Policy Watch
Regulatory Intelligence for Indian Critical Infrastructure
CERT-In Blueprint: Defending Against AI-Assisted Vulnerability Exploitation
Applies to: All entities; emphasis on financial institutions, government, telecom, critical infrastructure
A 38-page, 14-section national blueprint responding to AI-accelerated attacks. It warns that generative AI, LLMs and autonomous agents compress the cyber kill chain — reconnaissance, vulnerability discovery and exploit generation…
RBI Customer Data Protection Advisory (Cyber Security & IT Risk Group)
Applies to: Banks, NBFCs, fintechs, payment aggregators
RBI's sector-specific operationalisation of the DPDP Act for the financial ecosystem. It directs regulated entities to obtain board-level (or board-committee) approval for customer-data-security, privacy and third-party-risk policies, and to review…
India AI Governance Guidelines
Applies to: AI developers, deployers and regulators across sectors (non-binding framework)
India's national framework for AI governance, developed by a MeitY drafting committee constituted in July 2025 (chaired by Prof. Balaraman Ravindran) and published on 15 February 2026 ahead of the…
IT (Intermediary Guidelines) Amendment Rules, 2026 — Synthetic Media
Applies to: Intermediaries and Significant Social Media Intermediaries (SSMIs); platforms enabling creation or dissemination of synthetic/AI-generated content
India's first statutory framework for synthetically generated information (SGI) — AI-created or AI-altered audio-visual content, including deepfakes. Notified by MeitY on 10 February 2026 under Section 87 of the IT…
DPDP Rules, 2025
Applies to: All Data Fiduciaries processing digital personal data connected to India (extraterritorial)
India's first comprehensive personal-data regime. The DPDP Rules were notified on 14 November 2025 and roll out over an 18-month window. Phase 1 (Nov 2025) established the Data Protection Board…
Next deadline: 13 May 2027
CERT-In Cyber Security Audit Policy Guidelines, 2025
Applies to: CERT-In empanelled auditing organisations and all auditee organisations (public and private) that undergo cyber security audits — including RBI/SEBI/IRDAI-regulated entities and voluntary auditees
Issued by CERT-In on 25 July 2025 under Section 70B of the IT Act, the Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0) standardise how cyber security audits are conducted…
Telecom Cybersecurity Rules, 2024 (with 2025 amendment)
Applies to: Licensed telecom service providers; certain non-telecom entities using telecom identifiers
Issued by the Department of Telecommunications under the Telecommunications Act, 2023, these rules treat telecom networks as foundational digital infrastructure. Carriers must report breach incidents within 6 hours, retain logs…
SEBI CSCRF + AI Vulnerability Detection Advisory
Applies to: All SEBI regulated entities, tiered across five categories
A 205-page master framework replacing SEBI's 2015/2018 cyber guidelines, built on five resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) and a five-tier model from Market Infrastructure Institutions down to self-certification…
Recurring deadline: 30 Jun 2026
PFRDA Information & Cyber Security Policy Guidelines, 2024
Applies to: PFRDA regulated entities — CRAs, pension funds, PoPs, APY-SPs, trustee banks, custodians, non-individual retirement advisors
The pension-sector cyber regime protecting NPS and APY subscriber data. The 2024 guidelines classify regulated entities into Category I (CRAs and pension funds) and Category II (PoPs, APY-SPs, trustee banks,…
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices
Applies to: Scheduled commercial banks, urban cooperative banks, NBFCs, payment system operators
Consolidates and updates earlier RBI IT and cyber circulars into a single governance-led direction. Board-level IT governance is mandatory via a dedicated IT Strategy Committee; the IT Risk Framework requires…
IRDAI Information and Cyber Security Guidelines
Applies to: Insurers and insurance intermediaries
The insurance-sector cyber overlay. The guidelines mandate a designated CISO, a board-approved information-security policy, periodic risk assessment, VAPT, and incident reporting aligned to the 6-hour national baseline. They emphasise data…
CERT-In Directions (6-Hour Incident Reporting), 2022
Applies to: All entities operating IT systems in India — no minimum threshold
The national baseline. Covered entities must report any of 20 categories of cyber incident to CERT-In within 6 hours of becoming aware of it — the clock starts at awareness,…
NCIIPC Protected System Rules & CII Guidelines
Applies to: Entities notified as Protected Systems — power, banking, telecom, transport, government
The designation regime that defines Critical Information Infrastructure in India. Framed under Section 70 of the IT Act, the Rules (2018) and Guidelines (2015) protect CII from unauthorised access, modification,…