The Indian government is considering a significant expansion of its cybersecurity regulations for connected devices, moving beyond the already-mandated security certification for CCTV cameras to encompass a wide range of Internet of Things (IoT) products, according to a report by Business Today. The move targets vulnerabilities in devices such as smart meters, home automation systems, and industrial sensors, many of which are imported primarily from China.
Background: The CCTV Precedent
Since April 1, the government has barred manufacturers from selling internet-enabled CCTV cameras in India unless their products comply with essential security requirements under the Standardisation Testing and Quality Certification (STQC) framework. The same logic now applies across the broader IoT ecosystem, officials said, as concerns mount over weak or inconsistent security standards creating larger attack surfaces for hackers.
Scope of the Proposed Framework
Discussions at the official level are underway but no final decision has been taken, persons in the know told Business Today. The proposed framework would likely require stricter security and certification standards before any connected device can be sold in India. The following device categories are under consideration:
- Smart meters
- Home automation products
- Connected appliances
- Industrial sensors
- Wearable devices
- Healthcare equipment
- Other internet-enabled products
As these devices proliferate across homes, factories, offices, and critical infrastructure, they create "much larger attack points for hackers if security standards are weak or inconsistent," the source noted.
Supply Chain and Compliance Emphasis
A key element of the proposed approach is greater visibility into supply chains. The government is examining whether a common baseline security framework can ensure that all connected devices entering the Indian market meet minimum cybersecurity requirements before deployment. The emphasis is expected to be on:
- Product testing
- Vulnerability assessment
- Software integrity
- Supply chain transparency
Crucially, the focus is on ensuring that connected products meet India's cybersecurity requirements "irrespective of where they are made," according to officials. This has direct implications for enterprise technology procurement leaders and supply chain managers who must ensure their IoT deployments comply with future regulations.
| Aspect | Current Status (CCTV Cameras) | Proposed Expansion (All IoT) |
|---|---|---|
| Mandate | Since April 1 | Under discussion |
| Certification Body | STQC | Likely STQC or similar |
| Key Requirements | Essential security requirements | Product testing, vulnerability assessment, software integrity, supply chain visibility |
| Import Sensitivity | High (mainly from China) | High (many categories imported from China) |
Implications for Enterprise Technology
For CTOs and technology procurement leaders, this signals a shift toward mandatory cybersecurity baselines for all connected devices used in business operations. Companies deploying IoT in supply chain, logistics, or industrial automation will need to verify that their vendors comply with Indian standards — even if the devices are manufactured overseas. The move also highlights the growing intersection of cybersecurity and supply chain risk management, as visibility into component sourcing becomes a regulatory requirement.
The government's emphasis on vulnerability assessment and software integrity suggests that future regulations may require ongoing security updates and transparent reporting of security patches. Enterprise buyers should start auditing their IoT suppliers now to assess readiness for India's emerging cyber framework.