India Releases National Cybersecurity Policy 2026 with Zero-Trust Mandate
All critical infrastructure operators — power, telecom, banking, defence — must implement zero-trust architecture within 24 months under the new framework.
The Ministry of Electronics and Information Technology has released the National Cybersecurity Policy 2026, mandating zero-trust security architecture adoption for all critical infrastructure operators and government systems within 24 months — a significant tightening from the previous framework's advisory posture.
Zero-trust architecture requires continuous verification of every user, device, and network connection rather than assuming safety once inside a perimeter. The approach addresses the principal vulnerability exposed in India's most significant recent cyber incidents: the AIIMS Delhi ransomware attack and the UIDAI data breach, both of which exploited trusted internal network access.
The policy classifies 57 categories of critical information infrastructure — from power generation control systems and banking transaction platforms to the Aadhaar verification infrastructure and national election management systems — and assigns each a compliance timeline and minimum security standard.
A new National Cyber Security Coordinator's office will oversee implementation, with authority to conduct mandatory audits, issue compliance certificates, and impose operational restrictions on non-compliant operators. The government has allocated ₹3,200 crore for a subsidy and capacity-building programme to support smaller critical infrastructure operators who lack the technical resources to implement the required changes independently.
Reader Responses
Leave a Response
Your comment will appear after editorial review.
