[Home](/)/[Resources](/resources)/India Telecom Security Testing

IndiaTelecom

# India Telecom Security Testing — DoT and NCCS Requirements

India's Department of Telecommunications (DoT) has implemented mandatory security testing and certification for telecom equipment — including telecom network elements, Wi-Fi access points, and certain IoT devices — through the National Centre for Communication Security (NCCS) and the Trusted Telecom Portal. For telecom equipment manufacturers, understanding which products require security certification, the testing process, and the interaction with TEC MTCTE type approval is essential for market access.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Findia-telecom-security-testing)

At a glance

Security testing body

NCCS (DoT)

Type approval body

TEC (MTCTE)

Portal

Trusted Telecom Portal

Testing timeline

3-6 months

Key operators

BSNL, MTNL, Jio, Airtel

## DoT security testing framework

India's telecom security testing framework sits alongside — but is distinct from — the technical type approval process managed by TEC. NCCS handles security evaluation while TEC handles interface and performance conformance. Both are required for telecom network equipment, and the two processes run in parallel rather than sequentially.

### NCCS — National Centre for Communication Security

**Details:** NCCS is the government-designated security testing laboratory under the Department of Telecommunications (DoT). It conducts mandatory security evaluation of telecom equipment against DoT's security requirements framework. NCCS is distinct from TEC (Telecommunications Engineering Centre), which handles type approval.

### Trusted Telecom Portal

**Details:** The Trusted Telecom Portal is DoT's product listing platform for security-certified telecom equipment. Products that pass NCCS security testing are listed on the portal, enabling government-owned operators (BSNL, MTNL) and private operators to verify that equipment meets India's trusted telecom requirements.

### TISM — Telecom Information Security Management System

**Details:** TISM is DoT's security standards framework for telecom equipment, specifying the security controls and evaluation criteria against which NCCS conducts product testing. TISM draws on international frameworks (ISO 27001, NIST) adapted for telecom network equipment security.

### TEC MTCTE and DoT security certification

**Details:** TEC's Mandatory Testing and Certification of Telecom Equipment (MTCTE) scheme covers technical interoperability and interface standards for telecom equipment. DoT security certification is a separate requirement that sits alongside MTCTE — both are required for telecom equipment sold to Indian operators. The two certifications have different scopes, test labs, and application processes.

## Products requiring DoT security testing

Not all telecom-connected products require NCCS security testing. The requirement is concentrated on infrastructure equipment deployed in operator networks and critical sectors. Consumer products generally fall outside the mandatory security testing scope, though this boundary is subject to DoT notification changes.

01

Telecom network equipment — base stations (2G/3G/4G/5G), core network elements, routers, and switches deployed in telecom operator networks — requires both TEC MTCTE and DoT security testing before supply to Indian operators.

02

Wi-Fi access points — enterprise and carrier-grade APs operating in 6 GHz and certain 5 GHz bands, particularly those supplied to telecom operators or deployed in critical infrastructure, are subject to Trusted Telecom Portal requirements.

03

Telecom terminal equipment with encryption — VoIP phones, encrypted push-to-talk (PTT) devices, and encrypted communication devices used in telecom networks require DoT security testing if they implement encryption algorithms in the call path.

04

IoT devices in critical infrastructure sectors — IoT devices using licensed telecom spectrum and deployed in power, water, transport, or defence sectors may require DoT security testing under sector-specific regulations that reference the Trusted Telecom framework.

05

Equipment supplied to BSNL and MTNL — government-owned operators are required by their operating licence conditions to procure equipment from vendors listed on the Trusted Telecom Portal. Equipment not listed cannot be supplied to BSNL or MTNL regardless of TEC MTCTE status.

## Security testing process and NCCS

The NCCS evaluation process is documentation-intensive — security architecture transparency and supply chain disclosure are evaluated alongside functional security testing. Companies with mature security documentation practices (aligned with frameworks like ISO 27001 or NIST CSF) are better positioned to complete evaluation efficiently.

### Security evaluation against DoT requirements framework

**Details:** NCCS evaluates products against DoT's published security requirements, which cover network interface security, authentication mechanisms, cryptographic implementation, firmware update security, logging and audit trails, and supply chain transparency. The specific requirements vary by product category.

### NCCS testing timeline and product family grouping

**Details:** Security evaluation at NCCS typically takes 3-6 months for complex telecom network equipment. Products with similar hardware platforms and software stacks can be grouped into product families, reducing redundant testing. Early engagement with NCCS before formal application is advisable to understand the applicable test scope.

### Source code review and documentation requirements

**Details:** Software-defined networking elements and products with significant software components may require source code review as part of NCCS evaluation. All applicants must provide: security architecture document, cryptographic algorithms declaration (algorithms, key lengths, implementation), supply chain disclosure (country of origin for hardware components and software), and vulnerability management process documentation.

### Post-certification surveillance

**Details:** Certified products are subject to post-certification surveillance — DoT can require re-evaluation if significant firmware updates are released or if vulnerabilities are discovered. Manufacturers must notify DoT of security vulnerabilities affecting certified products and submit to re-evaluation if required.

## Trusted Telecom Portal and procurement implications

Listing on the Trusted Telecom Portal is a commercial prerequisite for selling into the Indian operator market — particularly for government-owned operators and government-funded network deployments. Understanding the portal's requirements and the procurement conditions that reference it is as important as the technical testing process itself.

01

Trusted Telecom Portal listing: after NCCS security certification, products are listed on the Trusted Telecom Portal with their certification details. The listing is public and accessible to operators verifying vendor compliance. Delisting occurs if certification lapses or is revoked.

02

BSNL and MTNL mandatory procurement from trusted vendor list: India's government-owned telecom operators are required under their operating licences to source network equipment exclusively from vendors listed on the Trusted Telecom Portal. This creates a hard commercial requirement for any vendor selling to the government operator market.

03

Private operator licence conditions referencing trusted telecom: private telecom operators (Jio, Airtel, Vi) are increasingly required under their unified licence conditions to prefer or exclusively source critical network equipment from Trusted Telecom Portal-listed vendors, particularly for 5G core and radio access network equipment.

04

TCCF — Telecom Cyber Crisis Framework: certified vendors are incorporated into DoT's Telecom Cyber Crisis Framework, which defines incident reporting obligations when security breaches affecting certified equipment are discovered. Vendors must report incidents to DoT within defined timelines.

05

Interaction with allied advisories: DoT's Trusted Telecom framework is informed by supply chain security concerns shared by allied regulators (NCSC UK, CISA US). Vendors whose equipment has been flagged in foreign supply chain advisories face additional scrutiny in the NCCS evaluation process.

## Frequently asked questions

### Is DoT security testing mandatory for all telecom equipment sold in India?

No — mandatory security testing applies to specific categories of telecom equipment, not all products sold in India. The requirement applies primarily to: telecom network equipment (base stations, routers, switches for operator networks), equipment supplied to BSNL/MTNL under their licence conditions, and products in categories specifically notified by DoT. Consumer products like smartphones, home Wi-Fi routers, and consumer IoT devices sold in the retail market are not subject to NCCS security testing, though they may require TEC MTCTE and BIS CRS.

### What is the difference between TEC MTCTE type approval and DoT security certification?

TEC MTCTE (Mandatory Testing and Certification of Telecom Equipment) covers technical performance, interoperability, electromagnetic compatibility, and interface standards for telecom equipment. DoT security certification (via NCCS) covers cybersecurity — whether the equipment is secure against network attacks, implements strong cryptography, has a secure software supply chain, and meets DoT's security architecture requirements. Both are required for telecom network equipment sold to Indian operators, but they are separate applications with different labs, test scopes, and timelines.

### How long does NCCS security testing typically take?

For complex telecom network equipment (base stations, core network elements), NCCS security evaluation typically takes 3-6 months from application submission to certificate issuance. Simpler products with limited network interfaces may complete in 2-3 months. Timeline depends on: completeness of submitted documentation, whether source code review is required, NCCS lab workload, and whether any deficiencies require remediation and re-testing. Engaging NCCS through pre-application consultation before formal submission can reduce delays.

### Does the Trusted Telecom Portal requirement apply to consumer Wi-Fi routers?

Consumer Wi-Fi routers sold through retail channels (for home and small office use) are not currently subject to mandatory Trusted Telecom Portal listing. The requirement primarily targets equipment deployed in operator networks and critical infrastructure. However, enterprise-grade Wi-Fi access points — particularly 6 GHz APs — deployed in operator-managed networks or supplied under government tenders may require Trusted Telecom Portal listing. The boundary between consumer and enterprise products is defined by deployment context and procurement channel, not product specifications alone.

**Disclaimer:** This page is an educational resource only. DoT security testing requirements, NCCS procedures, and Trusted Telecom Portal listing criteria are subject to change by notification. Confirm current requirements directly with DoT and TEC before initiating certification.

🇮🇳 India roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇮🇳 India compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/10-india-wireless-type-approval-wpc-eta-mtcte)[Prefer to read? Get the book — $24.99](/books/10-india-wireless-type-approval-wpc-eta-mtcte)

Related guides

*   [TEC MTCTE CertificationComplete guide to TEC MTCTE certification: Mandatory Testing and Certification of Telecom Equipment, phase-wise implementation,…](/guides/tec-mtcte-certification)
*   [TEC Type Approval for RoutersComplete guide to TEC MTCTE (Mandatory Testing and Certification of Telecom Equipment) for routers, switches, and network equip…](/guides/tec-type-approval-routers)
*   [WPC ETA CertificationComplete guide to WPC ETA certification: equipment type approval requirements, application process, test reports, labeling, and…](/guides/wpc-eta-certification)
*   [India DPDP Act for HardwareHow India's Digital Personal Data Protection Act 2023 applies to connected hardware — consent architecture, data fiduciary obli…](/guides/india-dpdp-act-hardware)