India mulls security certification for IoT devices
The government is considering extending mandatory cybersecurity certification, currently applied to internet-enabled CCTV cameras, to a broader category of Internet of Things (IoT) devices, including smart meters.
The move responds to concerns over security vulnerabilities in imported IoT hardware, particularly devices sourced from China.
The existing CCTV certification framework requires devices to meet government-notified Essential Requirements covering firmware security, encrypted communication, and supply-chain transparency before they can be legally sold in India.
Extending a similar framework to other connected devices would bring categories such as smart meters, which are part of India's electricity grid digitisation, under mandatory security testing.
Essential Requirements and Certification Framework for CCTV Cameras
The Ministry of Electronics and Information Technology (MeitY) notified Essential Requirements for the cybersecurity of CCTV cameras, mandating testing by Standardisation Testing and Quality Certification (STQC) directorate laboratories and registration under the Bureau of Indian Standards (BIS) Compulsory Registration framework before such devices can be sold in India. This dual-track approach — BIS registration as the baseline "licence to sell" and STQC system-level testing for stricter government-procurement use — is the working model the government is now considering extending to other IoT categories.
Key Details
- CCTV cameras were brought under the BIS Compulsory Registration Order via a Gazette notification (2024), alongside government-notified Essential Requirements from MeitY.
- The six core Essential Requirements include: no default/hardcoded passwords, encrypted data streams, digitally signed firmware, disabled unnecessary debug ports, supply-chain/chipset-origin transparency, and a vulnerability disclosure policy.
- STQC operates the IoT System Certification Scheme (IoTSCS), grading device security assurance on a scale of Level 0 to Level 4, covering physical, communication, and application interfaces.
- Non-compliant CCTV cameras face a legal sale prohibition in India from the notified compliance deadline.
The government is examining whether this same BIS-registration-plus-STQC-testing model, built for CCTV cameras, should be generalised to other IoT categories such as smart meters, given similar risks from imported hardware.
Indian Telecom Security Assurance Requirements (ITSAR) and NCCS
The National Centre for Communication Security (NCCS), a body under the Department of Telecommunications (DoT), issues Indian Telecom Security Assurance Requirements (ITSARs) — mandatory security baselines for categories of telecom and consumer IoT equipment — under the Mandatory Testing and Certification of Telecom Equipment (MTCTE) framework. NCCS-designated Telecom Security Test Laboratories (TSTLs) test devices against the relevant ITSAR before certification.
Key Details
- ITSAR requirements are issued category-wise; smart electricity meters fall under a distinct device group with dedicated common security requirements, given their role in India's Advanced Metering Infrastructure (AMI).
- Mandated controls for smart meters include secure boot, encryption of data at rest and in transit, mutual authentication between the meter and the data concentrator, anti-tampering protection, and secure firmware lifecycle management.
- ITSAR compliance is layered on top of, and distinct from, MeitY/STQC/BIS certification for consumer IoT devices such as cameras — reflecting India's still-evolving, multi-regulator approach to IoT security (DoT/NCCS for telecom-linked devices, MeitY/STQC/BIS for consumer electronics).
- The baseline consumer IoT security document, the Code of Practice for Securing Consumer Internet of Things (TEC 31318), issued by the Telecommunication Engineering Centre under DoT, aligns with international standards such as ETSI EN 303 645.
Smart meters are already within the ITSAR/NCCS security framework administered by DoT; the reported proposal to extend "security certification" more broadly signals a push to harmonise or widen coverage across the MeitY/STQC/BIS and DoT/NCCS/ITSAR tracks for a larger set of IoT device categories.
Supply-Chain Security and Import Dependence in Electronics
Concerns over imported IoT hardware — particularly from a single dominant source country — reflect a broader Indian internal-security and economic-security concern: dependence on foreign-manufactured electronic components and devices creates risks of embedded vulnerabilities, backdoors, or data exfiltration in critical and consumer infrastructure. Mandatory security certification with supply-chain/component-origin disclosure requirements is one policy tool to mitigate this; it complements trade and manufacturing-incentive measures such as Production-Linked Incentive (PLI) schemes for electronics and telecom equipment manufacturing, which aim to reduce import dependence over time.
Key Details
- Supply-chain and chipset-origin transparency is one of the notified Essential Requirements for CCTV cameras, directly targeting the risk of unknown or undisclosed foreign components in security-sensitive devices.
- CERT-In (Indian Computer Emergency Response Team), functioning under MeitY, is the national nodal agency for cybersecurity incident response and coordinates on vulnerabilities in deployed IT and IoT systems.
- The PLI Scheme for large-scale electronics manufacturing and the PLI Scheme for telecom and networking products are complementary industrial-policy measures aimed at building domestic manufacturing capacity for the same device categories now facing tighter security certification.
Extending certification to a wider set of IoT devices used in critical functions (like smart meters, integral to the power grid) is a security-hardening measure that sits alongside India's broader push to reduce strategic dependence on imported electronics in sensitive infrastructure.
- Existing mandatory framework: BIS Compulsory Registration Order for CCTV cameras (2024 Gazette notification) plus MeitY-notified Essential Requirements, tested by STQC laboratories.
- STQC's IoT System Certification Scheme (IoTSCS) grades device security assurance from Level 0 to Level 4.
- Smart electricity meters are already covered under an ITSAR issued by the National Centre for Communication Security (NCCS, under DoT) as part of India's Advanced Metering Infrastructure (AMI) security framework.
- Six core CCTV Essential Requirements: no default passwords, encrypted streams, signed firmware, disabled debug ports, supply-chain/chipset transparency, vulnerability disclosure policy.
- Consumer IoT baseline standard: Code of Practice for Securing Consumer IoT (TEC 31318), aligned with ETSI EN 303 645.