
The Centre is examining ways to streamline cybersecurity compliance requirements for telecommunications service providers through a potential single-point incident-reporting mechanism. According to reports from Business Standard, a senior official from the Department of Telecommunications (DoT) stated that the effort aims to avoid duality in regulation to enhance ease of doing business. The official noted that while cybersecurity is largely governed by the Ministry of Electronics and Information Technology (Meity), where telecom networks are impacted, the government is open to reviewing whether existing rules create unnecessary regulatory duality. As per Business Standard, no changes to the broader regulatory framework or rules are being considered, but rationalisation of dual structures for audit and compliance reporting by carriers may be examined.
Initial discussions between the Indian Computer Emergency Response Team (CERT-In) under Meity and DoT have resulted in the formation of a working group comprising officials and industry representatives. As reported by Business Standard, a top industry executive confirmed that this working group has been established to identify commonalities and potentially designate a single reporting body. The executive noted that there is significant overlap between the reporting requirements of CERT-In and DoT, with both departments aligned on this initiative. According to Business Standard, both departments are aligned on this initiative, so progress should be seen soon.
According to the Telecom Cybersecurity Rules, 2024 issued by DoT, carriers are required to report breach incidents within six hours and retain logs or records for up to two years. Carriers are also subject to security and data obligations including lawful interception, data retention, subscriber know-your-customer requirements, and data localisation expectations. Under the Information Technology Act, cybersecurity incidents must be reported to CERT-In within six hours with logs and data retention for five years. Section 69 of the Act allows lawful interception, monitoring, and blocking of unlawful content. CERT-In serves as the nodal body responsible for collecting, analysing, and disseminating information on cyber incidents, forecasts, and alerts, and for issuing emergency measures to entities across India.
While a single reporting body may not be viable due to different laws governing cybersecurity norms under Meity and DoT, as noted by a senior Meity official, harmonization of reporting requirements could be considered. As reported by Business Standard, this approach would ensure the same information reaches both departments, thereby reducing compliance burden. The ministry issued amendments to the cybersecurity rules in October 2025 that retained existing compliance requirements while introducing additional layers to the mobile number validation platform to address rising mule accounts and identity fraud. CERT-In also issues guidelines, advisories, and vulnerability notes related to the prevention and reporting of cyber incidents. The initiative aligns with broader global trends toward digital resilience, where cybersecurity is increasingly measured by a state's ability to protect identity, ensure data integrity, and maintain citizen trust under pressure.