This article is a general overview and does not constitute legal advice. India's compliance landscape is evolving quickly - confirm current obligations with qualified counsel and official sources including cert-in.org.in, meity.gov.in, and the Data Protection Board of India.
The Foundation: IT Act, 2000
India's cybersecurity and data law traces back to the Information Technology Act, 2000 - the primary legislation governing electronic records, digital signatures, and cybercrime. Everything else in India's current compliance stack is built on top of it, most directly through Section 70B, which empowers CERT-In as the national nodal agency for cybersecurity incident response.
CERT-In Directions: The 6-Hour Rule
The single most consequential compliance obligation for organisations operating in India is the CERT-In Directions dated April 28, 2022 (effective June 27, 2022), issued under Section 70B of the IT Act.
What it requires: Mandatory reporting of cybersecurity incidents to CERT-In within 6 hours of noticing or becoming aware of the incident - not 6 hours from when the incident occurred. This applies across 20 categories of reportable incidents, including unauthorised access, data breaches, ransomware, DDoS attacks, and compromise of critical systems.
Who it applies to: This is broader than most people realise. The Directions cover service providers, intermediaries, data centres, corporate bodies, and government organisations - and critically, any entity providing services in India, whether incorporated domestically or abroad.
Other obligations under the same Directions: Maintain ICT system logs for a rolling 180-day period stored within India, synchronise system clocks to NTP servers maintained by NIC or NPL, and VPN/cloud/data centre operators must maintain KYC and subscriber records.
Penalties: Up to ₹1 lakh and imprisonment of up to 1 year under Section 70B(7). A pending amendment has proposed raising this fine to ₹1 crore, though it was not yet in effect as of early 2026.
The 6-hour clock starts from awareness, not from when the incident actually happened. If your detection-to-notification pipeline takes days rather than hours, you are structurally unable to comply, regardless of intent.
Digital Personal Data Protection Act, 2023 (DPDP Act)
India's answer to GDPR, and the other major compliance obligation reshaping how Indian organisations - and foreign companies serving Indian users - handle personal data.
Timeline (phased implementation):
- Phase 1 - November 13, 2025: Data Protection Board of India (DPBI) formally established
- Phase 2 - November 13, 2026: Consent Manager registration framework becomes operational
- Phase 3 - May 13, 2027: Full substantive compliance obligations become enforceable - notice requirements, 72-hour breach notification to the DPBI, data principal rights, security safeguard obligations
Who it applies to: Any "data fiduciary" processing digital personal data in India - and, like GDPR, it has extraterritorial reach: foreign entities offering goods or services to individuals in India are covered too.
Penalties are severe: Up to ₹250 crore for failing to implement reasonable security safeguards to prevent a data breach. Up to ₹200 crore for failing to notify the Board or affected individuals. Lesser violations still carry penalties up to ₹50 crore.
Any connected device or platform collecting personal data from Indian users - which covers most consumer IoT - needs security safeguards that can withstand DPBI scrutiny well before the May 2027 deadline.
Sectoral Regulators: RBI, SEBI, IRDAI
Beyond the horizontal frameworks above, specific sectors carry additional, often stricter obligations:
- RBI - Banks, NBFCs, and payment system operators face cybersecurity requirements under various Master Directions, including outsourcing and IT governance rules that specifically reference CERT-In empanelled auditors.
- SEBI - Market intermediaries operate under the Cybersecurity and Cyber Resilience Framework (CSCRF), with defined audit cycles and empanelled-auditor requirements.
- IRDAI - Insurers and intermediaries follow the IRDAI Information and Cyber Security Guidelines, covering continuous ICT monitoring, extended log retention, and rapid incident reporting to both IRDAI and CERT-In.
IoT-Specific Rules: MeitY, STQC, and Essential Requirements
India has also started building IoT-specific technical requirements, distinct from general cybersecurity law. STQC Certification (Standardisation Testing & Quality Certification Directorate) introduced "Essential Requirements" for specific IoT categories, most notably CCTV and video surveillance systems, under the government's domestic manufacturing push. It's increasingly the gate for public safety and infrastructure-related connected devices, and for government and enterprise procurement more broadly.
NCIIPC (National Critical Information Infrastructure Protection Centre), established under Section 70A of the IT Act, has a separate mandate from CERT-In, focused specifically on formally designated Critical Information Infrastructure across power, telecom, banking, and government services.
CERT-In Empanelment: Who Actually Needs It
This is one of the most misunderstood parts of India's compliance landscape. CERT-In empanelment is not a general requirement for private companies to operate in India - it's a credential for the auditors themselves, and it's only mandatory in specific circumstances.
Empanelled auditors are legally required for: central and state government departments and PSUs; any system hosted on NIC infrastructure (requires a "Safe to Host" certificate); government tenders, where most RFPs specify empanelment as a bid qualification; formally designated Critical Information Infrastructure operators; and regulated private-sector entities specifically where their regulator mandates it - banks and NBFCs under RBI, SEBI-regulated intermediaries under CSCRF, and IRDAI-regulated insurers.
Not required for: most private companies - SaaS platforms, e-commerce, general enterprise software, and IoT manufacturers not selling into government or the regulated sectors above - can engage any competent, methodologically sound penetration testing provider.
The practical upshot: whether you need an empanelled auditor depends entirely on who your buyer is, not on the nature of your product.
How This Maps to the Global Frameworks You Might Already Know
| Global Framework | India Equivalent / Overlap |
|---|---|
| EU CRA (vulnerability reporting, SBOM) | CERT-In Directions (6-hour incident reporting) - different mechanics, similar intent |
| GDPR | DPDP Act, 2023 - similar structure, India-specific penalty scale and phased rollout |
| ISO 27001 | Directly applicable in India as-is; increasingly requested by Indian enterprise buyers |
| IEC 62443 | Directly applicable in India as-is; relevant for India's growing industrial IoT sector |
| FDA cybersecurity (medical devices) | No direct Indian equivalent yet at the same technical depth - CDSCO governs medical devices generally |
ISO 27001 and IEC 62443 travel well - implement them once, and they support both Indian and international positioning. CRA and FDA-specific requirements only matter if you're actually shipping into the EU or US markets. But CERT-In and DPDP are non-negotiable if you're operating in India at all.
A Practical Checklist for Indian IoT Companies
- Confirm whether CERT-In Directions apply to you - if you have any Indian infrastructure, customers, or hosting, they almost certainly do.
- Build a real incident detection-to-notification pipeline that can hit 6 hours from awareness, not from occurrence.
- Start DPDP gap assessments now, even though full enforcement isn't until May 2027 - data mapping, consent flows, and security safeguards take longer than most teams expect.
- Check whether your buyer requires a CERT-In empanelled auditor before you commission a penetration test.
- If you're in industrial or infrastructure IoT, treat IEC 62443 alignment as an increasingly standard procurement expectation.
- If you sell internationally, layer India's requirements on top of - not instead of - CRA, FDA, or other market-specific obligations.
Where CyberKartel Fits
Compliance documentation tells you what you've promised. Independent testing tells you what's actually true. Whether you're preparing for a CERT-In-aligned security assessment, building a DPDP-ready security posture, or validating IEC 62443 alignment for an industrial IoT deployment, the gap between "documented" and "tested" is exactly where breaches happen.
If you're based in India and mapping your compliance obligations across CERT-In, DPDP, and any international frameworks your product touches, get in touch.