Home Services About Blog Contact
Compliance

IoT & Cybersecurity Compliance in India CERT-In, DPDP Act, and How It Maps to Global Standards

July 24, 2026 · 10 min read · CyberKartel Research Team · Compliance

If you're building, deploying, or securing connected products in India, the compliance landscape you actually operate under looks very different from the EU's Cyber Resilience Act or the US FDA framework. India has its own regulatory stack - and it's tightening fast.

Not Legal Advice

This article is a general overview and does not constitute legal advice. India's compliance landscape is evolving quickly - confirm current obligations with qualified counsel and official sources including cert-in.org.in, meity.gov.in, and the Data Protection Board of India.

The Foundation: IT Act, 2000

India's cybersecurity and data law traces back to the Information Technology Act, 2000 - the primary legislation governing electronic records, digital signatures, and cybercrime. Everything else in India's current compliance stack is built on top of it, most directly through Section 70B, which empowers CERT-In as the national nodal agency for cybersecurity incident response.

CERT-In Directions: The 6-Hour Rule

The single most consequential compliance obligation for organisations operating in India is the CERT-In Directions dated April 28, 2022 (effective June 27, 2022), issued under Section 70B of the IT Act.

What it requires: Mandatory reporting of cybersecurity incidents to CERT-In within 6 hours of noticing or becoming aware of the incident - not 6 hours from when the incident occurred. This applies across 20 categories of reportable incidents, including unauthorised access, data breaches, ransomware, DDoS attacks, and compromise of critical systems.

Who it applies to: This is broader than most people realise. The Directions cover service providers, intermediaries, data centres, corporate bodies, and government organisations - and critically, any entity providing services in India, whether incorporated domestically or abroad.

Other obligations under the same Directions: Maintain ICT system logs for a rolling 180-day period stored within India, synchronise system clocks to NTP servers maintained by NIC or NPL, and VPN/cloud/data centre operators must maintain KYC and subscriber records.

Penalties: Up to ₹1 lakh and imprisonment of up to 1 year under Section 70B(7). A pending amendment has proposed raising this fine to ₹1 crore, though it was not yet in effect as of early 2026.

The Practical Trap

The 6-hour clock starts from awareness, not from when the incident actually happened. If your detection-to-notification pipeline takes days rather than hours, you are structurally unable to comply, regardless of intent.

Digital Personal Data Protection Act, 2023 (DPDP Act)

India's answer to GDPR, and the other major compliance obligation reshaping how Indian organisations - and foreign companies serving Indian users - handle personal data.

Timeline (phased implementation):

Who it applies to: Any "data fiduciary" processing digital personal data in India - and, like GDPR, it has extraterritorial reach: foreign entities offering goods or services to individuals in India are covered too.

Penalties are severe: Up to ₹250 crore for failing to implement reasonable security safeguards to prevent a data breach. Up to ₹200 crore for failing to notify the Board or affected individuals. Lesser violations still carry penalties up to ₹50 crore.

Any connected device or platform collecting personal data from Indian users - which covers most consumer IoT - needs security safeguards that can withstand DPBI scrutiny well before the May 2027 deadline.

Sectoral Regulators: RBI, SEBI, IRDAI

Beyond the horizontal frameworks above, specific sectors carry additional, often stricter obligations:

IoT-Specific Rules: MeitY, STQC, and Essential Requirements

India has also started building IoT-specific technical requirements, distinct from general cybersecurity law. STQC Certification (Standardisation Testing & Quality Certification Directorate) introduced "Essential Requirements" for specific IoT categories, most notably CCTV and video surveillance systems, under the government's domestic manufacturing push. It's increasingly the gate for public safety and infrastructure-related connected devices, and for government and enterprise procurement more broadly.

NCIIPC (National Critical Information Infrastructure Protection Centre), established under Section 70A of the IT Act, has a separate mandate from CERT-In, focused specifically on formally designated Critical Information Infrastructure across power, telecom, banking, and government services.

CERT-In Empanelment: Who Actually Needs It

This is one of the most misunderstood parts of India's compliance landscape. CERT-In empanelment is not a general requirement for private companies to operate in India - it's a credential for the auditors themselves, and it's only mandatory in specific circumstances.

Empanelled auditors are legally required for: central and state government departments and PSUs; any system hosted on NIC infrastructure (requires a "Safe to Host" certificate); government tenders, where most RFPs specify empanelment as a bid qualification; formally designated Critical Information Infrastructure operators; and regulated private-sector entities specifically where their regulator mandates it - banks and NBFCs under RBI, SEBI-regulated intermediaries under CSCRF, and IRDAI-regulated insurers.

Not required for: most private companies - SaaS platforms, e-commerce, general enterprise software, and IoT manufacturers not selling into government or the regulated sectors above - can engage any competent, methodologically sound penetration testing provider.

The practical upshot: whether you need an empanelled auditor depends entirely on who your buyer is, not on the nature of your product.

How This Maps to the Global Frameworks You Might Already Know

Global Framework India Equivalent / Overlap
EU CRA (vulnerability reporting, SBOM) CERT-In Directions (6-hour incident reporting) - different mechanics, similar intent
GDPR DPDP Act, 2023 - similar structure, India-specific penalty scale and phased rollout
ISO 27001 Directly applicable in India as-is; increasingly requested by Indian enterprise buyers
IEC 62443 Directly applicable in India as-is; relevant for India's growing industrial IoT sector
FDA cybersecurity (medical devices) No direct Indian equivalent yet at the same technical depth - CDSCO governs medical devices generally

ISO 27001 and IEC 62443 travel well - implement them once, and they support both Indian and international positioning. CRA and FDA-specific requirements only matter if you're actually shipping into the EU or US markets. But CERT-In and DPDP are non-negotiable if you're operating in India at all.

A Practical Checklist for Indian IoT Companies

Where CyberKartel Fits

Compliance documentation tells you what you've promised. Independent testing tells you what's actually true. Whether you're preparing for a CERT-In-aligned security assessment, building a DPDP-ready security posture, or validating IEC 62443 alignment for an industrial IoT deployment, the gap between "documented" and "tested" is exactly where breaches happen.

If you're based in India and mapping your compliance obligations across CERT-In, DPDP, and any international frameworks your product touches, get in touch.

CYBERKARTEL RESEARCH TEAM