Skip to content

National CERT

Definition

A government-operated or government-designated team responsible for coordinating cyber incident information at the national level. Examples include CERT-In (India), CISA (US), NCSC (UK), and BSI (Germany). They issue advisories, coordinate sector-wide responses, and may hold legal authority to receive breach notifications.

Role
Coordinates cyber incident information nationally
Examples
CERT-In (India), CISA (US), NCSC (UK), BSI (Germany)
Function
Issues advisories and coordinates sector-wide responses
Legal role
May hold authority to receive mandatory breach notifications

Common questions

Does every organisation's breach have to be reported to the national CERT?+

This depends on the jurisdiction's specific law; some countries, such as India under CERT-In directions, mandate reporting of certain categories of incidents within a defined timeframe, while others rely on sector-specific regulators or voluntary reporting, so obligations vary by country and by the type of entity involved.

What is the difference between a national CERT and a private incident response team?+

A national CERT coordinates at the country or sector level, issuing broad advisories, tracking trends across many organisations, and sometimes holding statutory authority, while a private or organisational CSIRT handles incident response for its own specific environment and may report relevant findings up to the national CERT.

Can a national CERT compel an organisation to take specific remediation actions?+

Authority varies by country; some national CERTs, like CERT-In, have statutory powers to direct certain actions or require compliance from regulated entities, while others operate purely in an advisory and coordination capacity without direct enforcement power.

Related terms

CSIRT
Computer Security Incident Response Team. The organisational unit responsible for preparing for, detecting, coordinating, and resolving security incidents. Sometimes called CERT (Computer...
FIRST
Forum of Incident Response and Security Teams. A global membership organisation that sets standards for CSIRT capability and facilitates trusted information sharing...
Legal Liaison
The CSIRT role responsible for advising on legal obligations during an incident: evidence preservation requirements, breach notification deadlines, law enforcement engagement, and...
Retainer Agreement
A contract between an organisation and an external IR firm that guarantees a defined response time and service scope in exchange for...
Team Lead
The person who owns the incident response process during an active incident. The team lead coordinates analyst tasks, manages escalation to leadership,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.