Knowledge base

Statutory Cybersecurity and Data Protection Obligations for Manufacturing Companies in India: A Reference Guide

What the DPDP Act, the CERT-In Directions and the IT Act require of Indian manufacturers, independent of any customer, and where the obligations overlap.

Neha Dvivedi · September 13, 2026

Manufacturers responding to a customer cybersecurity assessment often assume the requirement originates entirely with the customer. It does not. Indian manufacturing companies carry cybersecurity and data protection obligations under statute, independent of any contract. This guide sets out what those obligations are, who they apply to, and how they overlap with customer assessments and with ISO/IEC 27001. It is written as a reference on DPDP Act compliance for manufacturing companies and the related statutory duties that sit alongside it.

Contractual and statutory requirements are not the same thing

The distinction matters, because the two carry different consequences and different remedies.

  • Contractual. A customer cybersecurity assessment is issued under a commercial relationship. Failure produces a score, a corrective action requirement and, if unresolved, commercial consequences. It is not a legal breach.
  • Statutory. Obligations under the Digital Personal Data Protection Act, the Information Technology Act and the CERT-In Directions apply to the organisation directly, whether or not any customer ever asks. Failure carries regulatory consequences.

A useful check: an obligation that would still exist if every customer disappeared tomorrow is statutory. Most of what appears in a vendor assessment is contractual, but the data privacy and incident reporting sections substantially restate obligations the supplier already owes.

The Digital Personal Data Protection Act, 2023

The DPDP Act governs the processing of digital personal data in India. Manufacturing companies commonly assume it concerns consumer-facing businesses only. It does not. Employee data alone brings most manufacturers within scope.

  • Data Fiduciary. The entity determining the purpose and means of processing personal data. A manufacturer processing its own employee records is a Data Fiduciary in respect of that data.
  • Data Processor. An entity processing personal data on behalf of a Data Fiduciary. A supplier handling personal data supplied by a customer typically acts as a Processor for that data while remaining a Fiduciary for its own.
  • Typical holdings in a manufacturing company. Employee records, payroll data, biometric attendance data, CCTV footage, contractor and visitor records, customer contact data in CRM systems, and vendor contact data.
  • Core obligations. Lawful basis for processing, purpose limitation, reasonable security safeguards, breach notification, and honouring data principal rights.

This is also the area of a vendor assessment where ISO/IEC 27701 maps most directly, since that standard extends an ISO/IEC 27001 management system to privacy information management.

The CERT-In Directions, April 2022

Issued under Section 70B(6) of the Information Technology Act, 2000, these directions apply broadly to organisations operating IT infrastructure in India.

  • Incident reporting. Specified cyber incidents must be reported to CERT-In within six hours of being noticed. This is materially shorter than most organisations assume and generally requires a defined internal escalation route to be workable.
  • Log retention. Logs of ICT systems must be maintained for a rolling period, and retained within Indian jurisdiction.
  • Time synchronisation. System clocks are to be synchronised to designated network time protocol servers.
  • Point of contact. A named point of contact for interaction with CERT-In.

The log retention policy manufacturing companies need for a customer assessment and the one required by CERT-In are the same document. Suppliers frequently write one and overlook the other.

The Information Technology Act, 2000

  • Section 43A of the IT Act. Establishes liability where a body corporate handling sensitive personal data fails to maintain reasonable security practices and thereby causes wrongful loss or gain. The associated rules made in 2011, commonly called the SPDI Rules, expressly recognise ISO/IEC 27001 as a standard meeting the reasonable security practices requirement.
  • Section 72A. Addresses disclosure of information in breach of a lawful contract.
  • Section 70B. The provision under which CERT-In operates and issues directions.

Section 43A is the bridge between statutory obligation and certification. It is the clearest basis in Indian law for treating ISO/IEC 27001 as evidence of a defensible security posture rather than as a purely commercial credential.

AIS-189 and AIS-190: statutory, but not on the supplier

AIS-189, the Cyber Security Management System standard, and AIS-190, covering software update management, are frequently described as supplier requirements. They are not, strictly. They bind the vehicle manufacturer as a condition of type approval, and apply to new vehicle types from October 2027, extending to all vehicle types from October 2028. The rules giving them force are still in draft, and the dates should be checked against the current position on the MoRTH site. The Ministry of Road Transport and Highways has moved to give them force through proposed Rules 125-T and 125-U.

The supplier connection runs through AIS-189’s requirement that the manufacturer manage cybersecurity dependencies across suppliers, service providers and sub-organisations, supported by bilateral cybersecurity interface agreements. The obligation reaching the supplier is therefore contractual in form, but its origin is statutory, and it cannot be negotiated away because the manufacturer cannot obtain approval without it.

Where the obligations overlap

The same controls satisfy multiple requirements, which is the practical argument for a single programme rather than several.

  • An information security policy satisfies the governance checkpoints of a customer assessment, supports the reasonable security practices requirement under Section 43A, and is a Clause 5 requirement of ISO/IEC 27001.
  • A log retention definition satisfies the audit and accountability checkpoints of an assessment and the CERT-In retention obligation.
  • An incident response procedure satisfies assessment checkpoints, the CERT-In six-hour reporting obligation, and the DPDP breach notification requirement.
  • A personal data inventory and classification satisfies the data privacy checkpoints of an assessment and the foundation of DPDP compliance.
  • An ISO/IEC 27001 management system provides the framework for all of the above and is the standard named in the rules under Section 43A.

Frequently asked questions

Is cybersecurity mandatory for auto component manufacturers in India?

Cybersecurity certification is not mandatory. Certain cybersecurity obligations are. The DPDP Act, the CERT-In Directions and Section 43A of the Information Technology Act apply to manufacturing companies directly. Separately, customer assessments impose contractual requirements. Neither route makes ISO/IEC 27001 certification compulsory, though Section 43A expressly recognises it.

Does the DPDP Act apply to a company with no consumer business?

Yes, in most cases. Employee personal data, contractor records, biometric attendance data and CCTV footage are all within scope. A manufacturer with no consumer-facing activity at all will still be processing personal data about its own workforce.

What is the CERT-In six hour incident reporting requirement?

The April 2022 directions require specified cyber incidents to be reported to CERT-In within six hours of being noticed. Meeting that timeline in practice requires a defined internal escalation route and a named point of contact established in advance.

Does ISO/IEC 27001 certification satisfy these statutory obligations?

It does not automatically discharge them, but it is directly relevant. The rules made under Section 43A recognise ISO/IEC 27001 as a standard meeting the reasonable security practices requirement, and a certified management system provides the documentation, incident procedures and records that demonstrate compliance with the others. Privacy-specific obligations under the DPDP Act are better addressed by extending the system with ISO/IEC 27701.

The control families reference covers what a customer assessment asks for, as distinct from what statute requires. ISO/IEC 27001 is the framework named in the rules under Section 43A, and ISO/IEC 27701 extends it to privacy. MSCi works with manufacturers on both. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist gives a starting position.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles