Skip to content
Macksofy Technologies
India regulatory

Telecom Cyber Security Rules 2024: What India's Telecom Entities Must Do

India's Telecom Cyber Security Rules, 2024 put a six-hour incident-reporting clock, a mandatory Chief Telecommunication Security Officer, and standing SOC and testing duties on every telecom entity. Who must comply, the timelines, and the compliance checklist.

Telecom Compliance CERT-In Regulatory
Macksofy Audit Team5 September 2026 10 min read
Telecom Cyber Security Rules 2024: What India's Telecom Entities Must Do — Compliance · Macksofy

On 21 November 2024 the Department of Telecommunications notified the Telecommunications (Telecom Cyber Security) Rules, 2024 under the Telecommunications Act, 2023. They place hard obligations on every telecom service provider and network operator in India: a six-hour clock to report a security incident, a mandatory Chief Telecommunication Security Officer who must be an Indian citizen, and a standing duty to test, monitor and defend the network. Here is what the rules require, who they bind, and what a telecom entity has to put in place.

Who has to comply

The rules bind a 'telecommunication entity': anyone who provides a telecommunication service or operates a telecommunication network under the Telecommunications Act, 2023. In practice that is mobile operators, internet service providers, and the operators of the networks behind them. Equipment manufacturers and importers pick up a narrower set of duties around device identifiers, covered below.

The six-hour incident clock

The headline obligation is speed. A telecommunication entity that becomes aware of a security incident affecting its network or services must report it to the Central Government within six hours. A fuller report follows within twenty-four hours and must set out the number of users affected, the duration of the incident, the geographical area impacted, the extent of the disruption, the impact, and the remedial measures taken or proposed.

The CTSO — a named, accountable person

Every telecommunication entity must appoint a Chief Telecommunication Security Officer. The CTSO must be a citizen and resident of India, owns the implementation of the entity's telecom cyber security framework, and is the entity's liaison with the government for compliance and incident reporting. This is a named, accountable role rather than a committee: the point is that there is one person the regulator can hold responsible.

The standing security obligations

Beyond reporting, the rules require a telecommunication entity to run a real security programme. It must adopt a telecom cyber security policy covering risk assessment, network testing, incident response and forensics; put in place the means to monitor its network for security incidents; test its systems for vulnerabilities; keep the records the government may call for; and comply with the directions and audits the government issues. In plain terms: a written policy, a monitoring capability, regular testing, and the logs to prove it.

DutyWhat it means in practiceOwner
Report incidents6 hours to notify, 24 hours for the detailed reportCTSO
Cyber security policyRisk assessment, testing, response, forensicsCTSO / board
Monitor the networkA SOC or equivalent watching for incidentsSecurity operations
Test for vulnerabilitiesVulnerability assessment and penetration testingSecurity / external auditor
Keep recordsLogs and evidence the government may requireIT / security
Cooperate with governmentFurnish data and submit to directions and auditCTSO

The core duties and who owns them

What the government can ask for

The rules let the Central Government, or an agency it authorises, require a telecommunication entity to furnish traffic data and other data — not the content of messages — for the purpose of telecom cyber security. Data collected this way may be shared with other agencies or stakeholders only for telecom cyber security, and the rules require safeguards against unauthorised access. If you operate a network, assume the data you hold can be called for, and hold it accordingly.

Device identifiers (IMEI)

A separate strand binds device makers and importers. Manufacturers must register the International Mobile Equipment Identity (IMEI) of a device before its first sale in India, and importers must register identifiers before import. Tampering with a device identifier is prohibited, and devices with tampered identifiers can be blocked from networks. If your business touches the device supply chain rather than the network, this is the part of the rules that reaches you.

The compliance checklist

  1. Appoint a CTSO who meets the citizen-and-resident test and give them board-level access.
  2. Write and adopt the telecom cyber security policy — risk assessment, testing, incident response, forensics.
  3. Stand up monitoring: a security operations centre, in-house or managed, that can actually see an incident.
  4. Run a baseline vulnerability assessment and penetration test, and fix what it finds.
  5. Build one incident runbook that files the six-hour report to both the DoT and CERT-In, and rehearse it.
  6. Sort out logging and retention so you can produce what the government may require.
  7. Register device identifiers if you manufacture or import equipment.

Most of this you can reuse from CERT-In work

If you already run a CERT-In empanelled audit programme, you are closer than you think. The testing, monitoring and incident-response duties in these rules overlap heavily with the CERT-In 2022 Directions and the empanelled-audit process — see our walkthrough of the CERT-In empanelment process and the buyer's guide to a CERT-In empanelled audit. The practical gaps for most telecom entities are the named CTSO, the DoT reporting line, and proof that the monitoring and testing actually run. Macksofy covers those pieces as a CERT-In empanelled auditor: VAPT for the testing duty, a managed SOC for the monitoring duty, and digital forensics and incident response for the six-hour clock.

Preparing for the Telecom Cyber Security Rules?

Macksofy is a CERT-In empanelled auditor. We run the VAPT, the SOC and the incident response the rules require, and help you stand up the reporting line and the evidence trail. Tell us where your network is today.

Talk to our audit team
FAQ

Quick answers.

Every telecommunication entity — telecom service providers and network operators under the Telecommunications Act, 2023. Equipment manufacturers and importers additionally have to register and protect device identifiers.
A telecommunication entity must report a security incident affecting its network or services to the Central Government within six hours of becoming aware of it, then file a detailed report within twenty-four hours covering users affected, duration, geography, disruption, impact and remedial action.
The CTSO must be a citizen and resident of India. They own the entity's telecom cyber security framework and act as the liaison with the government for compliance and incident reporting.
Yes in substance. The cyber security policy must cover network testing, and the entity must be able to monitor for and respond to incidents. Vulnerability assessment and penetration testing plus a security operations centre are the practical way to meet those duties.
They were notified on 21 November 2024 and came into force on publication, with a short transition before the operative obligations apply. Confirm the current applicable deadlines against the DoT Gazette notification, as some duties phase in.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements