Knowledge base
Cybersecurity and Data Protection Requirements for Manufacturing Companies in India
A Simple Guide to the DPDP Act, CERT-In Directions, IT Act and Customer Cybersecurity Assessments
Neha Dvivedi · September 13, 2026
Many manufacturing companies believe that cybersecurity assessments are required only because their customers ask for them. That is not entirely correct.
Indian manufacturers may have legal and regulatory responsibilities for cybersecurity and data protection even when no customer has asked for an assessment.
Customer assessments, the Digital Personal Data Protection Act (DPDP Act), the Information Technology Act and CERT-In Directions may overlap in several areas. ISO/IEC 27001 can provide a structured framework to manage many of these requirements.
This guide explains the difference between these requirements, who they apply to, and how they can work together.
________________________________________
1. Contractual vs. Statutory Requirements
The first step is to understand the difference between contractual requirements and statutory requirements.
Contractual Requirements
A customer may ask a supplier to complete a cybersecurity assessment before awarding or continuing a contract.
For example, a customer may ask about:
• Information security policies
• Access controls
• Incident management
• Data protection
• Business continuity
• Employee security
• Cybersecurity certifications
If the supplier does not meet the required score, the customer may ask for corrective action. If the issues remain unresolved, there may be commercial consequences, such as delayed onboarding, additional reviews or loss of business.
These requirements are generally contractual because they arise from the business relationship with the customer.
Statutory Requirements
Statutory requirements are different.
Requirements under laws and regulatory directions such as the DPDP Act, Information Technology Act and CERT-In Directions apply to organisations based on the scope of those laws and directions, regardless of whether a customer asks about them.
Non-compliance can result in regulatory or legal consequences.
A Simple Way to Understand the Difference
Ask yourself:
“If all our customers disappeared tomorrow, would this obligation still apply to us?”
If the answer is yes, it is likely to be a statutory or regulatory obligation.
Many questions in customer cybersecurity assessments are contractual. However, sections relating to personal data protection, cybersecurity safeguards and incident reporting often overlap with obligations that the organisation already has under applicable law.
________________________________________
2. Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 (DPDP Act) deals with the processing of digital personal data.
Manufacturing companies sometimes assume that the DPDP Act applies mainly to online businesses, e-commerce companies or consumer-facing organisations.
That is not necessarily the case.
A manufacturing company can process significant amounts of personal data through its employees, contractors, visitors, customers and suppliers.
Data Fiduciary
A Data Fiduciary is an organisation that decides why and how personal data is processed.
For example, when a manufacturer collects and uses employee information for employment, payroll or HR purposes, the manufacturer may act as a Data Fiduciary for that information.
Data Processor
A Data Processor processes personal data on behalf of a Data Fiduciary.
For example, a third-party payroll provider may process employee information on behalf of a manufacturing company.
A company can also have both roles depending on the data and processing activity.
Examples of Personal Data in a Manufacturing Company
A manufacturing organisation may hold:
• Employee records
• Payroll information
• Biometric attendance data
• CCTV recordings
• Contractor information
• Visitor records
• Customer contact information
• CRM data
• Vendor contact information
Key Areas of DPDP Compliance
Organisations need to consider areas such as:
• Lawful processing of personal data
• Purpose of collecting and using data
• Appropriate security safeguards
• Data breach management and notification
• Rights of individuals relating to their personal data
• Data retention and related controls
This is also where ISO/IEC 27701 becomes particularly relevant because it provides a privacy information management framework that can work alongside ISO/IEC 27001.
________________________________________
3. CERT-In Directions – April 2022
The CERT-In Directions were issued under the Information Technology Act, 2000 and contain cybersecurity-related requirements for organisations covered by the Directions.
Some important areas include:
Cyber Incident Reporting
Specified cyber incidents must be reported to CERT-In within six hours of noticing the incident.
This means organisations need a clear internal process for identifying, escalating and reporting relevant incidents.
Log Retention
Organisations covered by the Directions are required to maintain relevant ICT logs for the prescribed period and comply with the applicable requirements regarding storage within India.
Time Synchronisation
ICT systems are required to maintain time synchronisation with designated time sources as specified by the Directions.
CERT-In Point of Contact
Organisations are required to designate a point of contact for communication with CERT-In.
Why This Matters to Manufacturers
A customer may ask a manufacturer about:
• Log management
• Incident reporting
• Monitoring
• Incident response
• Cybersecurity contacts
At the same time, some of these areas may already be covered by regulatory requirements.
Therefore, organisations should avoid creating separate processes for every customer questionnaire. A properly designed cybersecurity programme can address several requirements together.
________________________________________
4. Information Technology Act, 2000
The Information Technology Act, 2000 continues to be relevant to cybersecurity and data protection.
Section 43A
Section 43A deals with liability relating to the protection of sensitive personal data or information where applicable.
The associated rules, commonly referred to as the SPDI Rules, recognise reasonable security practices and specifically refer to ISO/IEC 27001.
This makes ISO/IEC 27001 relevant not only from a commercial or customer-assessment perspective but also when an organisation is demonstrating its approach to reasonable security practices.
Section 72A
Section 72A deals with disclosure of information in breach of a lawful contract.
Section 70B
Section 70B provides the legal basis for CERT-In and its functions, including issuing directions relating to cybersecurity.
________________________________________
5. AIS-189 and AIS-190 – Automotive Cybersecurity
Automotive manufacturers should also be aware of AIS-189 and AIS-190, particularly where cybersecurity requirements flow through the vehicle manufacturing and supply chain.
AIS-189 deals with Cyber Security Management Systems, while AIS-190 addresses software update management.
These requirements are particularly relevant to vehicle manufacturers and can affect suppliers because vehicle manufacturers need to manage cybersecurity risks across their supply chain.
Therefore, an automotive supplier may receive cybersecurity requirements from its OEM customer even though the underlying cybersecurity expectations originate from the broader regulatory framework applicable to vehicle manufacturers.
The exact applicability and effective dates should always be checked against the latest notifications and requirements issued by the Ministry of Road Transport and Highways (MoRTH SITE).
________________________________________
6. Where Do These Requirements Overlap?
This is one of the most important points for manufacturing companies.
A company does not necessarily need a completely separate system for:
• Customer cybersecurity assessments
• DPDP compliance
• CERT-In requirements
• IT Act requirements
• ISO/IEC 27001
Many controls can support multiple requirements at the same time.
Example 1: Information Security Policy
An information security policy can:
• Support a customer cybersecurity assessment
• Form part of an ISO/IEC 27001 management system
• Support the organisation's approach to reasonable security practices
Example 2: Log Management
A documented log-retention process can:
• Address customer assessment requirements
• Support monitoring and audit activities
• Help meet applicable CERT-In requirements
Example 3: Incident Response
A well-defined incident response process can:
• Address customer cybersecurity assessment questions
• Support ISO/IEC 27001 requirements
• Help the organisation respond within applicable CERT-In timelines
• Support the organisation's data breach management process under the DPDP framework
Example 4: Personal Data Inventory
A personal data inventory can help an organisation:
• Identify what personal data it holds
• Understand where the data is stored
• Identify who has access to it
• Support DPDP compliance
• Respond to customer privacy assessments
Example 5: ISO/IEC 27001 Management System
An ISO/IEC 27001-based information security management system can provide a structured framework for managing many of these controls.
Where privacy requirements are significant, ISO/IEC 27701 can be used to extend the information security framework into privacy information management.
________________________________________
7. Frequently Asked Questions
Is cybersecurity certification mandatory for auto component manufacturers in India?
Cybersecurity certification such as ISO/IEC 27001 is not automatically mandatory simply because a company is an auto component manufacturer.
However, organisations may have cybersecurity and data protection obligations under applicable laws and regulations. In addition, customers may impose cybersecurity requirements as part of their contractual or supplier-management processes.
Therefore, it is important to distinguish between mandatory legal requirements and customer-specific certification or assessment requirements.
________________________________________
Does the DPDP Act apply to a manufacturing company that has no consumer business?
Potentially, yes.
A manufacturing company may process personal data relating to employees, contractors, visitors, customers and vendors even if it does not sell products directly to consumers.
The organisation should therefore assess its personal-data processing activities and determine which requirements of the DPDP framework apply to it.
________________________________________
What is the CERT-In six-hour reporting requirement?
The April 2022 CERT-In Directions require specified cyber incidents to be reported to CERT-In within six hours of noticing the incident.
Organisations should therefore establish an internal escalation process, identify responsible personnel and maintain the necessary communication channels in advance.
________________________________________
Does ISO/IEC 27001 certification automatically mean that an organisation is legally compliant?
No.
ISO/IEC 27001 certification does not automatically discharge every statutory obligation.
However, it can provide a structured management system for implementing and demonstrating information-security controls. ISO/IEC 27001 is also specifically recognised in the framework associated with Section 43A's reasonable security practices.
Privacy-related requirements may require additional controls and processes, for which ISO/IEC 27701 can be relevant.
The control families reference covers what a customer assessment asks for, as distinct from what statute requires. ISO/IEC 27001 is the framework named in the rules under Section 43A, and ISO/IEC 27701 extends it to privacy. MSCi works with manufacturers on both. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist gives a starting position.
________________________________________
8. The Practical Approach for Manufacturers
Manufacturers should avoid treating every customer cybersecurity questionnaire as a completely separate exercise.
A better approach is to build a single, structured cybersecurity and data protection programme that addresses:
Legal & Regulatory Requirements
↓
Customer / Contractual Requirements
↓
Information Security – ISO/IEC 27001
↓
Privacy Management – ISO/IEC 27701
↓
Policies, Processes, Controls & Evidence
↓
Customer Assessments & Certification Readiness
This approach can help an organisation use the same policies, procedures, controls and evidence to respond to multiple requirements.
________________________________________
Conclusion
Cybersecurity for a manufacturing company is no longer only a customer requirement.
A manufacturer may have responsibilities arising from applicable data protection laws, cybersecurity regulations and contractual obligations.
The DPDP Act, Information Technology Act, CERT-In Directions, customer cybersecurity assessments and ISO/IEC 27001 address different aspects of the overall cybersecurity and data protection environment.
The objective should therefore not be to create a separate system for every requirement.
Instead, manufacturers can develop an integrated framework that brings together information security, privacy, incident management, data protection, regulatory requirements and customer expectations.
ISO/IEC 27001 can provide the information-security management framework, while ISO/IEC 27701 can help address privacy information management.
For organisations preparing for customer cybersecurity assessments, regulatory compliance or ISO certification, the first step should be to understand which requirements are statutory, which are contractual, and where the same controls can satisfy multiple requirements.
About MSCI
MSCI is a consulting organisation that supports manufacturers and other organisations with cybersecurity, information security and management-system readiness.
MSCI helps organisations prepare for assessments and certification by supporting areas such as gap assessment, documentation, implementation support and audit readiness.
MSCI does not issue certificates and is not an approved or empanelled certification assessor for manufacturers.
Organizations can also use a readiness checklist as a starting point to understand their current position and identify areas requiring attention.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
September 13, 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
September 13, 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
September 13, 2026
