TL;DR for founders
Your CERT-In report is due in 6 hours. Your case is won or lost in the first 72. The regulatory report under Section 70B(6) of the Information Technology Act, 2000 does not register an FIR, does not freeze the fraudster's bank account and does not preserve a single log for trial. Three separate things do: the 1930 helpline (beneficiary-account hold in 24-72 hours), an FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023, and a Section 63(4) certificate under the Bharatiya Sakshya Adhiniyam, 2023 signed by the right custodian for every log you intend to rely on. Get the third one wrong and everything else was wasted effort.
Indian cybercrime response runs on two tracks that most incident-response plans collapse into one. This playbook covers the prosecution track — victim intake, FIR, preservation, and courtroom admissibility. It deliberately starts where Veritect's CERT-In six-hour incident-reporting SOP ends, and assumes offences dated on or after 1 July 2024, when the Bharatiya Nyaya Sanhita, 2023 ('BNS'), Bharatiya Nagarik Suraksha Sanhita, 2023 ('BNSS') and Bharatiya Sakshya Adhiniyam, 2023 ('BSA') replaced the Indian Penal Code 1860, the Code of Criminal Procedure 1973 and the Indian Evidence Act 1872.
Step 1 — Triage the intake route in the first hour
India gives a victim three concurrent routes, and the choice is a speed decision, not a legal one.
| Route | Use when | Realistic clock |
|---|---|---|
| 1930 helpline (Citizen Financial Cyber Fraud Reporting and Management System) | Live financial loss with a traceable beneficiary account | Bank hold / lien request in 24-72 hours |
NCRP — cybercrime.gov.in |
Impersonation, harassment, defamation, low-value cheating | State cyber-cell contact typically within 7-14 days |
| Direct FIR at a cyber police station | Ransomware on critical systems, cyber-terrorism (Section 66F, IT Act 2000), CSAM, large-scale breach | Same day, if you insist correctly |
NCRP has two intake tracks — "Report Women/Child Related Crime", which permits anonymous filing, and "Report Other Cybercrime". Registration needs name, email and mobile OTP; uploads are capped at 5 MB per file with multiple uploads allowed. The complaint auto-routes to the jurisdictional state cyber cell by the complainant's pincode and generates an Acknowledgement Number. Keep that number — it is the reference for every escalation.
Step 2 — Get an FIR, not a Non-Cognizable Report
Under Section 173 BNSS, information about a cognizable offence must be reduced to writing. Refusal is itself actionable: escalate to the Superintendent of Police under Section 175(3) BNSS, then to the Magistrate. The FIR copy is free under Section 173(2) BNSS.
Two practical points decide this step. First, insist on an FIR rather than a Non-Cognizable Report wherever Sections 66, 66C, 66D or 66F of the IT Act 2000, or BNS Sections 318 (cheating), 319 (cheating by personation), 336 (forgery, expressly covering false electronic records) or 351 (criminal intimidation) are attracted. Second, Section 202 BNSS gives jurisdiction to any court within whose limits the electronic communication was sent or received — so a victim can usually file at home rather than at the fraudster's location. Where the offence carries seven years or more, Section 176(3) BNSS makes forensic examination mandatory, which is a lever worth citing at the counter.
Step 3 — Preserve before you investigate
The integrity of every downstream exhibit is set here, before any analyst touches anything.
- Do not power on a seized device. Booting alters access timestamps and swap files, and hands the defence a ready-made integrity argument.
- Image bit-for-bit through a write-blocker, and record the blocker's serial number in the seizure memo.
- Hash with SHA-256 as primary. MD5 is a secondary cross-check only; SHA-1 is deprecated. Hash both source and image, and re-compute at every custody transfer.
- For live systems that cannot be imaged — production databases, cloud workloads — perform live acquisition with contemporaneous hashing, and document why imaging was impossible.
The Bureau of Police Research and Development SOP for Collection of Electronic Evidence is the reference standard; it requires both the source and the export to be hashed and the hashes recorded in the seizure memo. Note also that Section 105 BNSS requires the search and seizure and the list of items to be recorded by audio-video means — usually a mobile phone — and forwarded to the Magistrate without delay. Its absence is a live cross-examination point.
💡 Not sure which of the three clocks your incident has already started? The Veritect Legal AI platform holds the CERT-In Directions of 28 April 2022, the IT Rules 2021 preservation provisions and the BNSS 2023 investigation chapter side by side, so you can see which obligation is running and who owes what to whom. Explore Veritect Legal AI →
Step 4 — The Section 63 BSA certificate: the step that decides the case
Section 61 BSA saves electronic records from being rejected merely because they are electronic. Section 63 BSA then governs admissibility, carrying forward the architecture of the repealed Section 65B of the Evidence Act 1872 with substantive parity — which is why Anvar and Arjun Panditrao still govern.
The certificate under Section 63(4) BSA must accompany the electronic record at each instance where it is submitted for admission — the statute's own words. It must identify the record and describe how it was produced, give the particulars of the device involved, and be signed by a person in charge of the device or the management of the relevant activities, together with an expert.
Four drafting rules follow:
- Signature by the right person. The custodian of the system that produced the record — not the investigating officer, unless the IO also administers that log.
- Include the SHA-256 hash even though Section 63 does not expressly demand it. It is the audit signature courts treat as the integrity gold standard.
- State proper operation of the computer through the relevant period, or that any malfunction did not affect accuracy.
- File it with the record, not at the appellate stage. Arjun Panditrao Khotkar (2020) 7 SCC 1 expressly overruled Shafhi Mohammad (2018) 2 SCC 801 and left only a narrow window — a reasoned application showing genuine prior efforts — for a belated certificate.
Step 5 — Preservation and production from third parties
Two instruments do this work. Section 94 BNSS (successor to Section 91 CrPC) is the summons to produce a document or thing, addressed to intermediaries, banks and telcos. Rule 3(1)(j) of the IT Rules, 2021 obliges an intermediary receiving an order from a lawfully authorised agency to preserve the information for at least 180 days, or longer if specified.
Route the request to the intermediary's published Grievance / Nodal Officer under Rules 3(2) and 4 of the IT Rules 2021 — copying the Sahyog portal (sahyog.i4c.gov.in), which since the Rule 3(1)(d) amendment of 15 November 2025 is the administrative anchor for takedown and coordination. Sending the notice to a marketing or registered-office address buys the accused a procedural-compliance argument. Identify the target with specificity: handle, phone number, IP address with timestamp and time zone, transaction ID. Insist on a separate Section 63(4) BSA certificate from the intermediary's custodian on the date of production — a certificate you sign for their log is worthless.
Step 6 — Cross-border evidence
Send the 18 U.S.C. § 2703(f) preservation request to the overseas provider immediately — 90 days, extensible by 90 — and only then file the MLAT request through MHA's Internal Security-II Division, with the Department of Legal Affairs as Central Authority. India has roughly 45 active MLATs; content data typically returns in 6 to 18 months. India is not a party to the Budapest Convention on Cybercrime; the UN Convention against Cybercrime, adopted by UNGA Resolution A/RES/79/243 of 24 December 2024, will eventually change the routing but has not yet done so.
Step 7 — Chain of custody
No statute codifies chain of custody; courts read it into Sections 63 and 64 BSA. Every transfer — seizure to lab, lab to IO, IO to prosecutor, prosecutor to court — needs a dated, signed entry naming transferor and transferee, the purpose, the exhibit identifier, the recomputed hash and the tamper-seal number. Keep the register for a minimum of 10 years; appellate courts routinely recall it. If a copy is made for analysis, hash the copy at the moment of copying.
Step 8 — Court production
At tendering, the custodian witness proves the Section 63(4) certificate and identifies the device; the forensic examiner proves hash identity between source and image. Section 530 BNSS permits the trial, including witness examination, to run in electronic mode. Expect the defence to test, in order: the Section 105 BNSS audio-video record of the seizure, the hash continuity, and the identity and standing of the certificate signatory.
Founder checklist
- Name the certificate signatory per log source, today. For every system you would rely on in court — SIEM, application logs, payment gateway, email — record who the responsible custodian is and keep it current when they leave.
- Put 1930 in the runbook above CERT-In for money-out incidents. The six-hour regulatory clock does not freeze anyone's account; the helpline does.
- Ban screenshot-only evidence. Preserve native
.eml/.msgand platform chat exports, hash them SHA-256, then screenshot as a supplement.- Pre-agree a forensic examiner and a write-blocker process before an incident, not during one.
- Diarise both 180-day clocks — Rule 3(1)(j) preservation and CERT-In Direction (iv) log retention — as concurrent, not alternative.
Frequently Asked Questions
Q1: Does the CERT-In report start a criminal case?
No. The six-hour notification under Section 70B(6) of the IT Act 2000 is a regulatory report to the national incident-response agency. Failure to comply with a CERT-In direction attracts imprisonment up to one year or a fine up to Rs 1 crore or both under Section 70B(7) — the figure substituted for "one lakh" by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023. But it registers no FIR and preserves no evidence.
Q2: Our vendor holds the logs. Whose certificate is needed?
The vendor's. The certificate must come from a person in a responsible official position in relation to the operation of the device that produced the record. Build the obligation into the contract now — an audit-and-evidence clause requiring the processor to furnish a Section 63(4) BSA certificate on request, with a named signatory role.
Q3: What if the police refuse to register the FIR?
Escalate under Section 175(3) BNSS to the Superintendent of Police in writing, and then to the Magistrate. Keep the NCRP Acknowledgement Number, the written refusal or the diary entry, and the date. Refusal to register a cognizable-offence FIR is itself actionable.
Q4: How long do we keep exhibits?
The original device stays in sealed custody until final disposal of the trial and exhaustion of appeals — realistically 5 to 10 years. Forensic images live on an air-gapped store in two copies, master and working, both hashed at creation and re-hashed at each archival anniversary.
Q5: Does the Enforcement Directorate get involved?
Where the predicate offence is scheduled under the Prevention of Money-Laundering Act, 2002 — cyber-terrorism under Section 66F IT Act and IT Act Sections 72 / 72A among them — Section 3 read with Section 4 PMLA attaches, carrying rigorous imprisonment of three to seven years, with provisional attachment of proceeds under Section 5. That converts a short cyber-FIR into a long financial investigation with confiscation consequences.
Q6: Do pre-July-2024 incidents follow different rules?
Offences dated before 1 July 2024 continue under the IPC, CrPC and Evidence Act under savings provisions. But the Section 65B certificate jurisprudence is identical in substance to what a Section 63 BSA court demands, so the drafting workflow above applies unchanged.
Beyond this brief Preview
Veritect Legal AI holds the full operative chain behind this workflow: the Bharatiya Sakshya Adhiniyam 2023 Sections 61-63 with the Anvar and Arjun Panditrao line; the BNSS 2023 investigation, search-and-seizure and jurisdiction provisions; the IT Act 2000 offence grid and Section 70B; the IT Rules 2021 as amended through the February 2026 synthetic-media amendment; and the CERT-In Directions of 28 April 2022.
Practitioner-level content available on Veritect Legal AI:
- Section 63(4) BSA certificate template with hash and device-particulars fields
- Custodian-designation matrix mapping each log source to its certifying officer
- Rule 3(1)(j) preservation-notice format and Sahyog routing note
- Chain-of-custody register schema with hash-recomputation checkpoints
- Parallel-clock calendar: CERT-In 6 hours, Rule 3(1)(j) 180 days, Direction (iv) 180 days
Primary Sources
- National Cyber Crime Reporting Portal (NCRP): https://cybercrime.gov.in/
- Indian Cybercrime Coordination Centre (I4C): https://i4c.mha.gov.in/
- Sahyog Portal: https://sahyog.i4c.gov.in/
- Bharatiya Nyaya Sanhita, 2023 (Act 45 of 2023) — India Code: https://www.indiacode.nic.in/
- Bharatiya Nagarik Suraksha Sanhita, 2023 (Act 46 of 2023) — India Code: https://www.indiacode.nic.in/
- Bharatiya Sakshya Adhiniyam, 2023 (Act 47 of 2023) — India Code: https://www.indiacode.nic.in/
- Information Technology Act, 2000 — India Code: https://www.indiacode.nic.in/handle/123456789/1999
- CERT-In Directions dated 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- MHA — Mutual Legal Assistance Treaties: https://www.mha.gov.in/en/commoncontent/mutual-legal-assistance-treaties-mlats
- Department of Legal Affairs (MLAT Central Authority): https://legalaffairs.gov.in/
- Bureau of Police Research and Development: https://bprd.nic.in/
- Central Forensic Science Laboratories: https://mha.gov.in/en/divisionofmha/cfsls
- Supreme Court of India — judgment portal: https://www.sci.gov.in/