Executive Summary:
This document is a response to questions raised in Lok Sabha regarding cybersecurity concerns related to telecom components, particularly SIM cards of Chinese origin. The response outlines measures taken by the Government of India to ensure trusted telecom sourcing, including the implementation of the National Security Directive on the Telecommunication Sector (NSDTS) and continuous auditing of telecom components. It clarifies that there is no current plan for a nationwide SIM card replacement.
Key Points / Main Content:
* **Chinese Chipsets in SIM Cards:**
* The issue of Chinese chipsets is addressed under the National Security Directive for the Telecom Sector (NSDTS) based on evaluations from security agencies.
* Specific details regarding the inputs, deliberations, and conclusions are classified due to national security implications.
* **SIM Card Replacement:**
* No nationwide replacement of older SIM cards is being considered.
* **Trusted Sourcing and Auditing Measures:**
* The National Security Directive on Telecommunication Sector (NSDTS) was approved on December 16, 2020, mandating trusted products from trusted vendors for telecom entities.
* The Trusted Telecom Portal (trustedtelecom.gov.in) was launched to facilitate compliance with the NSDTS.
* License agreements have been amended, effective 15.06.2021, to require licensees to connect only Trusted Products as notified by the National Cyber Security Coordinator.
* Prior permission is required for upgrading or expanding networks with non-trusted Telecommunication Equipment.
* Licensees must submit half-yearly compliance reports via the Saral Sanchar Portal on January 1st and July 1st of each year.
* Audits are conducted by Licensed Service Area (LSA) field units of the Department of Telecommunications (DoT).
* Indian Telecommunication Security Assurance Requirements (ITSAR) were issued, setting baseline security requirements for telecom equipment, including SIM cards.
* Mandatory Testing and Certification of Telecom Equipment (MTCTE) scheme ensures compliance with Indian technical standards.
* A Standard Operating Procedure (SOP) for SIM personalization was issued in 2021.
* **eSIM Considerations:**
* Indian Telecommunication Security Assurance Requirements (ITSAR) have been released for eSIM.
* eSIM is covered under the Mandatory Testing and Certification of Telecom Equipment (MTCTE).
* The SOP for eSIM personalization is currently under process.
Impact Analysis:
* **Telecom Operators/Licensees:**
* *Impact:* Must procure and deploy only trusted products from trusted vendors. Must comply with the amended license agreements, including obtaining permission for network upgrades and submitting compliance reports.
* *Action Required:* Ensure compliance with the NSDTS, use the Trusted Telecom Portal, submit half-yearly compliance reports, and seek permission for network upgrades utilizing non-trusted equipment.
* **Consumers:**
* *Impact:* Indirectly affected through increased security measures and potentially higher costs for telecom services due to compliance requirements for operators.
* *Action Required:* No direct action required.
* **Government (Department of Telecommunications):**
* *Impact:* Responsible for enforcing the NSDTS, managing the Trusted Telecom Portal, conducting audits, and ensuring compliance.
* *Action Required:* Continue enforcing the NSDTS, managing the Trusted Telecom Portal, conducting audits, and refining security procedures (e.g., SOP for eSIM personalization).
Key Entities Referenced
National Cyber Security Coordinator: A government position or office responsible for coordinating national cybersecurity efforts in India. Referred to as NCSC.
National Security Directive for Telecom Sector: A directive issued by the National Cyber Security Coordinator (NSCS) related to national security in the telecommunications sector. Referred to as NSDTS.
National Security Committee on Telecom: A committee chaired by the Deputy National Security Advisor (NSA) responsible for evaluating security agencies' findings and implementing the National Security Directive for the Telecom Sector (NSDTS). Referred to as NSCT.
Union Cabinet: The council of ministers in the Government of India.
Department of Telecommunications: A department under the Ministry of Communications responsible for telecommunications policy and regulation in India. Referred to as DoT.
Trusted Telecom Portal: A portal launched by the Department of Telecommunications to facilitate compliance with the National Security Directive on the Telecommunication Sector. The URL is trustedtelecom.gov.in.
Indian Telecommunication Security Assurance Requirements: A set of baseline security requirements for telecom equipment issued by the Department of Telecommunications to ensure a secure and trusted communication infrastructure. Referred to as ITSAR.
Mandatory Testing and Certification of Telecom Equipment: A scheme that mandates telecom equipment be tested and certified to ensure compliance with Indian technical standards. Referred to as MTCTE.
GOVERNMENT OF INDIA
MINISTRY OF COMMUNICATIONS
DEPARTMENT OF TELECOMMUNICATIONS
LOK SABHA
UNSTARRED QUESTION NO. 2910
ANSWERED ON 6TH AUGUST, 2025
NATIONAL CYBER SECURITY COORDINATOR
2910. MS SAYANI GHOSH:
Will the Minister of COMMUNICATION be pleased to state:
(a) whether the Government is aware of recent findings by the National Cyber Security
Coordinator (NCSC) regarding the presence of chipsets of Chinese origin in certain mobile SIM
cards and if so, the number of such cases identified and the telecom operators or vendors involved;
(b) whether the Government is considering a nationwide replacement of older SIM cards due to
potential national security risks and if so, the details thereof;
(c) whether the Government has identified the techno-legal and financial implications of such a
replacement exercise for telecom operators and consumers and if so, the details thereof;
(d) the steps taken by the Government to strengthen the trusted sourcing and continuous auditing
of telecom components including SIM cards, to prevent unauthorised or unapproved imports; and,
(e) whether the Government is considering utilising the eSIM (embedded SIM) in order to avoid
cybersecurity threats and reliance on Chinese imports and if so, the details thereof?
ANSWER
MINISTER OF STATE FOR COMMUNICATIONS AND RURAL DEVELOPMENT
(DR. PEMMASANI CHANDRA SEKHAR)
(a) It has been informed by NSCS that the issue raised in question mentioning “National Cyber
Security Coordinator" pertains to the implementation of the National Security Directive for Telecom
Sector (NSDTS) issued by NSCS is implemented based on evaluations from security agencies by the
National Security Committee on Telecom (NSCT) chaired by Deputy NSA. The inputs, deliberations
and the basis for the conclusions are classified as secret and have national security implications.
(b) Currently, no nationwide replacement of older SIM cards is being considered.
(c) In view of reply to part (b), the question does not arise.
(d) Steps taken by the Government to strengthen trusted sourcing and continuous auditing of
telecom components to prevent unauthorized or unapproved imports are as follows:
1i. The National Security Directive on Telecommunication Sector (NSDTS) was
approved by the Union Cabinet on December 16, 2020. It mandates that all the
Telecommunication entities in India must procure and deploy only “trusted
products” sourced from “trusted vendors” to safeguard national security. The
Department of Telecommunications launched the Trusted Telecom Portal
(trustedtelecom.gov.in) to facilitate compliance.
ii. The Government has amended various License Agreements, including the Unified
License (UL), UL (VNO), Unified Access Service License, and Standalone
Licenses, to incorporate a specific condition related to the procurement and
installation of Telecommunication Equipment by licensees in their networks. This
condition mandates that, with effect from 15.06.2021, licensees are permitted to
connect only Trusted Products—as notified by the Designated Authority (i.e., the
National Cyber Security Coordinator) on the Trusted Telecom Portal—in their
networks. Licensees must also obtain prior permission from the Designated
Authority for any upgradation or expansion of existing networks using
Telecommunication Equipment not designated as Trusted Products. Further, to
ensure compliance with the above provisions, all licensees are required to submit
a half-yearly compliance report through the Saral Sanchar Portal on 1st
January and 1st July of each year. In addition, audits of telecom entities are
conducted by the Licensed Service Area (LSA) field units of the Department
of Telecommunications (DoT) to ensure adherence to the prescribed guidelines.
iii. The Department of Telecommunications (DoT) has issued Indian
Telecommunication Security Assurance Requirements (ITSAR)—a set of
baseline security requirements for telecom equipment to ensure a secure and
trusted communication infrastructure—which cover all Pluggable (U)ICC,
including SIM, USIM, and other (U)ICC-based applications/applets.
Additionally, SIM cards are covered under the Mandatory Testing and
Certification of Telecom Equipment (MTCTE)—a scheme that mandates telecom
equipment be tested and certified to ensure compliance with Indian technical
standards. Furthermore, in 2021, DoT has also issued a Standard Operating
Procedure (SOP) specifically for SIM personalization to ensure trusted sourcing
and continuous auditing of telecom components.
(e) The Department of Telecommunications (DoT) has released Indian Telecommunication
Security Assurance Requirements (ITSAR) for eSIM, and it is also covered under the Mandatory
Testing and Certification of Telecom Equipment (MTCTE). The SOP for eSIM personalization is
currently under process.
*****
2