, or on a National Cyber Crime Reporting Portal complaint that the state cyber cell converts into one. Run both tracks in parallel from hour zero.

Which of the three victim intake routes should we use first?

Apply a three-way test. If there is live financial loss with a traceable beneficiary account, call 1930 first — the helpline pushes a hold or lien request to the beneficiary bank, with an observed turnaround of 24 to 72 hours. If the offence is serious and investigation-ready — ransomware on critical infrastructure, cyber-terrorism under Section 66F of the IT Act 2000, child sexual abuse material — go directly to a cyber police station for an FIR. Everything else starts at cybercrime.gov.in, with escalation to the cyber police station if there is no contact within 7 days.

Who is allowed to sign the Section 63(4) BSA certificate?

A person in a responsible official position in relation to the operation of the device or the management of the relevant activities — in practice the custodian or administrator of the server, application or network the record came from. The investigating officer cannot sign for a bank's or an intermediary's log; the bank's or platform's nodal custodian must. Misattribution is the most common single point of failure, and under Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473 and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 a defective certificate is a complete bar to admissibility of secondary electronic evidence.

Is a certificate needed if we hand the actual laptop or phone to the court?

No. Arjun Panditrao Khotkar (2020) confirmed that where the original device is itself produced as primary evidence, no certificate is required. The certificate regime under Section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023 attaches to secondary electronic evidence — printouts, log exports, CDRs, chat exports and screenshots. In practice most enterprise evidence is secondary, because production servers cannot be surrendered to a malkhana.

How long must an intermediary preserve data once police ask for it?

At least 180 days under Rule 3(1)(j) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, or longer if the requesting agency specifies. That clock runs concurrently with — and does not replace — the 180-day rolling ICT log-retention obligation in Direction (iv) of the CERT-In Directions of 28 April 2022, and neither displaces the practical need to hold exhibits for the full duration of the trial.

The servers and the suspect are abroad. What actually works?

Two things, in this order. First, send a direct preservation request to the overseas provider — most large US intermediaries act on a law-enforcement preservation request under 18 U.S.C. § 2703(f), which holds data for 90 days and is extensible by a further 90. Second, file the Mutual Legal Assistance Treaty request through the Internal Security-II Division of the Ministry of Home Affairs, with the Department of Legal Affairs as Central Authority. India has roughly 45 active MLATs; typical response time for content data is 6 to 18 months, so preservation first is not optional — routine log rotation destroys the evidence while the request is in transit.

Does BNS 2023 reach an attacker sitting outside India?

Yes. Section 1(5) of the Bharatiya Nyaya Sanhita, 2023 extends the Sanhita to a person in any place outside India committing an offence targeting a computer resource located in India, and Section 75 of the Information Technology Act, 2000 is the long-standing special-law parallel. Section 202 of the BNSS 2023 gives jurisdiction to any court within whose limits the electronic communication constituting the cheating was sent or received — which for most Indian victims means their home court.

Can we take screenshots instead of preserving the source?

Only as a supplement, never as the record. Screenshots are secondary evidence requiring a Section 63(4) BSA certificate, and any editing overwrites the file metadata that establishes provenance. Preserve the native artefact — raw .eml or .msg for email so that Received, SPF, DKIM and DMARC headers survive for IP attribution, and the platform's own export format for chat — then hash it with SHA-256 and keep the screenshot alongside.

Prerequisites

  • Named incident commander with authority to authorise forensic imaging
  • Pre-identified forensic examiner (CERT-In-empanelled, CFSL or accredited private lab)
  • Named custodian for each log source who can sign a Section 63(4) BSA certificate
  • Published Grievance / Nodal Officer details under Rules 3(2) and 4 of the IT Rules, 2021
  • Chain-of-custody register and SHA-256 hashing capability

Sanctions for non-compliance

Failure to comply with a CERT-In direction under Section 70B(6) of the Information Technology Act, 2000 attracts imprisonment up to one year or a fine up to Rs 1 crore or both under Section 70B(7) — the 'one crore' figure substituted for 'one lakh' by the Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023) with effect from 30 November 2023. Disobedience to a lawful production summons under Section 94 BNSS attracts Section 223 of the Bharatiya Nyaya Sanhita, 2023. A missing or misattributed Section 63(4) BSA certificate carries no penalty of its own but renders the electronic evidence inadmissible.

Tags

cybersecurity cybercrime ncrp bsa-2023 section-63-certificate electronic-evidence bnss-2023 it-rules-2021 chain-of-custody
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free