India’s Cyber Security Framework
Institutional Architecture
The simplest way to understand the architecture is to classify the problem before naming the institution. A malware outbreak requires technical response; a disabling risk to an essential system requires critical-infrastructure protection; an online fraud requires police investigation and fund-interdiction; espionage requires intelligence coordination; and hostile action against military networks belongs to the defence domain.
| Strategic coordination | Situational awareness | Asset protection | Incident response | Crime response | Military operations |
| NCSC under NSCS | NCCC and sectoral feeds | NCIIPC, regulators and operators | CERT-In and CSIRTs | I4C with State/UT police | Defence Cyber Agency and Service structures |
India’s distributed cyber architecture — The route depends on whether the problem is coordination, protection, response, crime or military operations.
These compartments are connected. The same intrusion may begin as an incident handled by a sectoral response team, reveal a protected-system risk requiring NCIIPC, contain criminal evidence for State police and I4C, and carry national-security implications for intelligence or defence agencies. The institutional task is therefore leadership without isolation and cooperation without mandate confusion.
CERT-In and the 2022 Directions
The Indian Computer Emergency Response Team (CERT-In) is the national agency for cyber-security incident response under Section 70B of the Information Technology Act, 2000. It is neither a police station nor the owner of every affected network. Its distinctive function is to create a national response layer above individual organisations and sector teams.
| Statutory function | Operational meaning |
| Collection, analysis and dissemination of incident information | Combine reports and technical indicators so that one victim’s discovery can protect other potential victims. |
| Forecasts and alerts | Warn organisations of vulnerabilities, campaigns and threat patterns before or during exploitation. |
| Emergency measures | Provide technical measures and coordinated action when rapid containment is required. |
| Coordination of response activities | Connect affected entities, service providers, sector teams and relevant government bodies. |
| Guidelines, advisories, vulnerability notes and white papers | Convert observed threats into preventive and remedial practices. |
Under Section 70B(6), CERT-In may call for information and issue directions to service providers, intermediaries, data centres, bodies corporate and other persons for performing its statutory functions. Failure to supply the called-for information or comply with such a direction attracts the consequence in Section 70B(7). The power is therefore more than advisory, although its purpose remains incident prevention and response.
The directions dated 28 April 2022 converted several response expectations into specific, generally applicable duties:
Six-hour reporting: specified cyber incidents must be reported to CERT-In within six hours of noticing them or being brought to notice. An available initial report may be supplemented as information develops.
Time synchronisation: covered entities must connect system clocks to an approved or traceable time source so that logs from different systems can be correlated reliably.
Logging: service providers, intermediaries, data centres, bodies corporate and government organisations must enable ICT-system logs, retain them securely for a rolling period of 180 days, maintain them within Indian jurisdiction and furnish them when lawfully required.
Point of contact: an entity must designate a contact for CERT-In communications and directions, reducing delay during an incident.
Subscriber records: data centres, Virtual Private Server providers, cloud-service providers and Virtual Private Network service providers must register specified validated customer information and retain it for five years or longer where law requires after cancellation or withdrawal of registration.
Virtual-asset records: covered virtual-asset service providers, exchanges and custodian wallet providers must maintain KYC and financial-transaction records for the prescribed period under the relevant legal framework.
| Detect | Contain | Notify | Coordinate | Recover | Learn |
| Identify abnormal activity and preserve volatile evidence | Limit spread without destroying evidence | Initial report to CERT-In within the applicable timeline | Share indicators and seek sectoral or law-enforcement support | Restore clean services by consequence priority | Root-cause analysis, control repair and sector warning |
Incident-response sequence — Six-hour reporting is an early signal, not a demand for a completed forensic report.
The six-hour rule should be interpreted as early notification, not as a completed root-cause analysis. A mature organisation reports the known facts, affected services, preliminary indicators and containment status, then updates the record. Waiting for certainty sacrifices collective warning; reporting speculation as fact creates a different risk. Good incident governance records confidence levels and changes over time.
| What the directions improve | What remains difficult |
| Faster national warning and earlier sharing of indicators. | The moment of ‘noticing’ may be operationally contested, especially where alerts require validation. |
| Forensic quality through logs and synchronised time. | Continuous logging and local retention impose cost, capacity and security burdens, particularly on smaller entities. |
| Attribution support through provider and subscriber records. | Large retained datasets themselves require strict access control, purpose limitation and audit. |
| Clearer contact and escalation during a crisis. | Reporting is valuable only if alerts are de-duplicated, prioritised and converted into timely action. |
| CURRENT STATUS (AS OF AUGUST 2026) The CERT-In Directions of 28 April 2022 remain published and operative. CERT-In continues to function under Section 70B and now works through a wider network of sectoral and State/UT computer-security incident response teams. The directions must not be confused with the separate Guidelines on Information Security Practices for Government Entities, which impose a broader governance and audit baseline on government organisations. |
NCIIPC; National Cyber Coordination Centre; Cyber Swachhta Kendra
Three institutions that are often placed in one list actually solve different problems. NCIIPC concentrates on the resilience of critical information infrastructure; the National Cyber Coordination Centre (NCCC) creates network-level situational awareness; and the Cyber Swachhta Kendra (CSK) detects botnet or malware infection and supports remediation. The statutory foundations of critical infrastructure have already been developed; the focus here is functional division of labour.
| Institution | Primary problem | Core output | What it is not |
| NCIIPC | A computer resource whose incapacitation or destruction could have a debilitating national impact. | CII identification, protection guidance, coordination, threat information and assurance support. | Not the general portal for every cyber complaint or ordinary fraud. |
| NCCC | Fragmented visibility of existing and potential threats across Indian cyberspace. | Metadata-level monitoring, situational awareness and sharing with concerned organisations, States and agencies. | Not a substitute for an operator’s security operations centre or an investigating police unit. |
| Cyber Swachhta Kendra | Compromised end-user or organisational devices participating in botnets, carrying malware or exposing vulnerable services. | Detection notifications, cleaning tools, remedial advice and cyber-hygiene support in collaboration with service providers and industry. | Not an antivirus guarantee and not a mechanism for registering an FIR. |
The NCCC, implemented by CERT-In, examines cyberspace at the metadata level to detect potential threats and facilitate timely action. Metadata can reveal patterns such as malicious infrastructure, unusual traffic relationships or coordinated scanning without necessarily being the content of a message. Yet even metadata can be revealing. Its legitimate security value must therefore be accompanied by lawful purpose, access control, retention discipline and institutional oversight.
The Cyber Swachhta Kendra, also operated through CERT-In, reflects a public-health model of cyber security. An infected device harms not only its owner; it can send spam, attack other systems or participate in a botnet. Detection, notification through participating providers, safe cleaning tools and user education reduce this externality. The limit is behavioural: a cleaned device can be reinfected if unsupported software, weak passwords or unsafe installation practices remain unchanged.
| MAINS DISTINCTION Remember the verbs: NCCC sees patterns; CERT-In coordinates response; CSK cleans infections; NCIIPC protects high-consequence systems. A strong answer assigns the correct verb before naming the body. |
A persistent weakness is the last-mile conversion of warning into remediation. An alert may reach several nodal officers but still fail to produce patching, isolation or executive action. India therefore needs common severity levels, machine-readable threat exchange, service-level commitments for remediation and closure evidence that can be audited without exposing operational secrets.
| CURRENT STATUS (AS OF AUGUST 2026) NCCC is operational and implemented by CERT-In; current official descriptions state that it monitors cyberspace at the metadata level for situational awareness and shares relevant information with organisations, State governments and other stakeholders. CSK continues as CERT-In’s Botnet Cleaning and Malware Analysis Centre, while NCIIPC remains the specialised CII body under the technical-intelligence establishment. |
Indian Cyber Crime Coordination Centre (I4C) and Its Verticals — NCRP, CFMC, Samanvay and Sahyog
The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs addresses cybercrime as a policing and criminal-justice problem. It supports prevention, reporting, analysis, capacity building, forensics and inter-jurisdictional coordination. It does not displace State police: Police and Public Order are State subjects, and investigation, FIR registration, prosecution and victim communication remain primarily with State and Union Territory law-enforcement agencies.
I4C began as a central-sector scheme and was set up as an Attached Office of the Ministry of Home Affairs with effect from 1 July 2024. Its newer platforms should be understood as an operational pipeline rather than a list of websites.
| Platform or mechanism | Purpose | Operational caution |
| National Cyber Crime Reporting Portal (NCRP) and helpline 1930 | Citizen reporting of cybercrime; rapid intake of financial-fraud complaints and routing to the relevant law-enforcement system. | A portal complaint is not automatically an FIR. Speed, complete transaction details and follow-up with the competent police unit remain important. |
| Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) | Connects law enforcement, banks and financial intermediaries to place rapid holds on suspected fraud proceeds reported through the system. | A hold prevents onward movement where funds remain traceable; it is not an automatic finding of guilt or a guaranteed refund. |
| Cyber Fraud Mitigation Centre (CFMC) | Co-locates or connects representatives of banks, financial intermediaries, payment aggregators, telecom providers, IT intermediaries and State/UT law enforcement for immediate coordination. | CFMC is the collaborative centre; it should not be confused with the CFCFRMS transaction-interdiction workflow. |
| Samanvay Platform | A web-based Joint Cybercrime Investigation Facilitation System for data repository, sharing, crime mapping, analytics and inter-State cooperation. Official materials also render the name as ‘Samanvaya’. | Analytics indicate links for investigation; they do not replace admissible evidence, jurisdictional procedure or human verification. |
| Sahyog Portal | Centralised issuance of notices by authorised government agencies to intermediaries under Section 79(3)(b) for information used to commit an unlawful act. | Standardised transmission improves speed and traceability, but every notice still requires lawful authority, a reasoned basis and respect for constitutional limits. |
The underlying logic is compress the golden hour. Online financial fraud proceeds can move through several mule accounts and service providers within minutes. Rapid reporting through 1930 or NCRP, real-time bank coordination, identifier analysis and State police action increase the chance of interruption. The operational chain is:
| Victim reports | Transaction is traced | Funds or identifiers are flagged | Jurisdictional police act | Evidence and restitution process follow |
| 1930 or NCRP captures the complaint and transaction details | Banks and intermediaries identify the movement path | Available balances, accounts, SIMs or devices may be acted upon under lawful process | Complaint is converted into the appropriate criminal process and investigation | Records are preserved, accused are identified and court-regulated outcomes follow |
Central platforms produce scale, but federal execution determines outcomes. Delays may arise from incomplete complaints, multiple jurisdictions, inconsistent freezing practice, insufficient forensic capacity, language barriers and difficulty obtaining information from foreign platforms. Automated suspicion can also inconvenience innocent account holders.
Rapid interdiction must therefore be followed by time-bound review, speaking orders where required and accessible grievance mechanisms.
| CURRENT STATUS (AS OF AUGUST 2026) I4C operates as an Attached Office of the Ministry of Home Affairs. NCRP and helpline 1930, CFCFRMS, CFMC, Samanvay/Samanvaya and Sahyog are operational elements of the present architecture. Sahyog’s role is specifically tied to notices under Section 79(3)(b); it is not an independent source of content-blocking power. Recent financial-fraud analytics and bank coordination developed earlier should be read as part of this same prevention-to-investigation chain. |
Defence Cyber Agency; NTRO; State Cyber Cells and Cyber Police Stations
National cyber security includes at least three different coercive functions: military cyber operations, technical intelligence and criminal investigation. Their objectives, evidentiary standards and oversight cannot be treated as interchangeable.
| Body or level | Core domain | Typical contribution | Boundary |
| Defence Cyber Agency | Armed Forces and military cyber operations. | Tri-service coordination, defence-network posture, exercises and development of operational capability under the defence establishment. | It is not the investigating agency for ordinary civilian cybercrime. |
| National Technical Research Organisation (NTRO) | Technical intelligence and strategic technical capabilities. | Specialised technical support within the national-security system; NCIIPC is located under this establishment. | Its detailed operational mandate and methods are not publicly available and should not be invented. |
| State cybercrime cell | Specialised assistance within the State police system. | Complaint triage, technical analysis, investigation support, liaison, awareness and coordination with districts or specialised units. | A cell’s exact legal and investigative powers depend on State organisation and notified jurisdiction. |
| Cyber police station | Registration and investigation of offences within the assigned territorial or subject jurisdiction. | FIR, search, seizure, digital-evidence procedure, arrest where lawful, case diary and charge-sheet functions. | Technical complexity does not remove ordinary criminal-procedure safeguards. |
The Defence Cyber Agency emerged from the need for joint action across the Army, Navy and Air Force. Cyber operations do not respect Service boundaries: malware in a shared network, satellite link, logistics platform or contractor environment may affect joint operations. A tri-service agency promotes common doctrine, exercises, capability development and operational coordination. Each Service also retains its own structures and computer emergency response functions.
The publicly acknowledged role of NTRO is that of a technical-intelligence organisation, with NCIIPC placed under it. This supports high-end analysis and protection of national assets, but public notes should remain at the institutional level. Force strength, operational access, offensive capability and classified methods should neither be guessed nor presented as settled fact.
State capacity is the citizen-facing foundation. A well-designed model places a capable cyber cell at the State level, specialised or regional cyber police stations where caseload warrants, and trained cyber first responders in ordinary police stations. Every station need not reproduce a high-end laboratory; every station must know how to receive a complaint, preserve a device and account trail, trigger the rapid-fraud workflow, and reach expert support without delay.
Priority reforms for State and district execution include:
Standard first-response kits for volatile data, device seizure, account requests, cloud evidence and chain of custody.
Regional forensic capacity with quality assurance, validated tools and manageable case backlogs.
Specialised prosecutors and judicial training so that technically sound investigation becomes legally admissible proof.
Victim-centred communication, especially during account holds, intimate-image abuse, child victimisation and cross-State transfer of complaints.
Interoperable case and intelligence systems with role-based access, logging and clear data-retention rules.
| CURRENT STATUS (AS OF AUGUST 2026) The Defence Cyber Agency is officially described as fully functional and has continued to expand its capability within the tri-service structure. I4C and central assistance supplement—not replace—State/UT responsibility for cybercrime. The exact number, jurisdiction and maturity of cyber cells and cyber police stations varies by State and should not be reduced to an unverified national count. |
National Cyber Security Coordinator — Role and Limits
The National Cyber Security Coordinator (NCSC) functions under the National Security Council Secretariat (NSCS) to coordinate among agencies at the national level. The office responds to a structural reality: no single ministry owns cyberspace, yet a serious incident may simultaneously affect telecom, finance, power, policing, intelligence, defence and foreign policy.
| Coordinating role | Why it matters |
| Strategic coherence | Align the national threat picture, policy priorities, preparedness and cross-government action. |
| Inter-agency convening | Bring together bodies that possess different information, legal powers and operational capabilities. |
| Crisis-level escalation | Ensure that a sector incident with national consequences receives attention beyond the affected operator or ministry. |
| Exercises and preparedness | Test senior decision-making, information sharing and continuity before an actual crisis. |
| Strategy development | Steer an integrated national cyber-security strategy across departmental boundaries. |
Coordination is not the same as command. The NCSC is not publicly established as the regulator of all digital activity, the national incident-response team, a police agency, the CII operator or the military cyber commander. It generally cannot compensate for an operator that lacks asset visibility, a regulator that does not enforce, or a police unit that cannot obtain evidence. Its effectiveness depends on timely information, convening authority, clear escalation triggers and compliance by mandate-holding institutions.
A distributed system can be efficient if it follows centralised intent and decentralised execution. Strategic objectives, severity levels, information formats and crisis thresholds should be common; technical remediation and investigation should remain with the entity that has legal authority and operational knowledge. This avoids both fragmentation and a slow central bottleneck.
| CRITICAL ASSESSMENT India’s architecture is institution-rich but mandate-fragmented. The solution is not automatically another agency. It is a public responsibility matrix: who leads each incident class, who must be consulted, what information is shared, when escalation occurs, and who verifies closure—supported by privacy, audit and legislative oversight appropriate to the power exercised. |
A stronger coordination model would include:
a national cyber common operating picture that distinguishes technical indicators, criminal intelligence and classified information by access level;
a published responsibility matrix for major incident classes and centre–State escalation;
interoperable reporting between CERT-In, sector regulators, NCIIPC, I4C and State teams, with a single report reused lawfully rather than repeatedly recreated;
annual national and sector exercises that test executive decisions, public communication and cross-border service-provider dependencies; and
outcome metrics—time to detect, contain, restore and remediate—rather than only counts of alerts, meetings or training programmes.
| CURRENT STATUS (AS OF AUGUST 2026) Current official descriptions continue to place the NCSC under NSCS with the function of ensuring coordination among agencies. Public material does not establish the office as a single statutory cyber regulator or disclose a comprehensive coercive mandate. Its role should therefore be described accurately as strategic coordination, not operational control of every institution. |
Policy and Legal Framework
Institutions answer who acts; law answers with what authority and subject to which limits. India’s framework is layered rather than codified in one cyber-security statute. The Information Technology Act provides the horizontal backbone; data protection and telecommunications have dedicated laws; intermediary, interception and blocking rules operationalise powers; and sector regulators impose risk-specific controls.
| Constitutional limits | Primary statutes | Delegated rules | Directions and sectoral norms | Institutional enforcement |
| Legality, necessity, proportionality, speech, privacy and due process | IT Act, DPDP Act and Telecommunications Act | Intermediary, interception, blocking, data-protection and telecom rules | CERT-In directions plus RBI, SEBI, IRDAI and other sector requirements | Courts, tribunals, regulators, CERT-In, Board and police within their mandates |
The legal stack — A policy expresses direction; an Act creates authority; rules and directions convert it into operational duties.
Three categories must be separated in a Mains answer. A policy is a statement of national intent and priorities; a statute creates legal rights, powers, duties and penalties; and a direction or regulation supplies enforceable operational detail within delegated authority. Calling all three ‘laws’ hides important differences in accountability and remedy.
Information Technology Act, 2000 — Sections 43A, 66, 69, 69A, 70 and 79; the Shreya Singhal Legacy
The Information Technology Act, 2000, substantially amended in 2008, performs several jobs at once: it recognises electronic transactions, creates computer-related offences and civil contraventions, empowers interception and blocking, protects notified systems, establishes incident-response functions and conditions intermediary safe harbour. Its breadth gives India a common digital-law backbone, but also makes the statute conceptually crowded.
| Provision | Legal function | UPSC-ready significance |
| Section 43A | Compensation where a body corporate negligently fails to maintain reasonable security practices for sensitive personal data or information and thereby causes wrongful loss or wrongful gain. | A negligence-and-compensation bridge under the older data regime; its present transitional status is explained below. |
| Section 66 | Criminalises acts referred to in Section 43 when done dishonestly or fraudulently; punishment may extend to three years, fine up to ₹5 lakh, or both. | Do not reduce it to the loose label ‘hacking’: the mental element and the Section 43 act must both be shown. |
| Section 69 | Permits the Central or State Government, through authorised process and recorded reasons, to direct interception, monitoring or decryption on specified grounds; assistance may be compelled. | A security and investigation power bounded by statutory grounds, prescribed procedure and constitutional necessity and proportionality. |
| Section 69A | Permits the Central Government to block public access to information on specified national-security and public-order grounds through prescribed safeguards. | Blocking is distinct from interception. Non-compliance by an intermediary may attract imprisonment up to seven years and fine. |
| Section 70 | Allows the appropriate Government to notify a computer resource affecting critical information infrastructure as a protected system and control authorised access. | Criticality and notification are separate: not every important system is automatically a protected system. |
| Section 79 | Creates conditional safe harbour for third-party information where the intermediary’s role and conduct meet statutory requirements, including due diligence. | It is immunity from liability in specified circumstances, not a licence to ignore unlawful use or a rule that makes platforms generally liable for user speech. |
Section 69 concerns access to information for interception, monitoring or decryption. It requires a competent governmental decision on enumerated grounds, reasons in writing and the prescribed safeguards. A subscriber, intermediary or person in charge may be required to provide access, technical assistance or stored information; failure to assist may attract imprisonment up to seven years and fine. The provision must be applied consistently with privacy and proportionality.
Section 69A is a different power: it concerns blocking information from public access. The Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 provide the procedure. Secret or urgent proceedings may sometimes be justified by security needs, but opacity can make erroneous restriction difficult to challenge. Reasoned decision-making, review and a meaningful route to judicial scrutiny remain essential.
| CASE LAW — SHREYA SINGHAL V. UNION OF INDIA In Shreya Singhal v. Union of India (2015), the Supreme Court struck down Section 66A in its entirety for violating freedom of speech; it did not merely ‘repeal’ the provision. The Court upheld Section 69A and the Blocking Rules because of their structured safeguards. It also read ‘actual knowledge’ in Section 79(3)(b) consistently with a court order or valid government notification concerning unlawful material, preventing private complaints alone from becoming a general command to decide legality. |
The judgment’s deeper legacy is a constitutional method for digital regulation: distinguish discussion, advocacy and incitement; demand clear legal standards; and avoid vague speech offences that encourage self-censorship. At the same time, safe harbour remains conditional. An intermediary that participates in unlawful conduct or fails to observe legally valid due diligence cannot claim neutrality as an absolute defence.
| CURRENT STATUS (AS OF AUGUST 2026) Section 43A remains operative during the DPDP transition. The notification commencing the DPDP framework brings the omission of Section 43A under Section 44(2) of the Digital Personal Data Protection Act, 2023 into force only after eighteen months from publication—on the scheduled timeline in May 2027. Section 66A remains unconstitutional and unenforceable; it was struck down, not legislatively repealed. |
Information Technology Rules, 2021 and Subsequent Amendments — Intermediary Due Diligence and Grievance Appellate Committees
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 operationalise due diligence under Section 79 and create separate obligations for intermediaries, significant social media intermediaries, online gaming intermediaries, digital-news publishers and online curated-content publishers. For internal security, the central issue is the intermediary layer: how to preserve an open communication system while requiring responsible response to unlawful use.
| Layer | Principal obligation |
| All intermediaries | Publish rules, privacy policy and user agreement; inform users of prohibited use; secure systems; preserve specified records; cooperate with lawful requests; report cyber incidents; and maintain a grievance mechanism. |
| Grievance Officer | Acknowledge and resolve user complaints within the applicable timelines, with specially accelerated treatment for intimate imagery, impersonation and similar serious harms. |
| Significant social media intermediary | Appoint a resident Chief Compliance Officer, 24×7 nodal contact and Resident Grievance Officer; publish monthly compliance reports; maintain a physical contact address; and perform additional prescribed due diligence. |
| Messaging service within the significant category | Enable identification of the first originator only on the specified judicial or Section 69 process, for serious enumerated purposes, where less intrusive means are ineffective; the rule does not itself require disclosure of message content. |
| Grievance Appellate Committee (GAC) | Provides a digital appeal against a Grievance Officer’s decision or non-resolution; appeal may be filed within thirty days and the Committee endeavours to conclude it within thirty calendar days. |
The 2022 amendment introduced the GAC mechanism and placed a government-appointed appellate layer above platform grievance officers. It expands access to redress without forcing every user immediately into court. Its legitimacy, however, depends on independence, reasoned orders, procedural fairness, consistency and transparency. An executive appellate body should not become a substitute for judicial review or an informal censorship channel.
The safe-harbour bargain creates competing incentives. If platforms face no duty, harmful content and criminal coordination may persist. If deadlines are unrealistically short or legal categories vague, platforms may remove lawful speech to minimise risk. The correct assessment therefore asks whether a rule combines clear triggering authority, specific content identification, proportionate timelines, preservation of evidence, notice where feasible, appeal and public accountability.
| CURRENT STATUS (AS OF AUGUST 2026) The consolidated intermediary rules incorporate amendments of 2022, 2023, October 2025 and February 2026. The February 2026 amendment, effective from 20 February 2026, introduced duties concerning Synthetically Generated Information, visible labelling and technical provenance, and tightened several response timelines: valid court or authorised-government takedown orders under Rule 3(1)(d) are to be acted upon within three hours; ordinary grievance resolution is generally seven days; and qualifying intimate-image or impersonation complaints receive a two-hour response window. Three GACs continue under the notified structure. Separate proposals circulated for consultation in 2026 must not be presented as enacted rules unless finally notified. |
The 2026 synthetic-content duties address real risks from deepfakes, cloned voices and deceptive audio-visual material. Yet automated detection is probabilistic, provenance can be stripped outside compliant systems, and a visible label may be mistaken for a judgment that content is false. Strong implementation therefore needs technical standards, human review, accessibility, appeals and periodic assessment of false positives, bias and impact on privacy and speech.
National Cyber Security Policy, 2013 — Critical Evaluation
The National Cyber Security Policy, 2013 (NCSP) was India’s first umbrella statement dedicated to a secure and resilient cyberspace. Its vision—security for citizens, businesses and government—was broad enough to move cyber security from a narrow technical function to a national governance concern.
| Policy pillar | Enduring value | Implementation question |
| Secure cyber ecosystem | Treats trust, resilience and organisational security policy as conditions for digital growth. | Who owns compliance, and how are outcomes measured across public and private sectors? |
| National and sectoral response | Recognises 24×7 warning, incident response, crisis management and sector coordination. | Are reporting systems interoperable and remediation obligations enforceable? |
| Critical information infrastructure | Places resilience of high-consequence systems at the centre of national policy. | Have all essential dependencies, vendors and cross-sector cascades been mapped? |
| Assurance and testing | Promotes standards, audits, product testing and security by design. | Do audits measure real attack paths and closure, or only checklist compliance? |
| Capacity, research and indigenous capability | Recognises people, R&D, trusted products and skill development as strategic assets. | Are time-bound targets supported by funding, quality measures and retention pathways? |
| Public–private and international cooperation | Accepts that most infrastructure and threat information lie across institutional boundaries. | Are confidentiality, liability and action protocols clear enough for rapid sharing? |
The policy’s strongest contribution was agenda creation. It anticipated the need for national coordination, CII protection, sectoral mechanisms, CISOs, dedicated security budgets, assurance frameworks, workforce development, public–private cooperation and a dynamic legal environment. Several later institutions and practices are consistent with this agenda.
Its principal weakness is that it is aspirational rather than an accountable implementation compact. Responsibilities, financing, milestones, measurable outputs and consequences for non-performance are often unclear. A target to create 500,000 skilled professionals within five years was a time-bound 2013 objective; it should not be repeated as a present workforce count or continuing target without evidence of outcome and quality.
The technology context has also changed. The policy predates today’s scale of cloud concentration, ransomware-as-a-service, software-supply-chain compromise, pervasive mobile payments, 5G, large Internet of Things deployments, generative AI, deepfakes and the current data-protection framework. The problem is not that a policy failed to predict every technology; it is that a national cyber framework needs scheduled review and adaptable implementation instruments.
NCSP provides a national ecosystem but is not a military doctrine. Defence requires separate command relationships, protected networks, doctrine, exercises, indigenous capability and civil–military coordination. The later operationalisation of the Defence Cyber Agency partially strengthens that institutional dimension, but does not cure the policy’s wider accountability gaps.
| CURRENT STATUS (AS OF AUGUST 2026) NCSP 2013 remains the published national cyber-security policy and has been supplemented by the IT Act framework, CERT-In directions, NCIIPC and NCCC mechanisms, I4C, the DPDP framework, telecom legislation and regulator-specific norms. No publicly notified comprehensive successor strategy has displaced it. Its continuing value is conceptual; its age makes an integrated, measurable successor urgent. |
| MAINS ANSWER FRAME For a critical evaluation, write: historic contribution → enduring pillars → implementation and accountability deficits → changed threat environment → evidence of institutional progress → need for a measurable successor strategy. Avoid the extreme claims that the policy achieved nothing or that the existence of institutions proves complete implementation. |
The Pending National Cyber Security Strategy — Has India Developed a Comprehensive Strategy?
A policy states broad intent; a strategy connects ends, ways and means. A comprehensive cyber-security strategy should identify national objectives, allocate leadership, prioritise risks, assign resources, define legal and technical instruments, establish time-bound outcomes and provide a review cycle. By that standard, India has many strategic components but has not yet publicly completed the unifying document.
| Strategic element | India’s substantive building block | Remaining integration gap |
| Governance | NCSC, CERT-In, NCIIPC, I4C, sector regulators, defence structures and State units. | A public mandate map, escalation matrix and measurable ownership across bodies. |
| Risk and CII | Protected-system law, NCIIPC guidance, sector norms and exercises. | Dynamic dependency mapping, supply-chain assurance and minimum resilience outcomes across sectors. |
| Incident response | CERT-In, NCCC, CSIRTs, six-hour reporting and crisis-management arrangements. | One interoperable reporting architecture and closure verification across national, sectoral and State layers. |
| Cybercrime | I4C, NCRP, 1930, CFCFRMS, CFMC, analytics and State investigation. | Uniform first response, forensic quality, cross-border evidence speed and victim-centred review. |
| Defence and deterrence | Defence Cyber Agency, Service CERTs and national-security coordination. | Publicly articulable doctrine on thresholds, resilience and accountability without revealing operations. |
| People and technology | Training, exercises, R&D and indigenous-product initiatives. | Workforce-quality metrics, career pathways, procurement assurance and sustained research investment. |
| Rights and trust | Judicial doctrine, data-protection law, sector safeguards and grievance mechanisms. | Integrated privacy, speech, surveillance, transparency and redress principles across cyber powers. |
The most accurate answer to the 2022 Mains question is therefore qualified. India has developed an extensive strategic ecosystem: legal powers, specialist agencies, critical-infrastructure protection, national incident response, cybercrime coordination, sector regulation and defence capacity. However, the ecosystem is fragmented across instruments and lacks a publicly approved, integrated strategy with common metrics, resource priorities and transparent accountability.
| CURRENT STATUS (AS OF AUGUST 2026) The Government has formulated a draft National Cyber Security Strategy. The latest publicly verifiable parliamentary status states that it remains under process for approval; a revised draft had been circulated among concerned ministries and was being considered at the national level. It is therefore incorrect to present the proposed 2020-era pillars as an adopted or operational national strategy. |
A credible final strategy should contain:
a five-year risk assessment with annual public and classified review layers;
named lead and supporting institutions for each mission, supported by a statutory and executive mandate map;
minimum resilience outcomes for essential services—safe degraded operation, maximum recovery time, tested backups and supply-chain assurance;
a centre–State capability plan with district first response, regional forensics and interoperable platforms;
a national workforce, R&D and trusted-procurement mission linked to quality and deployment rather than training counts alone;
clear principles for defence, intelligence, law enforcement, private-sector cooperation and cross-border response; and
rights safeguards, audit, legislative oversight and measurable public reporting that preserve trust without disclosing exploitable operational detail.
| ONE-LINE JUDGEMENT India is capability-rich and strategy-fragmented: it possesses many elements of comprehensive cyber security, but they require an approved, resourced and measurable national strategy to operate as one system. |
Justice B. N. Srikrishna Committee Report — Strengths and Weaknesses
The Committee of Experts chaired by Justice B. N. Srikrishna submitted A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians and a draft Personal Data Protection Bill in 2018.
Its central insight was relational: an individual cannot realistically bargain as an equal with every State or commercial entity that collects data. The data controller should therefore carry fiduciary-like duties of fairness, purpose limitation, security and accountability.
| Recommendation or principle | Why it was significant |
| Data principal and data fiduciary | Shifted the vocabulary from ownership alone to rights of the individual and responsibility of the decision-maker. |
| Purpose and collection limitation | Required data to be collected and used for specified, necessary purposes rather than accumulated indefinitely. |
| Informed consent and non-consensual grounds | Recognised consent as important but insufficient for every welfare, legal, emergency or employment context. |
| Rights of individuals | Proposed confirmation and access, correction, data portability and a qualified right to be forgotten. |
| Accountability tools | Recommended privacy by design, transparency, security safeguards, audits, impact assessments and breach notification. |
| Independent Data Protection Authority | Placed supervision, enforcement and grievance redress in a specialised statutory institution. |
| Significant data fiduciaries and children’s data | Applied additional obligations where scale, sensitivity, profiling or vulnerability increased risk. |
| Cross-border processing and localisation | Sought enforceability and national access, while differentiating ordinary, sensitive and critical data in the draft framework. |
Its strengths were conceptual clarity and comprehensiveness. It connected privacy with the constitutional recognition of informational autonomy, applied obligations to both public and private processing, adopted technology-neutral principles and proposed an independent regulator. It also recognised that data security, breach response and accountability are not optional additions to consent.
Its limitations reveal the recurring tension between liberty, administration and economic growth. Proposed State-processing and security exemptions risked becoming broad if not subjected to necessity, proportionality and independent review. The proposed regulator’s appointment and governmental influence raised independence concerns. Data localisation could improve jurisdictional access but also create cost, concentration and security trade-offs; keeping a copy in India does not automatically make data secure.
The framework also risked consent fatigue and compliance formalism. A long notice clicked by a user is not meaningful control. Small organisations may struggle with complex obligations, while sophisticated firms can satisfy paperwork without changing invasive business models. Effective regulation must therefore combine clear duties, risk-based supervision, privacy-enhancing design, usable rights and proportionate assistance for smaller entities.
The report should be studied as an intellectual foundation, not as current law. Later bills changed materially, and the operative statutory design is the Digital Personal Data Protection Act, 2023 with its notified rules and phased commencement. Conflating the 2018 draft with the present Act produces wrong answers on rights, localisation, regulator design and remedies.
Digital Personal Data Protection Act, 2023 and the DPDP Rules
The Digital Personal Data Protection Act, 2023 (DPDP Act) creates a horizontal framework for processing digital personal data in a manner that recognises both an individual’s right to protection and the need to process data for lawful purposes.
Its conceptual sequence is simple: a person is the Data Principal; the entity deciding purpose and means is the Data Fiduciary; and a separate registered Consent Manager may help the individual give, manage, review or withdraw consent.
The Act applies to digital personal data processed in India, including data collected offline and subsequently digitised. It also applies outside India where processing is connected with offering goods or services to Data Principals within India. Personal or domestic processing and specified publicly available data fall outside its application. These boundary rules matter because not every data-related harm is governed by the Act.
| Actor or element | Design under the Act when the relevant substantive provisions commence |
| Consent | Must be free, specific, informed, unconditional and unambiguous, expressed through clear affirmative action and limited to data necessary for the specified purpose. It is not confined to a paper or written signature. |
| Certain legitimate uses | Permit defined processing without fresh consent in specified contexts, such as voluntarily provided data for a stated purpose, State benefits under conditions, legal duties, emergencies and employment-related purposes. |
| Data Fiduciary | Remains responsible for compliance, including processors; must use reasonable security safeguards, respond to breaches, maintain accuracy where decisions or disclosure require it, erase when retention is no longer lawful and provide grievance access. |
| Significant Data Fiduciary | Faces additional duties, including an India-based Data Protection Officer, independent data auditor, periodic Data Protection Impact Assessment, audit and prescribed due diligence. |
| Data Principal | Receives rights to information about processing, correction, completion, updating and erasure, grievance redress and nomination; also carries duties against impersonation, suppression and frivolous complaints. |
| Child | Means a person below eighteen. The Act requires verifiable parental consent and restricts detrimental processing, tracking, behavioural monitoring and targeted advertising, subject to lawful exemptions. |
| Data Protection Board of India | A digital-by-design adjudicatory body for breach and non-compliance matters, directions, inquiry and penalties within the statutory triggers and procedure. |
| Appeal | Lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) when the appellate provisions commence—not directly to a High Court under the Act’s first appellate design. |
The Act’s penalty model is administrative and deterrent. Its Schedule permits, after inquiry and once the relevant provisions are operational, penalties up to ₹250 crore for failure to take reasonable security safeguards to prevent a personal-data breach. Lower ceilings apply to other contraventions. Penalties are credited to the Consolidated Fund of India; the Act does not make the Board a general damages forum for individual compensation.
The design has notable strengths: a concise technology-neutral law, extraterritorial reach linked to the Indian market, clear fiduciary responsibility, breach obligations, meaningful consent language, children’s safeguards, risk-based Significant Data Fiduciaries and a digital enforcement body. The final Digital Personal Data Protection Rules, 2025 add operational detail on notice, security safeguards, breach intimation, erasure, children’s data, Consent Managers, cross-border access and the Board.
Its weaknesses concern both rights and institutional checks. The Act omits a general right to data portability and a dedicated right to be forgotten; provides broad State and other exemptions; gives the Central Government significant rule-making, appointment and information-calling influence; sets childhood at eighteen for the general rule; and relies heavily on delegated detail. The Board’s independence will depend on appointment practice, tenure, expertise, transparent procedure and reasoned orders—not statutory labels alone.
| CURRENT STATUS (AS OF AUGUST 2026) The Digital Personal Data Protection Rules, 2025 are final, not draft. They and the Act follow a phased commencement notified in November 2025. Sections establishing the Board and the Rules governing its institutional setup are in force, and the Board has been formally established with its head office in the National Capital Region. The Government invited applications for one Chairperson and four Members in May 2026. The principal rights, Data Fiduciary obligations, penalties, appeals and the omission of IT Act Section 43A are scheduled for the eighteen-month phase in May 2027; Consent Manager registration and the related Board function are scheduled for the one-year phase in November 2026. Therefore, the existence of final Rules does not mean every substantive obligation is already enforceable in August 2026. |
| TRANSITION PRINCIPLE Write the DPDP regime in two layers: enacted design and current commencement. A legally correct answer can explain future rights and duties while clearly stating which provisions are in force on the date of the question. |
Telecommunications Act, 2023; Sectoral Norms of RBI, SEBI and IRDAI
Cyber risk is sector-specific. A telecom failure can remove connectivity needed by every other sector; a banking compromise can threaten payment integrity; a securities-market outage can impair price discovery and settlement; and an insurance breach can expose long-lived health and financial profiles. Horizontal law therefore needs sectoral regulation by institutions that understand the service and its systemic consequences.
The Telecommunications Act, 2023 modernises and consolidates the framework for telecommunication services, networks and spectrum. Its security architecture includes national-security measures, protection of networks and services, a power to declare Critical Telecommunication Infrastructure, standards and conformity assessment, and rules concerning telecom cyber security, interception and temporary suspension.
| Telecom instrument | Security relevance |
| Section 22 of the Telecommunications Act, 2023 | Authorises rules to protect telecom networks and services, including collection and analysis of traffic data, and permits declaration of Critical Telecommunication Infrastructure where disruption would have debilitating impact. |
| Telecommunications (Telecom Cyber Security) Rules, 2024 | Require telecom entities to follow directions and standards, appoint a resident Chief Telecommunication Security Officer, report and respond to security incidents, protect identifiers and supply specified traffic data other than message content for telecom cyber security. |
| Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024 | Provide the operational framework for heightened standards, audits, testing, access and protection of declared critical telecom infrastructure. |
| Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 | Prescribe process and safeguards for lawful interception under the new telecom framework. |
| Telecommunications (Temporary Suspension of Services) Rules, 2024 | Govern temporary suspension through a rule-based process; network shutdown and cyber-security protection are related but legally distinct powers. |
The Act’s cyber-security power permits collection and analysis of traffic data, a term covering routing, duration, time and related network information. The Telecom Cyber Security Rules distinguish such data from message content. This is operationally useful for detecting fraud, spoofing, network abuse and attacks, but large-scale traffic analysis can still affect privacy. Purpose restriction, access logging, retention control, proportionality and independent review remain essential.
| Regulator | Current principal instrument | Security focus |
| Reserve Bank of India | Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023, supplemented by payment-security and cyber-resilience directions for relevant regulated entities. | Board and senior-management accountability, IT governance, third-party risk, change and patch management, business continuity, disaster recovery, information-systems audit and digital-payment controls. |
| Securities and Exchange Board of India | Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, issued in 2024 with subsequent clarifications and FAQs. | A graded framework across market institutions and intermediaries covering governance, asset classification, VAPT, audits, software supply chain, cloud, logs, recovery and cyber-capability assessment. |
| Insurance Regulatory and Development Authority of India | IRDAI Information and Cyber Security Guidelines, 2023. | Governance, risk assessment, asset and access control, data security, incident management, continuity, audit and differentiated application across insurers and insurance intermediaries. |
Sectoral regulation has a strong justification. A financial regulator can connect cyber resilience with prudential supervision, customer protection and systemic stability; a securities regulator can impose coordinated recovery expectations across exchanges, depositories, brokers and market intermediaries; and an insurance regulator can address sensitive policyholder data and outsourcing risk.
The cost is regulatory fragmentation. The same entity may report to CERT-In, a sector regulator, law enforcement, the data-protection authority and contractual partners under different timelines and formats. Controls may duplicate, while genuine gaps survive between mandates. A harmonised national baseline should allow sector regulators to add stricter requirements without forcing organisations to maintain incompatible evidence and incident taxonomies.
| CURRENT STATUS (AS OF AUGUST 2026) Core provisions of the Telecommunications Act have been brought into force in stages since June and July 2024, followed by the Telecom Cyber Security, Critical Telecommunication Infrastructure, lawful-interception and temporary-suspension rules. Implementation remains phased, with additional authorisation rules notified in 2026. RBI’s 2023 IT-governance directions, SEBI’s CSCRF and IRDAI’s 2023 guidelines remain central sectoral baselines; their applicability must be checked by entity category rather than assumed for every organisation in the sector. |
A coherent way forward is:
- one national minimum baseline for governance, incident classification, logging, third-party risk, secure development and recovery;
- sectoral overlays based on safety, financial stability, market integrity, privacy and service-continuity consequence;
- a report-once, route-many gateway that lawfully directs information to CERT-In, regulators, I4C, NCIIPC or the Data Protection Board according to mandate;
- mutual recognition of audits where scope and quality are equivalent, combined with independent verification of remediation;
- common third-party and cloud clauses covering access, incident notice, evidence, subcontracting, vulnerability disclosure, recovery and exit; and
- rights safeguards—necessity, proportionality, purpose limitation, grievance and judicial review—whenever security regulation authorises intrusive collection or restriction.
| SECTION TAKEAWAY India does not lack cyber institutions or legal instruments. Its central challenge is to make a federated architecture behave like one accountable system. That requires correct mandate routing, early reporting, interoperable information, enforceable remediation, State capacity, sector-specific resilience, constitutional safeguards and an approved national strategy that converts activity into measurable security outcomes. |
The institutional and legal architecture developed earlier is mainly territorial: an Indian authority regulates an Indian entity or protects a system within its mandate. Cyberspace is not so obedient. The victim, offender, infrastructure, service provider and electronic evidence may all be in different jurisdictions. At the same time, artificial intelligence, quantum technologies and next-generation networks are changing both offensive capability and defensive responsibility.
| TWO QUESTIONS ORGANISE THESE SECTIONS The international dimension asks: how can sovereign States cooperate in a borderless technical environment? The emerging-technology dimension asks: how can India gain strategic advantage without multiplying systemic vulnerability? |
