Telecom Cyber Security Rules 2024 Playbook: CTSO, 6-Hour Clock, MNV

Compliance Playbook Telecom & Emerging Tech 28 Jul 2026 Status: in-force
Statutory deadline
Security incident notification within 6 hours of detection and detailed report within 24 hours (Rule 6); CTSO appointment and registration of details on the designated DoT portal (Rule 8); IMEI registration before first sale in India (Rule 9)
TL;DR

The Telecommunications (Telecom Cyber Security) Rules, 2024, notified by the Department of Telecommunications on 21 November 2024 under Section 22 read with Section 56 of the Telecommunications Act, 2023, require every telecommunication entity to appoint a Chief Telecommunication Security Officer who is an Indian citizen and resident answerable to the board, run a Security Operations Centre with periodic VAPT, and report any security incident within 6 hours of detection with a detailed report within 24 hours. The Amendment Rules of 22 October 2025 (G.S.R. 771(E)) added the Telecommunication Identifier User Entity category and the Mobile Number Validation platform, pulling banks, fintechs, e-commerce and OTT services that use mobile numbers to identify customers into the regime.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
8 min read
Continue with Veritect

Meet the statutory clock with a pre-drafted workflow.

Try Veritect free Book a demo

TL;DR for founders

Two things surprise people about the Telecommunications (Telecom Cyber Security) Rules, 2024 (notified 21 November 2024). First, the incident clock is 6 hours to notify and 24 hours for the detailed report — and it runs on potential adverse effects, not just actual ones, so near-misses count. Second, since the 22 October 2025 amendment you do not have to be a telco to be caught: if you use mobile numbers to identify customers, you are a Telecommunication Identifier User Entity. That sweeps in banks, fintechs, e-commerce, ride-hailing and OTT messaging. Start with one question — telecommunication entity, TIUE, or both?

This playbook is the operational companion to Veritect's Telecom Cyber Security Rules 2024 explainer. The Rules were made under Section 22 read with Section 56 of the Telecommunications Act, 2023, and they supersede the narrower Prevention of Tampering of the Mobile Device Equipment Identification Number Rules, 2017.

Step 1 — Classify the entity

Everything downstream turns on this, and there are now three possible answers.

  • Telecommunication entity — any person providing a telecommunication service, or establishing, operating, maintaining or expanding a telecommunication network. It covers both an authorised entity under Section 3(1) of the Telecommunications Act, 2023 and a person exempted from authorisation under Section 3(3). Being exempt from authorisation is not being exempt from these Rules.
  • Telecommunication Identifier User Entity ('TIUE') — inserted by G.S.R. 771(E) dated 22 October 2025: a person other than a telecommunication entity that uses telecommunication identifiers issued by the Central Government or a telecom entity to identify customers or users, or to provision or deliver services to them.
  • Both — common in groups holding a connectivity licence alongside a consumer app.

Two notes on reach. A messaging or OTT platform is not a telecommunication entity — the Act's service definition does not extend there — but it is a TIUE if it verifies accounts by mobile number. That is the first formal regulatory nexus between OTT platforms and the Telecom Act. And the Rules apply to any telecommunication entity operating in India regardless of place of incorporation.

Step 2 — Appoint and register the CTSO

Rule 8 requires a Chief Telecommunication Security Officer. Three qualifying conditions are non-negotiable: an Indian citizen, an India resident, and responsible to the board of directors or equivalent governing body.

Appoint by board resolution, then register the CTSO's details on the designated DoT portal — name, designation, office address, email, mobile, office phone — and refresh on every change of incumbent or contact detail. Stale portal details are a self-inflicted failure: the CTSO is the named channel for both Rule 6 incident reports and Rule 7 traffic-data requests.

Do not silently fold this into the CISO role. The CTSO carries statutory duties and statutory personal exposure in a penalty proceeding. Designating the same individual is permissible; conflating the two role descriptions is not.

Step 3 — Adopt the Rule 3 policy and stand up the controls

Rule 3 requires a telecom cyber security policy covering four heads:

  1. Security safeguards — technical and administrative controls protecting confidentiality, integrity and availability of the network and services.
  2. Risk management — identification, assessment, mitigation and monitoring.
  3. Best practices — alignment with national and international standards, including DoT and Bureau of Indian Standards specifications and Telecom Engineering Centre standards.
  4. Enforcement measures — internal governance ensuring the policy is actually followed.

The policy must be backed by operating controls: a Security Operations Centre monitoring for attempts, intrusions and breaches; periodic vulnerability assessment and penetration testing; and periodic security audits by certified audit agencies, with reports available to the Central Government on request.

Treat the Rule 3 audit as additive. It does not discharge a CERT-In empanelled-auditor engagement under the 28 April 2022 Directions, nor a sectoral audit under an RBI or SEBI framework where the entity also holds that licensure.

💡 Running two six-hour clocks to two regulators on one incident? The Veritect Legal AI platform holds the Telecom Cyber Security Rules 2024 with the October 2025 amendment alongside the CERT-In Directions of 28 April 2022 and the DPDP Rules 2025 breach provisions — so the CTSO can see, obligation by obligation, who must be told what and by when. Explore Veritect Legal AI →

Step 4 — Build the dual-notification runbook

Rule 6 is the provision that will define your operational maturity.

Stage Deadline What goes in
Initial notification to the Central Government 6 hours from detection Fact of the incident; high-level classification
Detailed report 24 hours Users affected, duration, geographical scope, extent of disruption to networks and services, economic and societal impact, remedial measures taken or proposed

Three drafting points decide whether the runbook survives a real incident.

  • Define "detection" internally. The clock runs from detection, so the runbook must fix who is competent to declare detection and at what alert severity — otherwise the six hours are spent debating whether they have started.
  • Cover the "potential" limb. A security incident is an event with an actual or potential adverse effect on telecom cyber security. Near-misses and precursor indicators are in scope, which is broader than most SOC escalation matrices assume.
  • File twice. The CERT-In six-hour obligation under Section 70B(6) of the IT Act, 2000 runs in parallel to two different authorities. Build a single intake that forks into two notification templates, and record both acknowledgement references.

For context on how tight this is: India's six hours sits against 72-hour reporting timelines under the United States' Cyber Incident Reporting for Critical Infrastructure Act, 2022 and Article 23 of the EU NIS2 Directive. Industry consultation sought 24 hours; DoT retained six.

Step 5 — Prepare for identifier suspension (Rule 5)

Where an identifier is associated with conduct endangering telecom cyber security, the Central Government may identify the identifier and its holder, issue a show-cause notice under Rule 5(2), and direct the entity to temporarily suspend or permanently disconnect it. In an emergency, an order may issue without prior notice, recording reasons, with post-decisional review to follow.

For the operator, build the capability to execute a suspension direction and to evidence exactly what was suspended and when. For a customer on the receiving end, the emergency limb is the most challengeable part of the Rules: the standard grounds are absence of reasons on the face of the order, disproportionate scope where a class has been suspended without individualised assessment, failure to convene the post-decisional review in time, and the proportionality standard in Anuradha Bhasin v. Union of India, (2020) 3 SCC 637.

Step 6 — Handle Rule 7 data demands correctly

Rule 7 lets authorised Central Government agencies require traffic data or other data, excluding the contents of messages, for the purpose of ensuring telecom cyber security. The Government may also direct the entity to establish infrastructure at designated points for collection, analysis and transmission, and may share data onward with law-enforcement or national-security agencies subject to safeguards.

The single most important response discipline: identify which power is invoked on the face of the demand. Rule 7 targets non-content traffic data for a cyber-security purpose. Section 20 of the Telecommunications Act, 2023, read with the Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 notified on 6 December 2024, targets message content on public-emergency or public-safety grounds with competent-authority approval and review-committee oversight. The safeguards available to challenge each differ materially, and a demand answered under the wrong framework forfeits them.

Step 7 — TIUE obligations and the MNV platform

Rule 7A, inserted on 22 October 2025, creates a Government-run Mobile Number Validation ('MNV') platform. A TIUE can query whether a telecommunication identifier supplied by a customer matches the user recorded in the telecom entity's database, with integration expected for high-risk flows — KYC, onboarding, transaction authorisation.

Because an MNV query transmits the customer's mobile number and limited attributes, settle the DPDP lawful basis before enabling each flow — whether consent under the Digital Personal Data Protection Act, 2023 or the legitimate use of fulfilling a legal obligation — and record the determination per flow rather than once for the platform.

Step 8 — IMEI registration (Rule 9)

Manufacturers, and since the 2025 Amendment importers, must register the IMEI of equipment with the Central Government before first sale in India on the designated portal. Tampering with, altering, obliterating or removing a unique equipment identifier is prohibited; the Government may maintain a database of tampered or restricted IMEIs and require sellers and buyers of used equipment to check it before transacting. Rule 9 offences sit inside the Section 42(3) criminal gateway of the Telecom Act.

Founder checklist

  • Answer the classification question in writing — telecommunication entity, TIUE, or both — for every group entity, and re-run it whenever a product starts using mobile numbers for identity.
  • Board-resolve the CTSO appointment and diarise a quarterly check that the DoT portal details are current.
  • Rehearse the six-hour clock, not just document it. Run a tabletop where the only question is who declares detection and at what severity.
  • Fork the notification. One incident, two regulators, two acknowledgement references retained.
  • Triage every data demand by the power invoked — Rule 7 traffic data or Section 20 content interception — before anyone in the team produces anything.

Frequently Asked Questions

Q1: Does exemption from authorisation exempt us from these Rules?

No. The definition of telecommunication entity expressly includes both an authorised entity under Section 3(1) of the Telecommunications Act, 2023 and a person exempted from the authorisation requirement under Section 3(3). Captive-network operators above the prescribed threshold are a common example of an exempt class that remains inside the Rules.

Q2: What is the penalty exposure?

The Rules carry no standalone penalty schedule; enforcement runs through Chapter VIII of the Telecommunications Act, 2023. Section 42(3) provides imprisonment up to three years or a fine up to ₹50 lakh or both for specified offences including identifier tampering. Section 43 provides a civil penalty up to ₹5 crore, adjudicated by an Adjudicating Officer of Joint Secretary rank or above exercising Code of Civil Procedure, 1908 powers over summoning, evidence on affidavit and requisition of records. Section 44 covers failure to supply information. Where the same incident is reportable to CERT-In, Section 70B(7) of the IT Act, 2000 attaches in parallel — up to one year's imprisonment or a fine up to ₹1 crore or both.

Q3: Where do we appeal an adjudication order?

Civil penalties are imposed by the Adjudicating Officer, with appeal to the Designated Appeal Committee under the Telecom Act and onward to the Telecom Disputes Settlement and Appellate Tribunal for specified classes. Criminal offences under Section 42 are tried in the ordinary criminal courts. Judicial review of an adjudication order lies to the jurisdictional High Court under Article 226.

Q4: Is Critical Telecommunication Infrastructure covered by these Rules?

Separately. Section 22(1) of the Telecom Act is the parent of the Telecom Cyber Security Rules; Section 22(2) allows the Central Government to declare a network or part of it as Critical Telecommunication Infrastructure and impose additional standards, operationalised by the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024. A CTI designation adds obligations on top of this playbook; it does not displace them.

Q5: There were multiple gazette numbers for the 2025 amendment. Which one is operative?

The amendment issued as G.S.R. 771(E) dated 22 October 2025, following a draft at G.S.R. 411(E) of 24 June 2025. An inadvertent re-publication as G.S.R. 796(E) on 29 October 2025 was rescinded by G.S.R. 863(E) dated 25 November 2025. Cite the 22 October 2025 notification.

Q6: Do the new DoT network authorisation rules change any of this?

They add a separate constraint rather than altering these Rules. The Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, published 20 July 2026, include Rule 25(3), requiring the network system and all associated data, logs and information to be located in India with no copy routed or made available abroad. For a CTSO that matters directly: an offshore SOC or log-analytics tier that satisfies Rule 3 monitoring may still breach Rule 25(3) if the entity holds one of the six network authorisations.


Beyond this brief Preview

Veritect Legal AI holds the operative chain: the Telecommunications Act, 2023 with Sections 3, 20, 22, 42, 43, 44 and 56; the Telecom Cyber Security Rules, 2024 as amended by G.S.R. 771(E) of 22 October 2025; the Critical Telecommunication Infrastructure Rules, 2024; the lawful-interception rules of 6 December 2024; the 2026 network authorisation rules; the CERT-In Directions of 28 April 2022; and the DPDP Act, 2023 with the DPDP Rules, 2025.

Practitioner-level content available on Veritect Legal AI:

  • Entity-classification memorandum template — telecommunication entity vs TIUE vs both
  • CTSO board-resolution and portal-registration pack with quarterly refresh checklist
  • Dual six-hour notification runbook with a shared intake and forked DoT / CERT-In templates
  • Rule 7 vs Section 20 demand-triage flowchart with response templates for each power
  • MNV per-flow DPDP lawful-basis assessment sheet

Access Veritect Legal AI →


Primary Sources

Primary source

Title: Telecommunications (Telecom Cyber Security) Rules, 2024
Issuer: Department of Telecommunications, Ministry of Communications
Effective: 2024-11-21
Gazette: Notified 21 November 2024; Amendment Rules vide G.S.R. 771(E) dated 22 October 2025

Frequently asked

Who must appoint a Chief Telecommunication Security Officer?

Every telecommunication entity, under Rule 8 of the Telecommunications (Telecom Cyber Security) Rules, 2024. The CTSO must be a citizen of India and a resident of India, must be responsible to the board of directors or equivalent governing body, and the entity must register the CTSO's details — name, designation, office address, email, mobile and office phone — with the Central Government on the designated portal, refreshed on any change. A 'telecommunication entity' covers both an authorised entity under Section 3(1) of the Telecommunications Act, 2023 and a person exempted from authorisation under Section 3(3).

Is the CTSO the same person as our CISO?

Not by default. The CTSO is a statutory office with defined statutory duties and personal exposure in a penalty proceeding; the CISO is a role maintained under legacy DoT security conditions and under the RBI, SEBI and IRDAI cyber frameworks. A large operator may designate its existing CISO as CTSO, but the appointment should be made by board resolution and the roles should be documented separately, because the CTSO is the named point of contact for Rule 6 incident reporting and Rule 7 traffic-data requests.

What is the incident-reporting timeline and what triggers it?

Rule 6 requires notification to the Central Government within 6 hours of detection of a security incident, followed by a detailed report within 24 hours covering users affected, duration, geographical scope, extent of disruption, economic and societal impact, and remedial measures taken or proposed. The trigger is wide: Rule 2 defines a security incident as an event having an actual or potential adverse effect on telecom cyber security, so the 'potential' limb pulls near-misses and precursor indicators into the reporting net.

Does this replace the CERT-In six-hour reporting obligation?

No — both run in parallel on the same incident. Telecom entities are body corporates for the purposes of the Information Technology Act, 2000 and remain within CERT-In's jurisdiction under Direction (ii) of the CERT-In Directions of 28 April 2022 issued under Section 70B(6). The practical consequence is that the CTSO must be able to file two separate six-hour notifications to two different authorities, with a 24-hour detailed report to DoT under Rule 6 and the prescribed follow-ups to CERT-In.

Our company is a fintech, not a telco. Are we in scope?

Possibly, as a Telecommunication Identifier User Entity. The Amendment Rules of 22 October 2025 (G.S.R. 771(E)) inserted the TIUE category — a person, other than a telecommunication entity, that uses telecommunication identifiers issued by the Central Government or by a telecommunication entity to identify customers or users, or to provision or deliver services to them. Banks, NBFCs, fintechs, payment aggregators, digital lending apps, e-commerce and ride-hailing platforms and OTT messaging services that verify accounts by mobile number are within it.

What is the Mobile Number Validation platform?

Rule 7A, inserted by G.S.R. 771(E) dated 22 October 2025, introduces a Government-run Mobile Number Validation platform through which a TIUE can validate whether a telecommunication identifier supplied by a customer matches the user recorded in the telecom entity's database. It is aimed at high-risk flows such as KYC, onboarding and transaction authorisation. Because an MNV query transmits the customer's mobile number and limited attributes, the lawful basis under the Digital Personal Data Protection Act, 2023 should be settled before each flow is enabled.

How does Rule 7 traffic-data collection differ from Section 20 interception?

They are different powers with different safeguards, and the distinction decides how you respond. Rule 7 of the TCS Rules allows authorised Central Government agencies to require traffic data or other data expressly excluding the contents of messages, for the purpose of ensuring telecom cyber security. Section 20 of the Telecommunications Act, 2023 read with the Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 notified on 6 December 2024 governs interception of message content on public-emergency or public-safety grounds, with competent-authority approval and review-committee oversight. Identify on the face of the demand which power is invoked before responding.

What are the IMEI obligations?

Under Rule 9, manufacturers — and, after the 2025 Amendment, importers — of equipment bearing an International Mobile Equipment Identity must register the IMEI with the Central Government before first sale in India, in the form specified on the designated portal. Intentional tampering, alteration, obliteration or removal of a unique telecommunication equipment identifier is prohibited, the Central Government may maintain a database of tampered or restricted IMEIs, and sellers and buyers of used equipment may be required to check it. Rule 9 consolidates and expands the Prevention of Tampering of the Mobile Device Equipment Identification Number Rules, 2017, which it supersedes.

Prerequisites

  • Board resolution appointing the Chief Telecommunication Security Officer
  • An Indian-citizen, India-resident candidate answerable to the board or equivalent governing body
  • Security Operations Centre coverage, in-house or contracted
  • Certified audit agency engaged for the Rule 3 periodic security audit
  • Determination of whether the entity is a telecommunication entity, a TIUE, or both

Sanctions for non-compliance

The Rules carry no standalone penalty schedule; contraventions are punishable under Chapter VIII of the Telecommunications Act, 2023 — Section 42(3) (imprisonment up to three years or fine up to Rs 50 lakh or both, covering identifier tampering under Rule 9), Section 43 (civil penalty up to Rs 5 crore, adjudicated by an Adjudicating Officer of Joint Secretary rank or above with Code of Civil Procedure, 1908 powers), and Section 44 (failure to supply information). Where the same incident is also reportable to CERT-In, Section 70B(7) of the Information Technology Act, 2000 attaches in parallel — imprisonment up to one year or fine up to Rs 1 crore or both, the 'one crore' figure substituted for 'one lakh' by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023.

Tags

telecom-emerging telecom-cyber-security-rules-2024 ctso incident-reporting mobile-number-validation tiue telecommunications-act-2023 imei
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free