India follows a mandatory telecom security certification framework for all equipment used in public telecom networks. The framework is administered by the Department of Telecommunications (DoT) through the National Centre for Communication Security (NCCS) to safeguard telecom networks, which are considered critical national infrastructure, from security threats and unauthorised access.
Under this framework, telecom equipment must meet Indian Telecommunication Security Assurance Requirements (ITSAR) and undergo security testing at designated Telecom Security Testing Laboratories (TSTLs) before being deployed.
Scope of Telecom Security Certification in India
Over the last two years, the scope of certification has expanded to encompass newer technologies, including 5G core network equipment, fibre broadband systems and advanced customer premises devices. This expansion has increased the need for updated compliance processes, greater testing capacity and better sequencing of regulatory approvals.
The telecom security certification framework applies to a wide range of equipment connected to Indian telecom networks. This includes access, transport, control, and application-layer components across wireless and wireline domains. Typical categories include IP routers, Wi-Fi customer premises equipment (CPEs), Optical Line Terminals (OLTs), Optical Network Terminals (ONTs), and multiple 5G core network functions such as Access and Mobility Management Function (AMF) and Session Management Function (SMF).
End-user and ICT devices, including mobile handsets, dongles, residential gateways and certain IoT-class devices, are also within scope. Security testing conducted by TSTLs encompasses areas such as access control, authentication, software and source code security, secure execution environments, audit logging, and cryptographic data protection. Testing methodologies reference globally recognised benchmarks, including OWASP Top 10, ETSI EN 303 645 for IoT security, and NIST-aligned penetration testing practices.
As mandatory security certification was extended to additional product categories, many operational challenges were identified. Testing capacity was limited, with a small number of designated labs handling a growing volume of equipment. Certification timelines lengthened, testing costs were high and the pace of technological deployment, particularly for 5G and fibre broadband, accelerated. These factors created a risk that compliance processes could delay network rollouts and disproportionately impact domestic manufacturers, especially MSMEs and startups.
To address this sequencing challenge, the DoT introduced an interim regulatory mechanism intended to preserve security oversight while preventing deployment bottlenecks.
Pro-Tem Security Certification
In October 2024, the government introduced Pro-Tem (pro tempore) security certification. Pro-Tem certification allows telecom equipment to be deployed on a provisional basis before completion of full security testing, subject to defined conditions. Manufacturers self-declare conformity with ITSAR requirements and submit equipment for parallel testing at designated TSTLs.
Under Pro-Tem certification, security testing is not waived. Instead, testing runs concurrently with deployment. If vulnerabilities are identified, manufacturers are required to remediate them within specified timelines. The DoT and NCCS retain the authority to impose conditions, withdraw approvals, or order de-deployment in cases of unresolved or critical security risks.
In December 2025, the DoT announced a set of significant compliance-related updates. The Pro-Tem security certification was extended by two additional years from January 1, 2026. At the same time, the validity of individual Pro-Tem certificates was increased from six months to two years, reducing the frequency of renewals and administrative overhead.
The government also implemented substantial reductions in testing and lab-related fees. Application and renewal fees for TSTLs were reduced by more than 50 percent, with additional concessions for startups, MSMEs, women-owned enterprises, and full fee waivers for government and academic laboratories.
Additionally, compliance processes for fibre broadband equipment were simplified. From January 1, 2026, ONT devices are subject to mandatory ITSAR compliance under revised norms that allow multiple product variants to be tested under a single certification process. This reduces the number of test cases and associated costs without altering the underlying security requirements.
Compliance Implications for Manufacturers and Operators
Pro-Tem certification alters the sequencing of obligations rather than the substance of requirements. Manufacturers must maintain comprehensive documentation, internal security controls and readiness to respond to testing outcomes. Telecom operators benefit from improved predictability in equipment availability and rollout timelines, particularly for 5G and fibre network expansion.
Domestic manufacturers and MSMEs experience lower entry barriers due to reduced testing costs and deferred certification timelines, while remaining subject to the same security standards as global vendors.
Forward Timeline
2026–2027
- Additional categories of telecom equipment are expected to be brought under mandatory security certification.
- This includes advanced transmission systems and expanded 5G network components.
- The Pro-Tem security certification regime is scheduled to remain in force during this transition period.
Post-2027
- Full security certification is intended to operate without provisional or interim mechanisms.
- The framework is expected to be supported by expanded testing capacity.
- Streamlined certification and compliance processes are expected to be in place.
India’s telecom security certification framework continues to mandate comprehensive security testing for all equipment deployed in public networks. Recent regulatory changes modify the timing and cost of compliance while preserving enforceability, testing requirements, and enforcement powers. For compliance professionals, the current regime requires close monitoring of certification timelines, testing outcomes, and post-deployment obligations as the framework moves toward a fully operational, capacity-aligned security regime.