TL;DR for founders
Two things surprise people about the Telecommunications (Telecom Cyber Security) Rules, 2024 (notified 21 November 2024). First, the incident clock is 6 hours to notify and 24 hours for the detailed report — and it runs on potential adverse effects, not just actual ones, so near-misses count. Second, since the 22 October 2025 amendment you do not have to be a telco to be caught: if you use mobile numbers to identify customers, you are a Telecommunication Identifier User Entity. That sweeps in banks, fintechs, e-commerce, ride-hailing and OTT messaging. Start with one question — telecommunication entity, TIUE, or both?
This playbook is the operational companion to Veritect's Telecom Cyber Security Rules 2024 explainer. The Rules were made under Section 22 read with Section 56 of the Telecommunications Act, 2023, and they supersede the narrower Prevention of Tampering of the Mobile Device Equipment Identification Number Rules, 2017.
Step 1 — Classify the entity
Everything downstream turns on this, and there are now three possible answers.
- Telecommunication entity — any person providing a telecommunication service, or establishing, operating, maintaining or expanding a telecommunication network. It covers both an authorised entity under Section 3(1) of the Telecommunications Act, 2023 and a person exempted from authorisation under Section 3(3). Being exempt from authorisation is not being exempt from these Rules.
- Telecommunication Identifier User Entity ('TIUE') — inserted by G.S.R. 771(E) dated 22 October 2025: a person other than a telecommunication entity that uses telecommunication identifiers issued by the Central Government or a telecom entity to identify customers or users, or to provision or deliver services to them.
- Both — common in groups holding a connectivity licence alongside a consumer app.
Two notes on reach. A messaging or OTT platform is not a telecommunication entity — the Act's service definition does not extend there — but it is a TIUE if it verifies accounts by mobile number. That is the first formal regulatory nexus between OTT platforms and the Telecom Act. And the Rules apply to any telecommunication entity operating in India regardless of place of incorporation.
Step 2 — Appoint and register the CTSO
Rule 8 requires a Chief Telecommunication Security Officer. Three qualifying conditions are non-negotiable: an Indian citizen, an India resident, and responsible to the board of directors or equivalent governing body.
Appoint by board resolution, then register the CTSO's details on the designated DoT portal — name, designation, office address, email, mobile, office phone — and refresh on every change of incumbent or contact detail. Stale portal details are a self-inflicted failure: the CTSO is the named channel for both Rule 6 incident reports and Rule 7 traffic-data requests.
Do not silently fold this into the CISO role. The CTSO carries statutory duties and statutory personal exposure in a penalty proceeding. Designating the same individual is permissible; conflating the two role descriptions is not.
Step 3 — Adopt the Rule 3 policy and stand up the controls
Rule 3 requires a telecom cyber security policy covering four heads:
- Security safeguards — technical and administrative controls protecting confidentiality, integrity and availability of the network and services.
- Risk management — identification, assessment, mitigation and monitoring.
- Best practices — alignment with national and international standards, including DoT and Bureau of Indian Standards specifications and Telecom Engineering Centre standards.
- Enforcement measures — internal governance ensuring the policy is actually followed.
The policy must be backed by operating controls: a Security Operations Centre monitoring for attempts, intrusions and breaches; periodic vulnerability assessment and penetration testing; and periodic security audits by certified audit agencies, with reports available to the Central Government on request.
Treat the Rule 3 audit as additive. It does not discharge a CERT-In empanelled-auditor engagement under the 28 April 2022 Directions, nor a sectoral audit under an RBI or SEBI framework where the entity also holds that licensure.
💡 Running two six-hour clocks to two regulators on one incident? The Veritect Legal AI platform holds the Telecom Cyber Security Rules 2024 with the October 2025 amendment alongside the CERT-In Directions of 28 April 2022 and the DPDP Rules 2025 breach provisions — so the CTSO can see, obligation by obligation, who must be told what and by when. Explore Veritect Legal AI →
Step 4 — Build the dual-notification runbook
Rule 6 is the provision that will define your operational maturity.
| Stage | Deadline | What goes in |
|---|---|---|
| Initial notification to the Central Government | 6 hours from detection | Fact of the incident; high-level classification |
| Detailed report | 24 hours | Users affected, duration, geographical scope, extent of disruption to networks and services, economic and societal impact, remedial measures taken or proposed |
Three drafting points decide whether the runbook survives a real incident.
- Define "detection" internally. The clock runs from detection, so the runbook must fix who is competent to declare detection and at what alert severity — otherwise the six hours are spent debating whether they have started.
- Cover the "potential" limb. A security incident is an event with an actual or potential adverse effect on telecom cyber security. Near-misses and precursor indicators are in scope, which is broader than most SOC escalation matrices assume.
- File twice. The CERT-In six-hour obligation under Section 70B(6) of the IT Act, 2000 runs in parallel to two different authorities. Build a single intake that forks into two notification templates, and record both acknowledgement references.
For context on how tight this is: India's six hours sits against 72-hour reporting timelines under the United States' Cyber Incident Reporting for Critical Infrastructure Act, 2022 and Article 23 of the EU NIS2 Directive. Industry consultation sought 24 hours; DoT retained six.
Step 5 — Prepare for identifier suspension (Rule 5)
Where an identifier is associated with conduct endangering telecom cyber security, the Central Government may identify the identifier and its holder, issue a show-cause notice under Rule 5(2), and direct the entity to temporarily suspend or permanently disconnect it. In an emergency, an order may issue without prior notice, recording reasons, with post-decisional review to follow.
For the operator, build the capability to execute a suspension direction and to evidence exactly what was suspended and when. For a customer on the receiving end, the emergency limb is the most challengeable part of the Rules: the standard grounds are absence of reasons on the face of the order, disproportionate scope where a class has been suspended without individualised assessment, failure to convene the post-decisional review in time, and the proportionality standard in Anuradha Bhasin v. Union of India, (2020) 3 SCC 637.
Step 6 — Handle Rule 7 data demands correctly
Rule 7 lets authorised Central Government agencies require traffic data or other data, excluding the contents of messages, for the purpose of ensuring telecom cyber security. The Government may also direct the entity to establish infrastructure at designated points for collection, analysis and transmission, and may share data onward with law-enforcement or national-security agencies subject to safeguards.
The single most important response discipline: identify which power is invoked on the face of the demand. Rule 7 targets non-content traffic data for a cyber-security purpose. Section 20 of the Telecommunications Act, 2023, read with the Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 notified on 6 December 2024, targets message content on public-emergency or public-safety grounds with competent-authority approval and review-committee oversight. The safeguards available to challenge each differ materially, and a demand answered under the wrong framework forfeits them.
Step 7 — TIUE obligations and the MNV platform
Rule 7A, inserted on 22 October 2025, creates a Government-run Mobile Number Validation ('MNV') platform. A TIUE can query whether a telecommunication identifier supplied by a customer matches the user recorded in the telecom entity's database, with integration expected for high-risk flows — KYC, onboarding, transaction authorisation.
Because an MNV query transmits the customer's mobile number and limited attributes, settle the DPDP lawful basis before enabling each flow — whether consent under the Digital Personal Data Protection Act, 2023 or the legitimate use of fulfilling a legal obligation — and record the determination per flow rather than once for the platform.
Step 8 — IMEI registration (Rule 9)
Manufacturers, and since the 2025 Amendment importers, must register the IMEI of equipment with the Central Government before first sale in India on the designated portal. Tampering with, altering, obliterating or removing a unique equipment identifier is prohibited; the Government may maintain a database of tampered or restricted IMEIs and require sellers and buyers of used equipment to check it before transacting. Rule 9 offences sit inside the Section 42(3) criminal gateway of the Telecom Act.
Founder checklist
- Answer the classification question in writing — telecommunication entity, TIUE, or both — for every group entity, and re-run it whenever a product starts using mobile numbers for identity.
- Board-resolve the CTSO appointment and diarise a quarterly check that the DoT portal details are current.
- Rehearse the six-hour clock, not just document it. Run a tabletop where the only question is who declares detection and at what severity.
- Fork the notification. One incident, two regulators, two acknowledgement references retained.
- Triage every data demand by the power invoked — Rule 7 traffic data or Section 20 content interception — before anyone in the team produces anything.
Frequently Asked Questions
Q1: Does exemption from authorisation exempt us from these Rules?
No. The definition of telecommunication entity expressly includes both an authorised entity under Section 3(1) of the Telecommunications Act, 2023 and a person exempted from the authorisation requirement under Section 3(3). Captive-network operators above the prescribed threshold are a common example of an exempt class that remains inside the Rules.
Q2: What is the penalty exposure?
The Rules carry no standalone penalty schedule; enforcement runs through Chapter VIII of the Telecommunications Act, 2023. Section 42(3) provides imprisonment up to three years or a fine up to ₹50 lakh or both for specified offences including identifier tampering. Section 43 provides a civil penalty up to ₹5 crore, adjudicated by an Adjudicating Officer of Joint Secretary rank or above exercising Code of Civil Procedure, 1908 powers over summoning, evidence on affidavit and requisition of records. Section 44 covers failure to supply information. Where the same incident is reportable to CERT-In, Section 70B(7) of the IT Act, 2000 attaches in parallel — up to one year's imprisonment or a fine up to ₹1 crore or both.
Q3: Where do we appeal an adjudication order?
Civil penalties are imposed by the Adjudicating Officer, with appeal to the Designated Appeal Committee under the Telecom Act and onward to the Telecom Disputes Settlement and Appellate Tribunal for specified classes. Criminal offences under Section 42 are tried in the ordinary criminal courts. Judicial review of an adjudication order lies to the jurisdictional High Court under Article 226.
Q4: Is Critical Telecommunication Infrastructure covered by these Rules?
Separately. Section 22(1) of the Telecom Act is the parent of the Telecom Cyber Security Rules; Section 22(2) allows the Central Government to declare a network or part of it as Critical Telecommunication Infrastructure and impose additional standards, operationalised by the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024. A CTI designation adds obligations on top of this playbook; it does not displace them.
Q5: There were multiple gazette numbers for the 2025 amendment. Which one is operative?
The amendment issued as G.S.R. 771(E) dated 22 October 2025, following a draft at G.S.R. 411(E) of 24 June 2025. An inadvertent re-publication as G.S.R. 796(E) on 29 October 2025 was rescinded by G.S.R. 863(E) dated 25 November 2025. Cite the 22 October 2025 notification.
Q6: Do the new DoT network authorisation rules change any of this?
They add a separate constraint rather than altering these Rules. The Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, published 20 July 2026, include Rule 25(3), requiring the network system and all associated data, logs and information to be located in India with no copy routed or made available abroad. For a CTSO that matters directly: an offshore SOC or log-analytics tier that satisfies Rule 3 monitoring may still breach Rule 25(3) if the entity holds one of the six network authorisations.
Beyond this brief Preview
Veritect Legal AI holds the operative chain: the Telecommunications Act, 2023 with Sections 3, 20, 22, 42, 43, 44 and 56; the Telecom Cyber Security Rules, 2024 as amended by G.S.R. 771(E) of 22 October 2025; the Critical Telecommunication Infrastructure Rules, 2024; the lawful-interception rules of 6 December 2024; the 2026 network authorisation rules; the CERT-In Directions of 28 April 2022; and the DPDP Act, 2023 with the DPDP Rules, 2025.
Practitioner-level content available on Veritect Legal AI:
- Entity-classification memorandum template — telecommunication entity vs TIUE vs both
- CTSO board-resolution and portal-registration pack with quarterly refresh checklist
- Dual six-hour notification runbook with a shared intake and forked DoT / CERT-In templates
- Rule 7 vs Section 20 demand-triage flowchart with response templates for each power
- MNV per-flow DPDP lawful-basis assessment sheet
Primary Sources
- DoT — Telecommunications (Telecom Cyber Security) Rules, 2024: https://www.dot.gov.in/actrules/telecommunications-telecom-cyber-security-rules-2024
- DoT — Telecommunications Act, 2023 resources: https://dot.gov.in/relatedlinks/telecommunications-act-2023
- PIB — release on telecom cyber security measures: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2206477
- Telecommunications Act, 2023 (Act 44 of 2023) — India Code: https://www.indiacode.nic.in/bitstream/123456789/20101/1/A2023-44.pdf
- CERT-In Directions dated 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- Information Technology Act, 2000 (Section 70B) — India Code: https://www.indiacode.nic.in/handle/123456789/1999
- MeitY — Digital Personal Data Protection Rules, 2025: https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- Telecom Engineering Centre: https://www.tec.gov.in/
- Gazette of India (eGazette): https://egazette.gov.in/
- Supreme Court of India — judgment portal: https://www.sci.gov.in/