Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

gations relating to content moderation and grievance handling. It also mandates all intermediaries to estab - lish a grievance redressal mechanism for addressing complaints from users or affected persons. DPDPA (2023) and DPDP Rules (2025) While primarily the DPDPA and the DPDP Rules are a data protection regime, it imposes cyber-risk manage - ment and breach prevention obligations on organisa - tions processing personal data. The Act is presently implemented in a phased manner as prescribed in the Rules with full effect by May 2027. The Act applies to all data fiduciaries processing digi - tal personal data within India as well as foreign enti - ties offering goods or services to individuals in India. It mandates the implementation of reasonable secu - rity safeguards and requires notification of personal data breaches to regulators and affected individuals. Codes of practice, guidance and directions issued by the Data Protection Board of India (DPBI) play a bind - ing role in enforcement and compliance. CERT-In Rules and Directions Under the IT Act, the CERT-In is authorised to issue binding rules and directions governing cybersecurity incident reporting and response. The scope includes mandatory reporting of specified cyber incidents, maintenance of system logs, time-bound reporting obligations, audit requirements and co-operation with government investigations. These obligations apply to service providers, intermediaries, data centres, cloud service providers, corporate entities and other cov - ered organisations. CERT-In Directions apply to entities operating in India and may extend to foreign entities where services are offered in India or Indian digital infrastructure is affect - ed. CERT-In advisories, while often framed as guid - ance, operate as de facto binding standards when issued as formal directions under statutory authority. NCIIPC Rules and Guidelines The NCIIPC has framed the Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 (the “NCIIPC Rules”) and issued Guidelines for the Protection of National Critical Information Infrastructure, 2015, (the “NCIIPC

Guidelines”) to safeguard India’s CII from unauthor - ised access, modification, use, disclosure and disrup - tion to ensure a safe, secure and resilient information infrastructure for critical sectors in the country. This framework applies to entities notified as “Pro - tected Systems” operating in sectors such as power, banking, telecommunications, transport and govern - ment services, where disruption could have a debili - tating impact on national security or public order. Sector-Specific Cybersecurity Regulations Sectoral regulators, including the RBI, SEBI, IRDAI and the DoT, issue binding cybersecurity and resil - ience frameworks applicable to entities within their respective domains as referred to in 1.1 Cybersecurity Regulation Strategy . These frameworks impose enhanced cyber-risk man - agement, governance, audit, testing and reporting obligations on regulated entities. They are binding within their respective sectors and enforced through supervisory inspections, penalties and licensing con - ditions. Proposed Digital India Act The proposed Digital India Act is intended to modern - ise India’s digital regulatory framework and replace or supplement parts of the IT Act. It is expected to introduce clearer cybersecurity governance norms, strengthen enforcement powers, and formalise obli - gations relating to digital intermediaries, platforms and online services, including cyber-resilience and incident reporting requirements. India’s cybersecurity framework operates through complementary and overlapping regimes. The IT Act and CERT-In Directions establish baseline cyberse - curity and incident reporting obligations applicable across sectors. The NCIIPC framework imposes heightened requirements for critical infrastructure. The DPDPA overlays data protection and breach noti - fication obligations where personal data is involved. Sectoral regulators impose additional requirements tailored to specific risk environments. In practice, organisations may be subject to parallel compliance obligations arising from multiple frame -

194 CHAMBERS.COM

Powered by