(1) The telecommunication entity shall–
(a) within six hours of becoming aware of a security incident affecting its telecommunication network or telecommunication service, report the same to the Central Government with relevant details of the affected system including the description of such incident; and
(b) within twenty-four hours of becoming aware of such incident, furnish the following information, as applicable:
(i) the number of users affected by the security incident;
(ii) the duration of the security incident;
(iii)the geographical area affected by the security incident;
(iv) the extent to which the functioning of the telecommunication network or telecommunication service is affected;
(v) the remedial measures taken or proposed to be taken; and
(vi) any other information it considers relevant.
(2) The Central Government may, where it determines that disclosure of the security incident is in the public interest, inform the public of such security incident, or require the affected telecommunication entity to do so.
1 Ins. by G.S.R. 771(E), dated 22.10.2025.
(3) The Central Government may require the affected telecommunication entity to —
(a) provide information needed to assess the security of the telecommunication network and telecommunication service including telecom cyber security policy;
(b) carry out a security audit by a certified agency as may be determined by the Central Government.
(4) The Central Government may issue directions including measures required to remedy a security incident or prevent one from occurring when a significant threat has been identified and may also specify the time limits for implementation of such directions to the affected telecommunication entity.