top of page

Ultimate Guide to Cybersecurity Standards in India

Security standards

As businesses rapidly embrace digital transformation, cyber threats have become one of the biggest risks to organisational security. To strengthen the nation's cyber resilience, India has established various cybersecurity laws, regulations, and standards that guide organisations in protecting critical systems, securing sensitive data, and responding effectively to cyber incidents. Understanding and complying with these requirements is essential for every organisation operating in today's digital landscape.


India does not have a single comprehensive cybersecurity law. Instead, it follows a layered framework consisting of foundational laws, government directions issued under those laws, sector-specific regulations for industries such as banking, insurance, telecom, and securities, and internationally recognized security standards adopted as Indian Standards by the Bureau of Indian Standards (BIS). Together, these form India's cybersecurity compliance framework.



1. Core Laws - Must Follow by Law


These are the primary cybersecurity laws and government directions in India. Compliance is mandatory, and non-compliance may result in legal penalties, regulatory action, or prosec

ution. Most other cybersecurity regulations and standards build upon these legal requirements.


Law

What It Means

 Purpose / Goal

Who Must Follow It

Information Technology (IT) Act, 2000 (Amended in 2008)

India's primary cyber law.

Gives legal recognition to digital records and signatures and defines cybercrimes like hacking and identity theft.

Everyone using computers or networks in India.

Sensitive Personal Data and Information (SPDI) Rules, 2011

Rules on handling sensitive personal data.

Explains how to safely collect, store, and use data such as passwords, financial, and health records.

Organisations handling sensitive personal data.

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

Rules governing online intermediaries and digital platforms.

Makes social media, gaming and digital publishing platforms more accountable to users.

Online platforms, social media, gaming companies.

CERT-In Directions, 2022

India's mandatory cyber incident reporting directions.

Requires reporting cyber incidents quickly and keeping activity logs to help India respond to cyberattacks.

Service providers, data centres, companies, and government bodies.

DPDP (Digital Personal Data Protection) Act, 2023

India's primary personal data protection law.

Controls how personal data is collected, used and shared, and gives citizens privacy rights.

Any organisation processing personal data in India.


2. Indian Cybersecurity Standards


Unlike laws and regulations, these standards are generally not legally mandatory. However, organisations voluntarily adopt them to demonstrate good cybersecurity practices, improve security maturity, build customer trust, and meet client, audit, or regulatory expectations. Most of these international ISO/IEC standards are adopted in India by the Bureau of Indian Standards (BIS) and are published as IS/ISO/IEC standards.


Indian Standard

Purpose / Goal

  Who Uses It

Indian Standard

IS/ISO/IEC 27000 Series

Provides the framework for Information Security Management Systems (ISMS), including risk management and security controls, auditing, and continual improvement.

Organisations of all sizes implementing information security management.

IS/ISO/IEC 27000 Series

IS/ISO/IEC 27032

Offers guidelines for cybersecurity and protecting systems connected to the internet.

Government agencies, enterprises, and security professionals.

IS/ISO/IEC 27032

IS/ISO/IEC 27033 Series

Defines best practices for securing network infrastructure and communications.

Organisations managing enterprise networks and network administrators

IS/ISO/IEC 27033 Series

IS/ISO/IEC 27035 Series

Provides guidance for preparing for, responding to, and recovering from cybersecurity incidents.

Organisations with Security Operations Centers (SOCs) and incident response teams.

IS/ISO/IEC 27035 Series

IS/ISO/IEC 18033 Series

Specifies approved cryptographic algorithms and encryption techniques.

Software developers, security vendors, and organisations implementing encryption.

IS/ISO/IEC 18033 Series

IS/ISO/IEC 11770 Series

Defines secure methods for cryptographic key management.

Organisations deploying encryption and Public Key Infrastructure (PKI).

IS/ISO/IEC 11770 Series

IS 17428 (Parts 1 & 2)

Provides an India-specific framework for implementing privacy management and data privacy assurance practices.

Organisations handling personal data and seeking an India-specific privacy framework.

IS 17428 (Parts 1 & 2)

Indian Common Criteria Certification Scheme (IC3S)

Evaluates and certifies the security functionality of IT products against internationally recognized security requirements.

Vendors supplying IT security products to government and critical sectors.

Indian Common Criteria Certification Scheme (IC3S)


3. Sector-Specific Regulatory Frameworks


In addition to the core legal framework, sector-specific regulators prescribe extra cybersecurity requirements for the industries they oversee. These requirements are applicable only to organisations within those sectors.


Framework

Issued By

Purpose / Goal

Who Must Follow It

RBI Cyber Security Framework (2016)

Reserve Bank of India

Establishes cybersecurity requirements for protecting banking systems and customer information.

Scheduled Commercial Banks regulated by RBI

RBI IT Framework for NBFCs (2017)

Reserve Bank of India

Extends similar IT and cybersecurity rules to non-banking financial institutions.

NBFCs and Housing Finance Companies.

RBI Guidance on Operational Resilience (2024)

Reserve Bank of India

Helps financial firms manage risk from outages and third-party vendors.

Banks, NBFCs, and financial institutions.

Cyber Security and Cyber Resilience Framework (CSCRF), 2024

Securities and Exchange Board of India (SEBI)

Establishes a standardized cybersecurity and cyber resilience framework for the securities market.

Stock exchanges, brokers, mutual funds, and depositories.

Cyber Security Guidelines (2023)

Insurance Regulatory and Development Authority of India (IRDAI)

Protects insurance companies and policyholder data.

Insurance companies and their outsourcing partners.

Telecom Cybersecurity Rules (2024)

Department of Telecommunications (DoT)

Requires monitoring and reporting to stop telecom fraud.

Telecom operators and related service providers.

Cyber Security Guidelines (2021)

Central Electricity Authority (CEA)

Protects India's power grid systems from cyberattacks.

Power generation, transmission, distribution companies.

NCIIPC Rules & Guidelines

National Critical Information Infrastructure Protection Centre (NCIIPC)

Protects India's Critical Information Infrastructure (CII) by issuing security guidelines and coordinating cybersecurity efforts.

Organisations operating officially notified Protected Systems and Critical Information Infrastructure.



India's cybersecurity framework is built on three key pillars: laws, sector-specific regulations, and cybersecurity standards. Together, they help organisations protect sensitive information, strengthen their security practices, and respond effectively to evolving cyber threats. While laws and regulations define the mandatory legal and regulatory requirements, cybersecurity standards provide structured best practices that organisations can adopt to improve their overall security posture and demonstrate their commitment to information security. Understanding how these laws, regulations, and standards work together enables organisations to identify their compliance obligations and implement appropriate security measures based on their industry and business needs. As cyber threats continue to evolve, staying informed about India's cybersecurity standards and regulatory framework is essential not only for achieving compliance but also for building trust, reducing security risks, and ensuring long-term business resilience.

Note : Most of the Products and Services offered by us are meant for Government, Defence and Law Enforcement Organisations and are required to be used in Ethical manner for National Interest. Usage of Products should be as per the Local Government Regulation/ Norms.

© 2026 by
Cyint Technologies

Tel : +91-88600 68007
Fax : +91-11-41660050
E-mail : info@cyint.in
1800 11 8007 
(Toll-Free Support)
 

Useful Links

Address : F-54, Third Floor
Okhla Industrial Area Phase - I (One)
New Delhi - 110 020, India

Corporate Office

Address : B-108, First Floor, DDA Sheds Okhla Industrial Area Phase - I (One)
New Delhi - 110 020, India

Registered Office

Thanks for submitting!

CONTACT US

bottom of page