The six-hour window requires affected telecom companies to provide details of the compromised system and describe the nature of the incident
In a significant move to strengthen cybersecurity in the telecom sector, the Department of Telecommunications (DoT) has introduced the Telecom Cyber Security Rules, 2024. Effective immediately, the rules mandate telecom entities to report cybersecurity incidents to the central government within six hours of detection. This timeframe aligns with the 2022 guidelines issued by CERT-In.
The six-hour window requires affected telecom companies to provide details of the compromised system and describe the nature of the incident. These rules, released for public consultation in August 2023, aim to fortify cybersecurity measures within the telecom sector and replace the Prevention of Tampering of the Mobile Device Equipment Identification Number Rules, 2017. They have been issued under sections 22 and 56(2)(v) of the Telecommunications Act, 2024.
One of the key provisions requires telecom entities to appoint an Indian Chief Telecommunication Security Officer who must be based within the country. The entities are also obligated to adopt a comprehensive telecom cybersecurity policy and conduct periodic cybersecurity audits to ensure compliance.
A noteworthy addition to the finalised rules is the requirement to create a digital portal for implementing the regulations. This digital interface is expected to streamline reporting and compliance processes.
The rules define a security incident as an event posing “a real or potential risk on telecom cybersecurity.” Beyond the initial six-hour reporting requirement, telecom firms must submit further information within 24 hours. These details include the number of affected users, the duration and geographical scope of the incident, the extent of service disruption, and proposed remedial measures.
Unlike the draft version of the rules, the final regulations have removed the obligation to specify the “extent of impact on economic and societal activities,” making compliance more focused on technical and operational aspects.
This step by the government highlights the growing emphasis on cybersecurity across various sectors as digital infrastructure becomes increasingly integral to the country’s economy.

