
The Computer Emergency Response Team (CERT-In) has issued new cybersecurity guidelines that will require technology vendors to adopt AI-assisted security testing and disclose critical vulnerabilities immediately. According to reports from The Times of India, the framework applies to OEMs, software vendors, cloud service providers, managed service providers and other technology suppliers operating in India. The move comes as cyber threats increasingly evolve with artificial intelligence, enabling attackers to identify vulnerabilities faster, automate reconnaissance and scale exploitation with greater precision. As per Moneycontrol, the guidelines were published on June 10 and represent a comprehensive response to the changing threat landscape where AI-powered attacks are becoming more sophisticated.
The new guidelines mandate that technology vendors must significantly accelerate patch deployment across India's digital ecosystem. According to Moneycontrol, the framework requires vendors to maintain continuous vulnerability assessments and keep assessing vulnerabilities and notifying affected organisations and the agency immediately. The guidelines propose indicative timelines for patching, including emergency releases for certain AI-exploitable critical vulnerabilities and seven-day windows for high-severity vulnerabilities affecting IT systems. The framework also encourages the use of AI-assisted testing techniques for regular security validation, representing a significant shift from traditional security practices to incorporate AI-powered threat detection capabilities. Recent developments show that AI technology can analyze masses of security information to identify critical weaknesses and prioritize areas of potential threat, enabling organizations to conduct greater number of more sophisticated simulations that help achieve more efficient vulnerability identification and enhanced security coverage.
CERT-In's 2022 directions have transformed from advisory guidelines to mandatory requirements with significant enforcement mechanisms. Non-compliance carries penalties including imprisonment of up to one year and fines reaching ₹1 crore (approximately USD 10 million) under Section 70B(6) of the Information Technology Act, 2000. All service providers, intermediaries, data centers, and government organizations must report specified cybersecurity incidents to CERT-In within six hours of detection or notification. Organizations are required to maintain logs of all their information and communication technology (ICT) systems for a rolling period of 180 days and synchronize all system clocks with designated Indian NTP servers. The framework also mandates that entities must conduct an annual audit of their ICT infrastructure and designate a named POC to interface with CERT-In.
The guidelines have met with an unusual degree of industry acceptance, with many companies acknowledging the additional costs involved while recognizing the urgent need for response. As reported by Moneycontrol, Malcolm Gomes, chief operating officer at data protection platform Privy by IDfy, noted that requirements around continuous assessments, SBOMs, accelerated patching, and stronger security practices feel less like regulatory overreach and more like a response to a changing threat environment. The industry acknowledges that when a cyber incident involves personal data, it does not remain a just cybersecurity issue but becomes a privacy, trust, and regulatory issue as well. While the guidelines are currently voluntary, experts suggest that businesses today have flexibility to adopt and calibrate these measures to their specific contexts, though the debate is no longer about whether cyber defences need to evolve but about whether organisations can move quickly enough to keep pace with adversaries using AI. The lack of talented, experienced security testing specialists restricts market growth through two primary mechanisms: restricts the ability of service providers to undertake significant engagements and retards client adoption, leading to higher service costs and variable quality assessments.
The guidelines are particularly significant for government procurement, where companies are increasingly being asked to prove they have strong cybersecurity practices before winning contracts, especially in sectors such as banking, healthcare and government. As per Moneycontrol, Jaydeep Singh, general manager for India at cybersecurity firm Kaspersky, noted that these guidelines land at a moment when the threat landscape is already shifting under the weight of AI, and we've entered an era where attackers and defenders are both armed with artificial intelligence and the margin for error has never been smaller. The framework represents a shift from traditional security measures to incorporate AI-assisted testing and faster vulnerability response mechanisms, aiming to enhance the resilience of India's digital infrastructure against sophisticated cyber threats. The regulatory environment is undergoing a philosophical transformation from perfunctory checklists to evidence-based audits that require objective, operational proof of security effectiveness. Rising cyber threat complexity compels organizations to expand and deepen their security testing programs, driving demand for advanced network security testing services and solutions as attack methods become more varied and subtle.