India

Asia-Pacific

India regulates telecom security through the Department of Telecommunications (DoT), TRAI, and CERT-In. The 2021 National Security Directive on the telecom sector introduced the Trusted Sources / Trusted Products framework for network equipment procurement.

Regulator: DoT + TRAI + CERT-In

Primary frameworks: National Security Directive on Telecom (2021), Trusted Sources framework, CERT-In directions (2022), Telecommunications Act 2023

Trusted Sources framework

Since June 2021, operators must procure telecom equipment only from Trusted Sources. Product-level and vendor-level designation is administered by the National Cyber Security Coordinator.

CERT-In directions

The 2022 CERT-In direction requires reporting of enumerated cyber incidents within 6 hours. Telecom operators must maintain logs for 180 days and support attribution investigations.

Telecommunications Act 2023

The new Act consolidates telecom regulation. Security obligations are cross-referenced to executive rules, including signaling and roaming risk management.

Key takeaways

  • Trusted Sources status is procurement-blocking — verify before RFP.
  • CERT-In's 6-hour reporting is one of the fastest in the world; SOC playbooks must be ready.
  • The 2023 Act is being rulemaking-implemented through 2025-26; expect signaling-security specifics to firm up.