Cloud Security Alliance
India's CERT-In 12-Hour Patch Mandate Overview
Pages
10
Time to read
14 mins
Language
English
Pages
10
Time to read
14 mins
Language
English
This technical report outlines the directive issued by India's Computer Emergency Response Team (CERT-In) on May 25-26, 2026, which mandates organizations to patch known exploited vulnerabilities on internet-facing systems within 12 hours where feasible. The document details the implications of AI-assisted attack tools that have drastically reduced the exploitation window, with average breakout times for eCrime actors now measured in minutes. The CERT-In blueprint not only establishes strict patch timelines but also introduces a comprehensive 60-day implementation roadmap that includes eleven core defensive principles, such as zero trust adoption and AI governance requirements. It emphasizes the need for compensating controls when patches are unavailable, reflecting an understanding of operational challenges faced by organizations. The report serves as a model for national cybersecurity agencies, encouraging security teams globally to evaluate these guidelines as a reference for enhancing their vulnerability management frameworks.