Central Government Proposes Amendments to Telecommunications (Telecom Cyber Security) Rules

The Ministry of Communications recently issued a notification in the Gazette of India, outlining the draft Telecommunications (Telecom Cyber Security) Amendment Rules, 2025. This notification, published on June 24, 2025, invited objections and suggestions from the public regarding the proposed rules for a period of thirty days from the date of their availability. Once finalized and published in the Official Gazette, these rules are intended to amend the principal Telecommunications (Telecom Cyber Security) Rules, 2024, which were originally published on November 21, 2024. The proposed amendments seek to introduce significant changes aimed at enhancing telecom cyber security and preventing security incidents by expanding regulatory oversight and establishing new validation mechanisms.
The draft rules introduce several key definitions, including "licensee," which refers to a person holding a license to provide telecommunication services under the Indian Telegraph Act, 1885. A crucial new concept is the "MNV platform," defined as a mobile number validation platform to be established under a new Rule 7A. This platform would enable validation by authorised entities and licensees regarding whether telecommunication identifiers (such as mobile numbers) correspond to the users in their databases. Furthermore, the rules define a "telecommunication identifier user entity (TIUE)" as any person, other than a licensee or authorised entity, that uses telecommunication identifiers for identifying its customers or users, or for provisioning and delivering services.
A central feature of the proposed amendments is the insertion of Rule 7A, which mandates the establishment of the Mobile Number Validation (MNV) platform. The legislation provided: “With a view to ensuring telecom cyber security and prevent security incidents, the Central Government shall by itself, or through an agency authorised by the Central Government, establish a MNV platform and issue directions to authorised entities and licensees, as regards the form and manner in which to participate on such platform.” This platform would allow TIUEs, either on their own initiative or upon direction from government authorities, to request validation of telecommunication identifiers. The Central Government or State Government, or their authorised agencies, could also seek such validation. Authorised entities and licensees would be required to undertake this validation and provide responses to the MNV platform. The rules also propose a fee structure for these validation requests, with charges ranging from nil for government entities to three rupees per request for private TIUEs, with a portion retained by the Central Government or its agency and the remainder transferred to the validating entity or licensee.
Beyond the MNV platform, the draft rules propose amendments to Rule 8 concerning International Mobile Equipment Identity (IMEI) numbers. These amendments would empower the Central Government to issue directions to manufacturers of telecommunication equipment bearing IMEI numbers, requiring them to assist with issues related to tampered equipment and to prevent the assignment of IMEIs already in use in India. A new sub-rule (6) would mandate the Central Government, directly or through an agency, to maintain a database of tampered or restricted IMEIs. Consequently, persons engaged in the sale and purchase of used telecommunication equipment in India would be required to apply for access to this database, pay a fee of ten rupees per IMEI, and ensure they do not deal with equipment listed in the database.
The proposed amendments also expand the scope of existing rules to include TIUEs. For instance, under the amended Rule 3, the Central Government would be able to seek data related to telecommunication identifiers used by TIUEs. Rule 5, which deals with immediate actions in the public interest, would be modified to allow the Central Government to direct TIUEs to temporarily suspend the use of relevant telecommunication identifiers for identification or service delivery without prior notice. Similarly, TIUEs would be brought under the purview of certain provisions in Rules 4 and 10, thereby extending regulatory compliance requirements to these entities.
The legislative intent behind these draft rules is primarily to bolster telecom cyber security and proactively prevent security incidents. The policy rationale underscores the necessity of verifying the authenticity of telecommunication identifiers and tracking mobile devices to curb fraudulent activities and misuse. By introducing the MNV platform, the government aims to address potential statutory gaps in verifying user identities associated with telecommunication services, especially those provided by entities beyond traditional telecom licensees. The inclusion of TIUEs within the regulatory framework acknowledges the increasing reliance of various service providers on telecommunication identifiers for customer interaction and service delivery, thereby expanding the ambit of security measures. The amendments concerning IMEI numbers seek to create a robust mechanism to deter the use of stolen or tampered mobile devices, which often contribute to criminal activities. The rules explicitly state that mobile number validation would be solely for the purpose of validating customers or users associated with a telecommunication identifier for linked services, with a mandatory requirement for compliance with applicable data protection laws.
Keywords: Telecommunications, Telecom Cyber Security, Amendment Rules, Mobile Number Validation, IMEI, TIUE, Central Government, India, Department of Telecommunications
Geo Tags: India District: Not Applicable