Telecom Cybersecurity Rules, 2024 (with 2025 amendment)
Applies to: Licensed telecom service providers; certain non-telecom entities using telecom identifiers
Issued by the Department of Telecommunications under the Telecommunications Act, 2023, these rules treat telecom networks as foundational digital infrastructure. Carriers must report breach incidents within 6 hours, retain logs and records for up to 2 years, and maintain infrastructure-protection, intrusion-monitoring and incident-reporting capabilities. They remain subject to lawful interception, data retention, subscriber KYC and data-localisation expectations, plus CERT-In reporting and ComSec equipment-certification requirements for network hardware. The 2025 amendment extended verification and reporting obligations to non-telecom entities that use telecom identifiers to provide their services.
Why it matters
The forward signal here is consolidation, not new obligation: MeitY and the Ministry of Communications opened discussions in May 2026 to rationalise the overlapping CERT-In and DoT audit/reporting structures, with a working group tasked to designate a single reporting body. For a telecom CISO that is the rare regulatory move that reduces burden — worth tracking, because dual reporting to CERT-In and DoT is current reality until it lands. The 2025 extension to "non-telecom entities using telecom identifiers" quietly widens scope to fintechs and platforms issuing OTPs and verification codes; check whether it reaches you.