
The Indian government is considering extending its cybersecurity regulatory framework beyond internet-enabled CCTV cameras to include a broader range of internet of things (IoT) devices. According to reports from The Times of India, discussions at the official level are underway on measures that could require connected devices to meet stricter security and certification standards before they can be sold in India. The move aims to reduce cyber vulnerabilities in internet-connected products and should not be interpreted as a proposal to ban any category of devices.
The cybersecurity push has gained significant momentum with the development of a Security Evaluation Standard for IoT Platforms (SESIP) profile for secure consumer IoT devices. As reported by The Times of India, this work item will specify a profile of the Security Evaluation Standard for IoT Platforms (SESIP) for consumer IoT devices implementing ETSI EN 303 645/TS 103 645. The SESIP general requirements for Security Functional Requirements (SFRs) and Security Assurance Requirements (SARs) will be mapped and further specified to meet the provisions from ETSI EN 303 645/TS 103 645 and ETSI TS 103 701 respectively. This development enables device manufacturers and evaluators to use the SESIP evaluation methodology in combination with ETSI TS 103 701 to assess compliance with ETSI EN 303 645/TS 103 645.
The cybersecurity push builds on the government's existing mandate for internet-enabled CCTV cameras under the Standardisation Testing and Quality Certification (STQC) framework. As reported by The Times of India, since April 1, manufacturers whose products do not comply with prescribed essential security requirements have been barred from selling connected CCTV cameras in India. This framework serves as the foundation for the proposed expansion to other IoT categories.
Officials cited increasing concerns across the wider IoT ecosystem as the primary driver for the proposed framework expansion. According to The Times of India, the same security concerns increasingly apply to the broader IoT ecosystem, which spans smart meters, home automation products, connected appliances, industrial sensors, wearable devices, healthcare equipment and other internet-enabled products. The vulnerabilities are particularly acute as these devices are imported, mainly from China, creating additional security risks for Indian consumers and infrastructure.
While no final decision has been taken on the proposed IoT framework, the discussions represent a significant step in India's cybersecurity regulatory evolution. As reported by The Times of India, the deliberations follow the government's decision to mandate security certification for internet-enabled CCTV cameras, indicating a systematic approach to addressing cybersecurity vulnerabilities across connected devices in the Indian market. The framework expansion reflects growing recognition that IoT devices create hidden tradeoffs between convenience and privacy, with students studying IoT ethics learning to ask better questions about who carries the benefit and who gets the risk in connected device implementations.