NCIIPC Protected System Rules & CII Guidelines

NCIIPC All Guideline Active 1 Jan 2018

Applies to: Entities notified as Protected Systems — power, banking, telecom, transport, government

The designation regime that defines Critical Information Infrastructure in India. Framed under Section 70 of the IT Act, the Rules (2018) and Guidelines (2015) protect CII from unauthorised access, modification, disclosure and disruption where impact would be debilitating to national security or public order. Once an organisation's assets are notified as a Protected System, NCIIPC-specified controls apply: third-party security certifications (government or private), implementation of applicable international security standards, asset-level certification mapping, and certification of personnel relative to their responsibilities. Sectoral regulators (RBI, SEBI, IRDAI, DoT) layer their own binding frameworks on top.
Why it matters
This is the regime your whole audience sits under, yet it is the least visible day to day — because the trigger is the Protected System notification, and many CII operators have never mapped which of their assets are, or should be, notified. The operational consequence of notification is significant: it pulls personnel-certification and asset-level certification obligations into scope that the sectoral frameworks alone do not impose. The practical action is to confirm your notification status and asset inventory now, rather than discover the gap during an incident when NCIIPC coordination is suddenly in play.