Telecommunications (Telecom Cyber Security) Amendment Rules, 2025 Enhance Digital Security Framework

The Central Government issued the Telecommunications (Telecom Cyber Security) Amendment Rules, 2025, a significant piece of delegated legislation aimed at bolstering the nation's telecom cyber security infrastructure. These rules, published in the Gazette of India on October 22, 2025, came into force on the same date. The amendment rules were formulated under the powers conferred by clause (v) of sub-section (2) of section 56 of the Telecommunications Act, 2023. A draft of these rules was initially published on June 24, 2025, inviting objections and suggestions from the public, which were duly considered by the Central Government before the final notification. The amendments introduce several key provisions, including new definitions and expanded regulatory oversight.
The new rules define "licensee" as a person holding a license to provide telecommunication services under the Indian Telegraph Act, 1885. Crucially, they introduce the concept of a "TIUE (telecommunication identifier user entity)," which refers to any person, other than a licensee or authorised entity, that uses telecommunication identifiers for customer identification or service provisioning. A "MNV platform" (mobile number validation platform) is also defined as a system established under the new Rule 7A to enable validation of telecommunication identifiers. The amendments empower the Central Government to seek data related to telecommunication identifiers used by TIUEs and expand the scope of temporary suspension and permanent disconnection orders for telecommunication identifiers to include TIUEs. Specifically, where immediate action is deemed necessary in the public interest, the Central Government may direct a telecommunication entity to temporarily suspend the use of a relevant telecommunication identifier and a TIUE to temporarily suspend its use for identification or service delivery. Furthermore, modifications to such orders can include directions for permanent disconnection by the telecommunication entity and prohibition or circumscription of use by the TIUE to facilitate reuse of identifiers.
A central objective of these amendments is to enhance telecom cyber security and prevent security incidents. The legislation provided: “The Central Government, for ensuring telecom cyber security and preventing security incidents, shall either by itself, or through an agency authorised by it, establish a MNV platform and issue directions to authorised entities and licensees to participate on such platform.” This Mobile Number Validation (MNV) platform will allow TIUEs, or Central/State Governments, to request validation of telecommunication identifiers against authorised entity or licensee databases, subject to specified fees. This mechanism aims to address issues arising from the misuse of telecommunication identifiers and to ensure the authenticity of users linked to various services. The rules also introduce new provisions concerning International Mobile Equipment Identity (IMEI) numbers. The Central Government may now issue directions to manufacturers of telecommunication equipment not to assign IMEIs already in use in India to new equipment. Additionally, the Central Government, or an authorised agency, will maintain a database of tampered or restricted IMEIs. Persons engaged in the sale or purchase of used telecommunication equipment bearing IMEI numbers are now mandated to access this database and ensure they do not deal in equipment listed therein, upon payment of specified fees. These measures are designed to curb the circulation of stolen or illicit telecommunication devices and enhance the traceability of equipment. The amendments also extend various compliance and reporting obligations under the principal rules, the Telecommunications (Telecom Cyber Security) Rules, 2024, to include TIUEs, thereby broadening the regulatory net to cover a wider array of entities involved in the telecommunications ecosystem.
Keywords: Telecommunications, Cyber Security, Amendment Rules, MNV Platform, IMEI, TIUE, India, Telecom Act 2023, Digital Security, Regulatory Compliance
Geo Tags: India, Not Applicable