India
Asia-Pacific
India regulates telecom security through the Department of Telecommunications (DoT), TRAI, and CERT-In. The 2021 National Security Directive on the telecom sector introduced the Trusted Sources / Trusted Products framework for network equipment procurement.
Regulator: DoT + TRAI + CERT-In
Primary frameworks: National Security Directive on Telecom (2021), Trusted Sources framework, CERT-In directions (2022), Telecommunications Act 2023
Trusted Sources framework
Since June 2021, operators must procure telecom equipment only from Trusted Sources. Product-level and vendor-level designation is administered by the National Cyber Security Coordinator.
CERT-In directions
The 2022 CERT-In direction requires reporting of enumerated cyber incidents within 6 hours. Telecom operators must maintain logs for 180 days and support attribution investigations.
Telecommunications Act 2023
The new Act consolidates telecom regulation. Security obligations are cross-referenced to executive rules, including signaling and roaming risk management.
Key takeaways
- Trusted Sources status is procurement-blocking — verify before RFP.
- CERT-In's 6-hour reporting is one of the fastest in the world; SOC playbooks must be ready.
- The 2023 Act is being rulemaking-implemented through 2025-26; expect signaling-security specifics to firm up.