India's product-security and cyber-resilience posture rests on two currently in-force instruments, plus several sector regimes this profile defers because their bound party is a licensed or government-designated status no declared LexLint activity can express.
Section 43A of the Information Technology Act, 2000 (inserted by the Information Technology (Amendment) Act, 2008 (Act 10 of 2009), with effect from 27 October 2009) makes a body corporate, the Act's own broad term for any company, firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities, liable to pay uncapped compensation to a person it injures by negligently failing to implement 'reasonable security practices and procedures' over sensitive personal data or information.
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), in force since their own publication on 11 April 2011) define that standard: a documented information security programme, deemed satisfied by certification to IS/ISO/IEC 27001.
This baseline duty is repealed once section 44(2) of the Digital Personal Data Protection Act, 2023 commences, currently scheduled for 13 May 2027 under Notification G.S.R. 843(E), and remains India's operative reasonable-security statute until then, exactly as this jurisdiction's privacy row already records.
Separately, the Indian Computer Emergency Response Team's Directions of 28 April 2022 (No. 20(3)/2022-CERT-In, issued under Information Technology Act section 70B(6), effective 27 June 2022, 60 days after issuance on the Directions' own stated offset) require 'any service provider, intermediary, data centre, body corporate and Government organisation' to report a broad enumerated list of cyber incidents to CERT-In within six hours of noticing them, to synchronise every ICT system clock to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, and to enable and securely retain logs of all ICT systems for a rolling 180 days within Indian jurisdiction.
Because 'body corporate' and 'intermediary' are the Act's own general terms for essentially any commercial or professional actor operating a computer resource in India, rather than a licensed or sector-specific status like a financial entity or an essential entity, this reaches an ordinary developer distributing software or a mobile app in India, and the row is flagged on that basis rather than deferred; the Directions separately impose a narrower five-year customer-record and KYC retention duty on data centres, virtual private server providers, cloud service providers, virtual private network service providers, and virtual asset service providers specifically, and that narrower bound-party class is named here rather than flagged, since no declared activity identifies it.
No enacted Indian statute sets security requirements a connected device or software product must meet before it is placed on the market, so the product-requirements research dimension is a researched absence.
The Reserve Bank of India's and the Securities and Exchange Board of India's own sector cybersecurity frameworks for banks, non-banking financial companies, and regulated market intermediaries, and the National Critical Information Infrastructure Protection Centre's regime for a government-designated 'protected system' under Information Technology Act section 70, each bind a licensed or government-designated status no declared LexLint activity can express; none is described here, so none is filed as an instrument, and each is named so a reader knows it exists.
CERT-In's Directions are enforced through Information Technology Act section 70B(7) (imprisonment for up to one year, a fine of up to one lakh rupees, or both, for non-compliance with a CERT-In direction), and the section 43A compensation duty through section 46's Adjudicating Officer (jurisdiction up to five crore rupees, above which the competent civil court hears the claim); no published enforcement record specific to either duty is confirmed in the primary text.
India's breach-notification duty for personal data is this jurisdiction's own privacy row, Digital Personal Data Protection Act, 2023 section 8(6) and Rule 7, not yet in force and scheduled for 13 May 2027; the DPDPA's separate general security-safeguards duty on a Data Fiduciary, section 8(5), is a controller security-of-processing article inside that comprehensive regime and stays there too, following the standing rule that such a provision is privacy even though it is triggered by a system holding personal data.