Read or download the official PDF of this gazette notification issued by the Ministry of Electronics and Information Technology on 14th August 2026. Classified under Press Release.
Executive Summary
This report details the Indian Government’s measures to strengthen the cyber security of digital platforms and citizen services in response to rising cyber incidents, which reached nearly 29.5 lakh in 2025. It outlines the institutional framework involving CERT-In, NCSC, and NCIIPC, along with mandatory auditing protocols and sectoral response teams. Key recurring action items include annual awareness months in October and monthly "Cyber Jagrookta Diwas" to enhance national cyber resilience.
Key Points / Main Content
Incident Statistics and Monitoring
Cyber security incidents tracked by CERT-In increased from 15,92,917 in 2023 to 29,44,248 in 2025.
CERT-In functions as the national agency for incident response under Section 70B of the IT Act, 2000.
Institutional Framework and Coordination
National Cyber Security Coordinator (NCSC): Coordinates cyber security efforts across various government agencies.
National Cyber Coordination Centre (NCCC): Detects threats and shares intelligence with State Governments and stakeholder agencies.
National Critical Information Infrastructure Protection Centre (NCIIPC): Protects critical infrastructure (CII) through real-time threat intelligence and vulnerability assessments.
Sector-Specific and Citizen Services
Sectoral CSIRTs: Dedicated units for the Finance sector (CSIRT-Fin, operational since 2022) and the Power sector (CSIRT-Power, operational since 2024).
Cyber Swachhta Kendra (CSK): A botnet cleaning and malware analysis center providing citizens with free tools and security best practices.
Compliance and Auditing Requirements
Mandatory Auditing: All government websites and applications must undergo cyber security audits before and after hosting.
Empanelled Auditors: 237 'Information Security Auditing Organisations' are empanelled to conduct vulnerability assessments and penetration testing.
Cyber Crisis Management Plan (CCMP): Formulated for implementation by all Central Ministries, State Governments, and their organizations.
Capacity Building and Awareness
ISEA Project: Conducted 6,650 awareness workshops reaching over 11.37 lakh participants, including students and government officials.
Regular Mock Drills: Conducted by CERT-In to assess the security posture of organizations in critical sectors.
Training: CERT-In upskills the cyber security workforce through collaboration with industry partners, training over 32,000 participants across 2025 and 2026.
Legal Framework
The Digital Personal Data Protection Act, 2023, provides a statutory framework for the lawful and secure processing of citizens' digital personal data.
Impact Analysis
Government Ministries and State DepartmentsImpact: Subjected to mandatory security compliance, including the implementation of the Cyber Crisis Management Plan (CCMP) and regular security drills.
Action Required: Ensure all websites and applications are audited prior to hosting and perform regular post-hosting audits through empanelled organizations.
Critical Information Infrastructure (CII) EntitiesImpact: These organizations receive near real-time threat intelligence and are subject to periodic vulnerability assessments by NCIIPC.
Action Required: Implement remedial measures advised by CERT-In and NCIIPC to protect protected systems from cyber-attacks.
General Public and CitizensImpact: Benefit from enhanced data protection laws and access to free tools for malware removal and cyber hygiene.
Action Required: Utilize Cyber Swachhta Kendra tools for botnet cleaning and participate in awareness activities like "Cyber Jagrookta Diwas."
Cyber Security Workforce and StudentsImpact: Increased access to specialized training, workshops, and multilingual educational material to improve technical skills and cyber awareness.
Action Required: Participate in CERT-In training programs and ISEA workshops to upskill in information security practices.
Key Entities Referenced
Indian Computer Emergency Response Team (CERT-In): The national agency designated under the Information Technology Act for responding to cyber security incidents and coordinating nationwide incident response.
Information Technology Act, 2000: The primary legislation providing the legal framework for cyber security, including the designation of national agencies and protection of critical infrastructure.
National Critical Information Infrastructure Protection Centre (NCIIPC): The agency established under Section 70A of the IT Act for the protection and threat assessment of Critical Information Infrastructure (CII).
Digital Personal Data Protection Act, 2023: A statutory framework established to ensure the lawful, secure, and accountable processing of citizens' digital personal data.
National Cyber Coordination Centre (NCCC): An initiative implemented by CERT-In to detect cyber threats and share intelligence with stakeholder agencies and State Governments.
Ministry of Electronics & IT
Government Strengthens Cyber Security
Preparedness of Central Government Digital
Platforms and Citizen Services
प्रव तथ: 14 AUG 2026 1:25PM by PIB Delhi
The Government is committed to ensuring an open, safe, trusted and accountable cyberspace. Several
legal, technical and administrative policy measures have been implemented to strengthen the cyber
security preparedness of Central Government digital platforms and citizen service portals, protect digital
infrastructure and enhance cyber resilience.
Indian Computer Emergency Response Team (CERT-In) has been designated as the national agency for
responding to cyber security incidents under Section 70B of the Information Technology Act, 2000.
As per the information reported to and tracked by CERT-In, the total number of cyber security incidents
observed during the last three years are given below:
Year No of incidents
2023 15,92,917
2024 20,41,360
2025 29,44,248
On observing cyber security incidents including those related to Government-managed platforms, CERT-
In advises remedial measures to concerned organizations and coordinates incident response measures with
affected organizations, service providers, respective sector regulators as well as Law Enforcement
Agencies.
The Government has institutionalized a nationwide integrated and coordinated system to deal with cyber-
attacks in the country. These measures, inter alia, include:
a. National Cyber Security Coordinator (NCSC) under the National Security Council Secretariat
(NSCS) to ensure coordination related to cyber security amongst different agencies.
b. National Cyber Coordination Centre (NCCC), implemented by CERT-In, examines cyberspace
to detect cyber security threats and shares threat intelligence with concerned organisations, State
Governments and stakeholder agencies for taking appropriate action.
c. National Critical Information Infrastructure Protection Centre (NCIIPC) has been established
under Section 70A of the Information Technology Act, 2000 for protection of Critical Information
Infrastructure (CII).d. NCIIPC provides near real-time threat intelligence and situational awareness, issues regular
alerts and advisories to Critical Information Infrastructure (CII)/Protected System (PS) entities,
periodically undertakes vulnerability and risk assessment of CII/Protected Systems and provides
feedback to the concerned entities.
e. Cyber Swachhta Kendra (CSK)
A citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber
Space.
It is the Botnet Cleaning and Malware Analysis Centre and helps to detect malicious programs and
provides free tools to remove the same.
It also provides cyber security tips and best practices for citizens and organisations.
f. Sectoral Computer Security Incident Response Team (CSIRT)
CSIRT in the Finance sector (CSIRT-Fin) under CERT-In is operational since May 2022 to coordinate
cyber incident response in the banking and financial sector.
CSIRT-Power has been operational since September 2024 as an extended arm of CERT-In to coordinate
cyber security issues within the power sector entities.
g. CERT-In operates an automated cyber threat intelligence exchange platform for sharing tailored
alerts with organisations across sectors for proactive threat mitigation.
h. CERT-In has formulated a Cyber Crisis Management Plan (CCMP) for countering cyber-
attacks and cyber terrorism for implementation by all Ministries/Departments, State Governments
and their organizations.
i. Cyber security mock drills are conducted regularly by CERT-In, to enable assessment of cyber
security posture and preparedness of organisations in Government and critical sectors.
j. CERT-In has created a panel of 'Information Security Auditing Organisations' for auditing,
including vulnerability assessment and penetration testing of computer systems, networks,
websites and applications of various organizations of the Government and critical sectors. 237
information security auditing organisations are empanelled by CERT-In to support and audit
implementation of Information Security Best Practices.
k. All the Government websites and applications are audited with respect to cyber security prior
to their hosting. The auditing of the websites and applications is conducted on a regular basis after
hosting also.
l. CERT-In issues alerts and advisories regarding latest cyber threats/vulnerabilities and
countermeasures to protect computers, networks and data on an ongoing basis.
m. The Government has put in place a statutory framework under the Digital Personal Data
Protection Act, 2023. The rules framed, thereunder, to ensure that the sharing and processing of
citizens’ digital personal data for law enforcement purposes is undertaken in a lawful, secure and
accountable manner.
n. Information Security Education and Awareness (ISEA) Workshops
● The Ministry of Electronics and Information Technology (MeitY) is implementing the
ISEA project for generating human resources in Information Security and creating general
awareness on various aspects of cyber hygiene & cyber security among the masses.
● 6,650 awareness workshops have been conducted across the country covering over
11.37 lakh participants, including students, teachers, law enforcement personnel,
Government officials, and the general public. This includes 70 awareness workshopsorganized in Kerala covering 9481 participants
● Further, multilingual awareness material in the form of handbooks, short videos,
posters, brochures, cartoon stories for children, etc. published and disseminated through
print, electronics, social media, and www.isea.gov.in & https://staysafeonline.in/ .
o. National Cyber Security Awareness Activities
● The Government organises events and activities for citizens as well as the technical
cyber community across the country. Some of these include:
● National Cyber Security Awareness Month (NCSAM) in October every year
● Safer Internet Day on the second Tuesday of February
● Swachhta Pakhwada (1st –15th February), and
● Cyber Jagrookta Diwas (CJD) on the first Wednesday of every month
p. Training programs by CERT-In
● CERT-In conducts cyber security training programs in collaboration with Industry partners
to upskill the cyber security workforce in Government, public and private organizations. 32
and 13 training programs were conducted covering 20799 and 12109 participants including
786 and 411 participants from Kerala during the year 2025 and 2026 (upto June) respectively
● CERT-In is regularly sharing safety and security tips and awareness posters, info-graphics
and videos through its official websites and social media handles such as Facebook,
X(Twitter), Instagram, YouTube and LinkedIn for sensitizing internet users on cyber security
attacks and frauds and prevention measures.
This information was given by Union Minister of State for Electronics and IT Shri Jitin Prasada in
Lok Sabha on 12.08.2026
****
Vinod Kumar / Kanishk Sharma
(रलीज़ आईडी: 2299339) आगंतुक पटल : 837
इस वज्ञ को इन भाषाओ ंम पढ़: Urdu , ही , Bengali , Tamil