**Executive Summary**
The Ministry of Electronics & IT has announced significant reforms to strengthen India’s cybersecurity framework, focusing on network security, data protection, and CCTV systems. The government has implemented mandatory "Essential Requirements" for CCTVs, restricted the procurement of non-compliant equipment by government departments, and blocked 652 mobile applications to mitigate data security risks. These measures, outlined in a Lok Sabha briefing on March 25, 2026, aim to enhance the transparency and security of digital infrastructure and supply chains.
**Key Points / Main Content**
**Legal and Regulatory Framework**
* **National Security Directive (2021):** Mandates that only telecommunication equipment from "trusted sources" be deployed in national networks.
* **Telecommunication Act, 2023:** Includes extensive provisions for the security of telecommunication networks.
* **Digital Personal Data Protection Act, 2022:** Establishes a legal framework to ensure the protection of personal data.
* **Section 69A of the IT Act, 2000:** Used to block 652 mobile applications due to data security concerns and malpractices.
**CCTV System Security Requirements**
* **Mandatory Essential Requirements (ERs):** All CCTV systems in the Indian market must now meet notified security criteria; 507 models are currently certified.
* **Hardware Security:** Manufacturers must provide clear documentation regarding the origin of critical components, such as System-on-Chip (SoC).
* **Vulnerability Testing:** Devices must be tested against vulnerabilities that could permit unauthorized remote access.
* **Accredited Testing:** CCTV equipment must undergo testing at accredited laboratories to ensure compliance.
* **Procurement Restrictions:** Government departments are prohibited from purchasing CCTV equipment that does not meet these mandatory criteria.
**Cybersecurity Monitoring and Guidelines**
* **National Cyber Coordination Centre (NCCC):** Operated by CERT-In to detect threats and share actionable intelligence with state governments and stakeholder agencies.
* **Security Auditing:** CERT-In has empanelled 237 organizations to audit the implementation of information security best practices.
* **Government Guidelines (June 2023):** Guidelines issued for government entities covering data security, network security, identity management, and incident response.
* **Technical Guidelines (July 2025):** Updated requirements for the Bill of Materials (BOM) for software, hardware, AI, Quantum Computing, and Cryptography to enhance supply chain transparency.
**Impact Analysis**
**Government Departments and Ministries**
**Impact**
They are restricted from purchasing any CCTV equipment that fails to meet the notified Essential Requirements and must follow specific information security practices.
**Action Required**
Strictly adhere to procurement restrictions and implement measures outlined in the advisory to address CCTV network vulnerabilities and ensure surveillance system integrity.
**CCTV Manufacturers and Vendors**
**Impact**
Their products must undergo rigorous testing and certification to be eligible for the Indian market, specifically for government procurement.
**Action Required**
Ensure all CCTV models meet Essential Requirements (ERs), obtain certification from accredited labs, and maintain clear documentation of the origin of critical hardware components like SoCs.
**Telecom Service Providers**
**Impact**
They are legally bound to use only "trusted sources" for their network infrastructure.
**Action Required**
Comply with the National Security Directive on Trusted Sources and the provisions of the Telecommunication Act, 2023, during equipment deployment.
**CERT-In Empanelled Auditing Organizations**
**Impact**
These 237 organizations are designated to support and verify the implementation of security practices across various entities.
**Action Required**
Conduct audits based on the Information Security Best Practices and technical guidelines issued by CERT-In.
Key Entities Referenced
Telecommunication Act, 2023: The primary legislation containing provisions for the security of telecommunication networks in India.
Digital Personal Data Protection Act, 2022: The legal framework established to ensure the protection and security of personal data.
Essential Requirements (ERs) for CCTVs: Mandatory security standards, hardware documentation, and testing protocols required for CCTV systems in the Indian market.
CERT-In: The national agency implementing the National Cyber Coordination Centre and issuing technical guidelines for information security and supply chain transparency.
Section 69A of the IT Act, 2000: The legal provision under which the government blocks mobile applications due to data security and malpractice concerns.
Ministry of Electronics & IT
Government has strengthened the legal
framework pertaining to network security and
data protection
Major reforms undertaken for strengthening of security of
CCTV systems; mandatory Essential Requirements required
for CCTVs in Indian market notified
Government departments restricted from buying CCTV
equipment that does not meet these criteria
Posted On: 25 MAR 2026 4:02PM by PIB Delhi
Government of India is conscious of the cybersecurity risks posed by digital technologies. In last 12 years,
numerous efforts have been made to strengthen India’s digital ecosystem, outlined below.
Protecting India’s telecom networks:
Telecom networks are the most critical part of digital infrastructure. In 2021, Government undertook
decisive step to implement National Security Directive on Trusted Sources. It ensures that
telecommunication equipment only from the trusted sources is deployed in the telecom networks in the
country.
Strengthening legal framework:
Government has strengthened the legal framework pertaining to network security and data protection.
Government has notified the Telecommunication Act, 2023 containing extensive provisions for security of
telecommunication networks in the country and Digital Personal Data Protection Act, 2022 containing
legal framework to ensure protection of personal data.
Strengthening security of CCTV systems:
Government has undertaken major reforms for strengthening of security of CCTV systems and notified the
mandatory Essential Requirements required for CCTVs in Indian market.
Additional security requirements are as follows:
For ensuring hardware security, clear documentation of the origin of critical components (like
System-on-Chip or SoC) is now mandatory.
Devices must be tested against vulnerabilities that could allow unauthorized remote access.
Devices must now undergo testing at accredited labs.
At present, 507 models of CCTVs cameras are certified for compliance of ERs.
CCTV use by Governments:Government departments have been restricted from buying CCTV equipment that does not meet these
criteria.
Additionally, an advisory was issued to all Ministries for taking appropriate measures to address the
security threats of the CCTV network vulnerability and to ensure the overall security and integrity of
CCTV/Video Surveillance Systems.
Blocking mobile applications:
Government of India has blocked 652 mobile applications on account of concerns relating to data security
and other malpractices under Section 69A of the IT Act, 2000.
Additional measures to enhance cybersecurity posture:
National Cyber Coordination Centre (NCCC) implemented by CERT-In, examines cyberspace to
detect cyber security threats. It shares the information with concerned organizations, state
governments and stakeholder agencies for taking action.
CERT-In has empanelled 237 security auditing organizations to support and audit implementation of
Information Security Best Practices.
CERT-In has issued guidelines on information security practices for government entities in June
2023 covering domains such as data security, network security, identity and access management,
application security, third-party outsourcing, hardening procedures, security monitoring, incident
management and security auditing.
CERT-In has issued updated technical guidelines in July 2025 for Bill of Materials (BOM) for
software, hardware, Artificial Intelligence, Quantum Computing & Cryptography requirements.
These guidelines are aimed to enhance the security and transparency of supply chains for software,
hardware & emerging technologies.
This information was submitted by Union Minister of State for Electronics and Information Technology
Shri Jitin Prasada in Lok Sabha on 25.03.2026.
***
MSZ
(Release ID: 2245073) Visitor Counter : 178
Read this release in: Urdu , ही