Draft Telecommunications (Telecom Cyber Security) Amendment Rules, 2025: A Comprehensive Review
The Ministry of Communications (MoC) issued the Draft Telecommunications (Telecom Cyber Security) Amendment Rules, 2025, on June 24, 2025, under Section 22(1) and Section 56(2) (v) of the Telecommunications Act, 2023. These Draft Rules propose to amend The Telecommunications (Telecom Cyber Security) Rules, 2024, aiming to enhance the real-time validation and suspension of telecommunication identifiers at all points of use. The new rules aim to bring non-operator users of telecom identifiers, such as OTT apps and payment platforms, under the cyber security regime of the Telecommunications framework.
Key Takeaways:
- The Draft Rules introduce the concept of Telecommunication Identifier User Entity (TIUE), encompassing non-operator users of telecom identifiers like OTT apps and payment platforms.
- The new rules expand the definitions and scope of applicability, clarifying the roles of Licensee and Mobile Number Validation (MNV) platform.
- Data sharing and cyber security obligations are extended to TIUEs, requiring them to share identifier-related data directly with the Central Government and adhere to general security obligations.
- The Central Government is empowered to temporarily suspend any identifier and require operators and TIUEs to cease use without prior notice when public security is at risk.
- A centralized, real-time validation service (MNV Platform) is established to validate telecommunication identifiers, with TIUEs initiating suo moto or complying with government-directed validation requests.
- IMEI bearing device manufacturers are mandated to assist in tampering incidents and not reuse IMEIs already deployed in India.
- A tampered IMEI database and pre-sale checks against this registry are introduced to restrict secondary-market transactions.
- The MNV Platform requires TIUEs to submit validation requests with a digital template and abide by the prescribed fee schedule.
- The Central Government or an authorized agency must set up and operate the MNV Platform, which will process and respond to validation requests.
- All participants must ensure compliance with applicable laws related to data protection when handling subscriber data.
Statistics:
- INR 1.50 per validation request for TIUEs acting on government direction, with the government retaining INR 0.50 and the authorized entity receiving INR 1.00.
- INR 3.00 per validation request for TIUEs initiating su moto, with the government retaining INR 1.00 and the authorized entity receiving INR 2.00.
Sources:
- Draft Telecommunications (Telecom Cyber Security) Amendment Rules, 2025 - https://www.teamleaseregtech.com/fileviewer/?f=https://avantiscdnprodstorage.blob.core.windows.net/legalupdatedocs/43915/MoC-issued-the-Draft-Telecommunications-Telecom-Cyber-Security-Amendment-Rules-2025-Jun252025.pdf
- Telecommunications Act, 2023 - https://egazette.gov.in/WriteReadData/2023/250880.pdf
- The Telecommunications (Telecom Cyber Security) Rules, 2024 - https://www.medianama.com/wp-content/uploads/2024/11/notified-telecom-rules-Copy.pdf