Ultimate Guide to Cybersecurity Standards in India
- Yakshi
- Jul 28
- 4 min read

As businesses rapidly embrace digital transformation, cyber threats have become one of the biggest risks to organisational security. To strengthen the nation's cyber resilience, India has established various cybersecurity laws, regulations, and standards that guide organisations in protecting critical systems, securing sensitive data, and responding effectively to cyber incidents. Understanding and complying with these requirements is essential for every organisation operating in today's digital landscape.
India does not have a single comprehensive cybersecurity law. Instead, it follows a layered framework consisting of foundational laws, government directions issued under those laws, sector-specific regulations for industries such as banking, insurance, telecom, and securities, and internationally recognized security standards adopted as Indian Standards by the Bureau of Indian Standards (BIS). Together, these form India's cybersecurity compliance framework.
1. Core Laws - Must Follow by Law
These are the primary cybersecurity laws and government directions in India. Compliance is mandatory, and non-compliance may result in legal penalties, regulatory action, or prosec
ution. Most other cybersecurity regulations and standards build upon these legal requirements.
Law | What It Means | Purpose / Goal | Who Must Follow It |
Information Technology (IT) Act, 2000 (Amended in 2008) | India's primary cyber law. | Gives legal recognition to digital records and signatures and defines cybercrimes like hacking and identity theft. | Everyone using computers or networks in India. |
Sensitive Personal Data and Information (SPDI) Rules, 2011 | Rules on handling sensitive personal data. | Explains how to safely collect, store, and use data such as passwords, financial, and health records. | Organisations handling sensitive personal data. |
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 | Rules governing online intermediaries and digital platforms. | Makes social media, gaming and digital publishing platforms more accountable to users. | Online platforms, social media, gaming companies. |
CERT-In Directions, 2022 | India's mandatory cyber incident reporting directions. | Requires reporting cyber incidents quickly and keeping activity logs to help India respond to cyberattacks. | Service providers, data centres, companies, and government bodies. |
DPDP (Digital Personal Data Protection) Act, 2023 | India's primary personal data protection law. | Controls how personal data is collected, used and shared, and gives citizens privacy rights. | Any organisation processing personal data in India. |
2. Indian Cybersecurity Standards
Unlike laws and regulations, these standards are generally not legally mandatory. However, organisations voluntarily adopt them to demonstrate good cybersecurity practices, improve security maturity, build customer trust, and meet client, audit, or regulatory expectations. Most of these international ISO/IEC standards are adopted in India by the Bureau of Indian Standards (BIS) and are published as IS/ISO/IEC standards.
Indian Standard | Purpose / Goal | Who Uses It | Indian Standard |
IS/ISO/IEC 27000 Series | Provides the framework for Information Security Management Systems (ISMS), including risk management and security controls, auditing, and continual improvement. | Organisations of all sizes implementing information security management. | IS/ISO/IEC 27000 Series |
IS/ISO/IEC 27032 | Offers guidelines for cybersecurity and protecting systems connected to the internet. | Government agencies, enterprises, and security professionals. | IS/ISO/IEC 27032 |
IS/ISO/IEC 27033 Series | Defines best practices for securing network infrastructure and communications. | Organisations managing enterprise networks and network administrators | IS/ISO/IEC 27033 Series |
IS/ISO/IEC 27035 Series | Provides guidance for preparing for, responding to, and recovering from cybersecurity incidents. | Organisations with Security Operations Centers (SOCs) and incident response teams. | IS/ISO/IEC 27035 Series |
IS/ISO/IEC 18033 Series | Specifies approved cryptographic algorithms and encryption techniques. | Software developers, security vendors, and organisations implementing encryption. | IS/ISO/IEC 18033 Series |
IS/ISO/IEC 11770 Series | Defines secure methods for cryptographic key management. | Organisations deploying encryption and Public Key Infrastructure (PKI). | IS/ISO/IEC 11770 Series |
IS 17428 (Parts 1 & 2) | Provides an India-specific framework for implementing privacy management and data privacy assurance practices. | Organisations handling personal data and seeking an India-specific privacy framework. | IS 17428 (Parts 1 & 2) |
Indian Common Criteria Certification Scheme (IC3S) | Evaluates and certifies the security functionality of IT products against internationally recognized security requirements. | Vendors supplying IT security products to government and critical sectors. | Indian Common Criteria Certification Scheme (IC3S) |
3. Sector-Specific Regulatory Frameworks
In addition to the core legal framework, sector-specific regulators prescribe extra cybersecurity requirements for the industries they oversee. These requirements are applicable only to organisations within those sectors.
Framework | Issued By | Purpose / Goal | Who Must Follow It |
RBI Cyber Security Framework (2016) | Reserve Bank of India | Establishes cybersecurity requirements for protecting banking systems and customer information. | Scheduled Commercial Banks regulated by RBI |
RBI IT Framework for NBFCs (2017) | Reserve Bank of India | Extends similar IT and cybersecurity rules to non-banking financial institutions. | NBFCs and Housing Finance Companies. |
RBI Guidance on Operational Resilience (2024) | Reserve Bank of India | Helps financial firms manage risk from outages and third-party vendors. | Banks, NBFCs, and financial institutions. |
Cyber Security and Cyber Resilience Framework (CSCRF), 2024 | Securities and Exchange Board of India (SEBI) | Establishes a standardized cybersecurity and cyber resilience framework for the securities market. | Stock exchanges, brokers, mutual funds, and depositories. |
Cyber Security Guidelines (2023) | Insurance Regulatory and Development Authority of India (IRDAI) | Protects insurance companies and policyholder data. | Insurance companies and their outsourcing partners. |
Telecom Cybersecurity Rules (2024) | Department of Telecommunications (DoT) | Requires monitoring and reporting to stop telecom fraud. | Telecom operators and related service providers. |
Cyber Security Guidelines (2021) | Central Electricity Authority (CEA) | Protects India's power grid systems from cyberattacks. | Power generation, transmission, distribution companies. |
NCIIPC Rules & Guidelines | National Critical Information Infrastructure Protection Centre (NCIIPC) | Protects India's Critical Information Infrastructure (CII) by issuing security guidelines and coordinating cybersecurity efforts. | Organisations operating officially notified Protected Systems and Critical Information Infrastructure. |
India's cybersecurity framework is built on three key pillars: laws, sector-specific regulations, and cybersecurity standards. Together, they help organisations protect sensitive information, strengthen their security practices, and respond effectively to evolving cyber threats. While laws and regulations define the mandatory legal and regulatory requirements, cybersecurity standards provide structured best practices that organisations can adopt to improve their overall security posture and demonstrate their commitment to information security. Understanding how these laws, regulations, and standards work together enables organisations to identify their compliance obligations and implement appropriate security measures based on their industry and business needs. As cyber threats continue to evolve, staying informed about India's cybersecurity standards and regulatory framework is essential not only for achieving compliance but also for building trust, reducing security risks, and ensuring long-term business resilience.



