Home India Ministry of Electronics and Information Technology Government upgrading the legacy e-mail system to a cloud bas...
Date: 2025-12-05 Category: Press Release State: Union Government Country: India

Government upgrading the legacy e-mail system to a cloud based, secure and scalable system

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** The Government of India is upgrading its legacy e-mail system to a cloud-based, secure, and scalable platform through M/s Zoho Corporation Ltd. The upgrade aims to protect critical government data and ensure data sovereignty. Key requirements include strict security measures, adherence to Indian laws, and a service availability uptime of at least 99.9%. The information was submitted by Union Minister Shri Jitin Prasada on 05 DEC 2025. **Key Points / Main Content** * **Upgrade Details:** * Upgrade is being carried out by M/s Zoho Corporation Ltd. * Model ensures timely upgrades, quick scaling, seamless migration, and integration of office productivity tools. * **Security Architecture:** * Defined rigorously to protect critical government data. * Email data encryption both at rest and in transit using RSA 256 and TLS 1.3. * Compliance with ISO 27001, ISO/IEC 27017, and ISO 27018 standards. * Implementation of Multi-Factor Authentication (MFA) for all protocols. * Application of Geo-fencing and IP-based restrictions. * Use of industry standards and policies to combat email spoofing. * Integrated with NIC-CERT Security Information and Event Management (SIEM) system. * Requires MFA, mobile device management (MDM), and advanced threat protection to prevent phishing, malware, and data loss (DLP). * **Data Sovereignty:** * Cloud-based solution with primary and disaster recovery data centers physically located within India. * No data can be shared or replicated outside the country. * M/s Zoho is a registered Indian entity subject to Indian laws and jurisdiction. * The contract emphasizes "Make in India" products. * Government retains full ownership of all data and intellectual property. * **Reliability and Availability:** * Service designed for high reliability, mandating at least 99.9% uptime on a 24x7x365 basis. * Service provider must maintain disaster recovery sites in different seismic zones (at least 500 km apart) with strict RTO and RPO. * **Clarification:** * Arattai, a messaging platform developed by M/s Zoho, is not part of the e-mail solution. **Impact Analysis** **Government of India** * **Impact:** Enhanced security, scalability, and reliability of government email communications; ensures data sovereignty and compliance with Indian laws. * **Action Required:** Ensure continued oversight and adherence to contract terms, security standards, and data sovereignty requirements. **Government Employees** * **Impact:** Changes to email system, enhanced security measures through MFA, and access to modern office productivity tools. * **Action Required:** Adoption of new email platform, adherence to security protocols including MFA, and utilization of integrated office productivity tools. **M/s Zoho Corporation Ltd.** * **Impact:** Responsibility to deliver a secure, scalable, and reliable email system compliant with government requirements. * **Action Required:** Adherence to security standards, data sovereignty requirements, and service uptime guarantees as per the contract; ongoing maintenance and support of the email platform.

Key Entities Referenced

Data Sovereignty: The policy prioritizes the protection of critical government data and ensures strict adherence to data sovereignty, requiring that data be stored and processed within India. Ministry of Electronics & IT: The ministry responsible for upgrading the government's legacy e-mail system to a cloud-based, secure, and scalable system. NIC-CERT Security Information and Event Management (SIEM) system: The security management system with which the upgraded email service is integrated. Make in India: The initiative which is emphasized in the contract with the service provider, ensuring that the government's digital communication infrastructure is sovereign. India: The upgraded email system requires that data centers for the cloud-based solution, including Primary and Disaster Recovery, are physically located within India, and that no data can be shared or replicated outside the country.
Official Source Record View Original Source →
See Full Document Text
Ministry of Electronics & IT Government upgrading the legacy e-mail system to a cloud based, secure and scalable system Security architecture of the e-mail platform defined rigorously to protect critical government data; strict adherence to data sovereignty is also being ensured प्रव तथ: 05 DEC 2025 4:11PM by PIB Delhi Government of India recognizes email as an important mode of official communication. Government is upgrading the legacy e-mail system to a cloud based, secure and scalable system. This upgrade is being carried out through M/s Zoho Corporation Ltd., a reputed Indian software service provider, selected through an open competitive process. This model ensures timely upgrades, quick scaling up, seamless migration of existing accounts, and the integration of modern office productivity tools—such as word processors, spreadsheets, and presentation software with email service. The security architecture of the e-mail platform has been defined rigorously to protect critical government data. The solution mandates that all email data be encrypted both at rest and in transit, with specific requirements for end-to-end encryption using RSA 256 and TLS 1.3 standards. The service provider is required to comply with rigorous control standards and certifications, including ISO 27001, ISO/IEC 27017, and ISO 27018. Key technical security requirements include the implementation of Multi-Factor Authentication (MFA) for user identities across all protocols (Web, IMAP, SMTP, POP, and Calendar), the application of Geo-fencing and IP-based restrictions, and the use of industry standards and policies to combat email spoofing. The service is integrated with the NIC-CERT Security Information and Event Management (SIEM) system. Furthermore, the system requires Multi-Factor Authentication (MFA), mobile device management (MDM), and advanced threat protection mechanisms to prevent phishing, malware, and data loss (DLP). The contract with the service provider ensures strict adherence to data sovereignty. The service provider has ensured that the cloud-based solution, including Primary and Disaster Recovery data centers, are physically located within India, and no data can be shared or replicated outside the country. M/s Zoho is a registered Indian entity subject to Indian laws and jurisdiction. The contract emphasizes "Make in India" products, ensuring that the government’s digital communication infrastructure is sovereign, with the government retaining full ownership of all data and intellectual property created during the contract. The service is designed for high reliability, mandating a service availability uptime of at least 99.9% on a 24x7x365 basis.To ensure high reliability, the service provider is required to maintain Disaster Recovery sites in different seismic zones at least 500 kilometres apart, with strict Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) to minimize data loss during contingencies. Arattai, a messaging platform developed by M/s Zoho, is not part of the e-mail solution. This information was submitted by Union Minister of State for Electronics and Information Technology Shri Jitin Prasada in Rajya Sabha on 05.12.2025. *** MSZ (रलीज़ आईडी: 2199413) आगंतुक पटल : 655 इस वज्ञ को इन भाषाओ ंम पढ़: Urdu , ही

Continue your research