Policy Watch

Regulatory Intelligence for Indian Critical Infrastructure

CERT-In All Advisory Active 25 May 2026

CERT-In Blueprint: Defending Against AI-Assisted Vulnerability Exploitation

Applies to: All entities; emphasis on financial institutions, government, telecom, critical infrastructure

A 38-page, 14-section national blueprint responding to AI-accelerated attacks. It warns that generative AI, LLMs and autonomous agents compress the cyber kill chain — reconnaissance, vulnerability discovery and exploit generation…

RBI BFSI Advisory Active 1 Apr 2026

RBI Customer Data Protection Advisory (Cyber Security & IT Risk Group)

Applies to: Banks, NBFCs, fintechs, payment aggregators

RBI's sector-specific operationalisation of the DPDP Act for the financial ecosystem. It directs regulated entities to obtain board-level (or board-committee) approval for customer-data-security, privacy and third-party-risk policies, and to review…

MeitY All Guideline Active 15 Feb 2026

India AI Governance Guidelines

Applies to: AI developers, deployers and regulators across sectors (non-binding framework)

India's national framework for AI governance, developed by a MeitY drafting committee constituted in July 2025 (chaired by Prof. Balaraman Ravindran) and published on 15 February 2026 ahead of the…

MeitY All Direction Active 10 Feb 2026

IT (Intermediary Guidelines) Amendment Rules, 2026 — Synthetic Media

Applies to: Intermediaries and Significant Social Media Intermediaries (SSMIs); platforms enabling creation or dissemination of synthetic/AI-generated content

India's first statutory framework for synthetically generated information (SGI) — AI-created or AI-altered audio-visual content, including deepfakes. Notified by MeitY on 10 February 2026 under Section 87 of the IT…

MeitY All Act / Legislation Upcoming 14 Nov 2025

DPDP Rules, 2025

Applies to: All Data Fiduciaries processing digital personal data connected to India (extraterritorial)

India's first comprehensive personal-data regime. The DPDP Rules were notified on 14 November 2025 and roll out over an 18-month window. Phase 1 (Nov 2025) established the Data Protection Board…

Next deadline: 13 May 2027

CERT-In All Guideline Active 25 Jul 2025

CERT-In Cyber Security Audit Policy Guidelines, 2025

Applies to: CERT-In empanelled auditing organisations and all auditee organisations (public and private) that undergo cyber security audits — including RBI/SEBI/IRDAI-regulated entities and voluntary auditees

Issued by CERT-In on 25 July 2025 under Section 70B of the IT Act, the Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0) standardise how cyber security audits are conducted…

TRAI / DoT Telecom Direction Active 1 Nov 2024

Telecom Cybersecurity Rules, 2024 (with 2025 amendment)

Applies to: Licensed telecom service providers; certain non-telecom entities using telecom identifiers

Issued by the Department of Telecommunications under the Telecommunications Act, 2023, these rules treat telecom networks as foundational digital infrastructure. Carriers must report breach incidents within 6 hours, retain logs…

SEBI BFSI Framework Active 20 Aug 2024

SEBI CSCRF + AI Vulnerability Detection Advisory

Applies to: All SEBI regulated entities, tiered across five categories

A 205-page master framework replacing SEBI's 2015/2018 cyber guidelines, built on five resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) and a five-tier model from Market Infrastructure Institutions down to self-certification…

Recurring deadline: 30 Jun 2026

PFRDA BFSI Guideline Active 1 Aug 2024

PFRDA Information & Cyber Security Policy Guidelines, 2024

Applies to: PFRDA regulated entities — CRAs, pension funds, PoPs, APY-SPs, trustee banks, custodians, non-individual retirement advisors

The pension-sector cyber regime protecting NPS and APY subscriber data. The 2024 guidelines classify regulated entities into Category I (CRAs and pension funds) and Category II (PoPs, APY-SPs, trustee banks,…

RBI BFSI Direction Active 1 Apr 2024

RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices

Applies to: Scheduled commercial banks, urban cooperative banks, NBFCs, payment system operators

Consolidates and updates earlier RBI IT and cyber circulars into a single governance-led direction. Board-level IT governance is mandatory via a dedicated IT Strategy Committee; the IT Risk Framework requires…

IRDAI BFSI Guideline Active 1 Jan 2023

IRDAI Information and Cyber Security Guidelines

Applies to: Insurers and insurance intermediaries

The insurance-sector cyber overlay. The guidelines mandate a designated CISO, a board-approved information-security policy, periodic risk assessment, VAPT, and incident reporting aligned to the 6-hour national baseline. They emphasise data…

CERT-In All Direction Active 28 Apr 2022

CERT-In Directions (6-Hour Incident Reporting), 2022

Applies to: All entities operating IT systems in India — no minimum threshold

The national baseline. Covered entities must report any of 20 categories of cyber incident to CERT-In within 6 hours of becoming aware of it — the clock starts at awareness,…

NCIIPC All Guideline Active 1 Jan 2018

NCIIPC Protected System Rules & CII Guidelines

Applies to: Entities notified as Protected Systems — power, banking, telecom, transport, government

The designation regime that defines Critical Information Infrastructure in India. Framed under Section 70 of the IT Act, the Rules (2018) and Guidelines (2015) protect CII from unauthorised access, modification,…