Knowledge base

Cybersecurity and Data Protection Requirements for Manufacturing Companies in India

A Simple Guide to the DPDP Act, CERT-In Directions, IT Act and Customer Cybersecurity Assessments

Neha Dvivedi · September 13, 2026

Many manufacturing companies believe that cybersecurity assessments are required only because their customers ask for them. That is not entirely correct.

Indian manufacturers may have legal and regulatory responsibilities for cybersecurity and data protection even when no customer has asked for an assessment.

Customer assessments, the Digital Personal Data Protection Act (DPDP Act), the Information Technology Act and CERT-In Directions may overlap in several areas. ISO/IEC 27001 can provide a structured framework to manage many of these requirements.

This guide explains the difference between these requirements, who they apply to, and how they can work together.

________________________________________

1. Contractual vs. Statutory Requirements

The first step is to understand the difference between contractual requirements and statutory requirements.

Contractual Requirements

A customer may ask a supplier to complete a cybersecurity assessment before awarding or continuing a contract.

For example, a customer may ask about:

• Information security policies

• Access controls

• Incident management

• Data protection

• Business continuity

• Employee security

• Cybersecurity certifications

If the supplier does not meet the required score, the customer may ask for corrective action. If the issues remain unresolved, there may be commercial consequences, such as delayed onboarding, additional reviews or loss of business.

These requirements are generally contractual because they arise from the business relationship with the customer.

Statutory Requirements

Statutory requirements are different.

Requirements under laws and regulatory directions such as the DPDP Act, Information Technology Act and CERT-In Directions apply to organisations based on the scope of those laws and directions, regardless of whether a customer asks about them.

Non-compliance can result in regulatory or legal consequences.

A Simple Way to Understand the Difference

Ask yourself:

“If all our customers disappeared tomorrow, would this obligation still apply to us?”

If the answer is yes, it is likely to be a statutory or regulatory obligation.

Many questions in customer cybersecurity assessments are contractual. However, sections relating to personal data protection, cybersecurity safeguards and incident reporting often overlap with obligations that the organisation already has under applicable law.

________________________________________

2. Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) deals with the processing of digital personal data.

Manufacturing companies sometimes assume that the DPDP Act applies mainly to online businesses, e-commerce companies or consumer-facing organisations.

That is not necessarily the case.

A manufacturing company can process significant amounts of personal data through its employees, contractors, visitors, customers and suppliers.

Data Fiduciary

A Data Fiduciary is an organisation that decides why and how personal data is processed.

For example, when a manufacturer collects and uses employee information for employment, payroll or HR purposes, the manufacturer may act as a Data Fiduciary for that information.

Data Processor

A Data Processor processes personal data on behalf of a Data Fiduciary.

For example, a third-party payroll provider may process employee information on behalf of a manufacturing company.

A company can also have both roles depending on the data and processing activity.

Examples of Personal Data in a Manufacturing Company

A manufacturing organisation may hold:

• Employee records

• Payroll information

• Biometric attendance data

• CCTV recordings

• Contractor information

• Visitor records

• Customer contact information

• CRM data

• Vendor contact information

Key Areas of DPDP Compliance

Organisations need to consider areas such as:

• Lawful processing of personal data

• Purpose of collecting and using data

• Appropriate security safeguards

• Data breach management and notification

• Rights of individuals relating to their personal data

• Data retention and related controls

This is also where ISO/IEC 27701 becomes particularly relevant because it provides a privacy information management framework that can work alongside ISO/IEC 27001.

________________________________________

3. CERT-In Directions – April 2022

The CERT-In Directions were issued under the Information Technology Act, 2000 and contain cybersecurity-related requirements for organisations covered by the Directions.

Some important areas include:

Cyber Incident Reporting

Specified cyber incidents must be reported to CERT-In within six hours of noticing the incident.

This means organisations need a clear internal process for identifying, escalating and reporting relevant incidents.

Log Retention

Organisations covered by the Directions are required to maintain relevant ICT logs for the prescribed period and comply with the applicable requirements regarding storage within India.

Time Synchronisation

ICT systems are required to maintain time synchronisation with designated time sources as specified by the Directions.

CERT-In Point of Contact

Organisations are required to designate a point of contact for communication with CERT-In.

Why This Matters to Manufacturers

A customer may ask a manufacturer about:

• Log management

• Incident reporting

• Monitoring

• Incident response

• Cybersecurity contacts

At the same time, some of these areas may already be covered by regulatory requirements.

Therefore, organisations should avoid creating separate processes for every customer questionnaire. A properly designed cybersecurity programme can address several requirements together.

________________________________________

4. Information Technology Act, 2000

The Information Technology Act, 2000 continues to be relevant to cybersecurity and data protection.

Section 43A

Section 43A deals with liability relating to the protection of sensitive personal data or information where applicable.

The associated rules, commonly referred to as the SPDI Rules, recognise reasonable security practices and specifically refer to ISO/IEC 27001.

This makes ISO/IEC 27001 relevant not only from a commercial or customer-assessment perspective but also when an organisation is demonstrating its approach to reasonable security practices.

Section 72A

Section 72A deals with disclosure of information in breach of a lawful contract.

Section 70B

Section 70B provides the legal basis for CERT-In and its functions, including issuing directions relating to cybersecurity.

________________________________________

5. AIS-189 and AIS-190 – Automotive Cybersecurity

Automotive manufacturers should also be aware of AIS-189 and AIS-190, particularly where cybersecurity requirements flow through the vehicle manufacturing and supply chain.

AIS-189 deals with Cyber Security Management Systems, while AIS-190 addresses software update management.

These requirements are particularly relevant to vehicle manufacturers and can affect suppliers because vehicle manufacturers need to manage cybersecurity risks across their supply chain.

Therefore, an automotive supplier may receive cybersecurity requirements from its OEM customer even though the underlying cybersecurity expectations originate from the broader regulatory framework applicable to vehicle manufacturers.

The exact applicability and effective dates should always be checked against the latest notifications and requirements issued by the Ministry of Road Transport and Highways (MoRTH SITE).

________________________________________

6. Where Do These Requirements Overlap?

This is one of the most important points for manufacturing companies.

A company does not necessarily need a completely separate system for:

• Customer cybersecurity assessments

• DPDP compliance

• CERT-In requirements

• IT Act requirements

• ISO/IEC 27001

Many controls can support multiple requirements at the same time.

Example 1: Information Security Policy

An information security policy can:

• Support a customer cybersecurity assessment

• Form part of an ISO/IEC 27001 management system

• Support the organisation's approach to reasonable security practices

Example 2: Log Management

A documented log-retention process can:

• Address customer assessment requirements

• Support monitoring and audit activities

• Help meet applicable CERT-In requirements

Example 3: Incident Response

A well-defined incident response process can:

• Address customer cybersecurity assessment questions

• Support ISO/IEC 27001 requirements

• Help the organisation respond within applicable CERT-In timelines

• Support the organisation's data breach management process under the DPDP framework

Example 4: Personal Data Inventory

A personal data inventory can help an organisation:

• Identify what personal data it holds

• Understand where the data is stored

• Identify who has access to it

• Support DPDP compliance

• Respond to customer privacy assessments

Example 5: ISO/IEC 27001 Management System

An ISO/IEC 27001-based information security management system can provide a structured framework for managing many of these controls.

Where privacy requirements are significant, ISO/IEC 27701 can be used to extend the information security framework into privacy information management.

________________________________________

7. Frequently Asked Questions

Is cybersecurity certification mandatory for auto component manufacturers in India?

Cybersecurity certification such as ISO/IEC 27001 is not automatically mandatory simply because a company is an auto component manufacturer.

However, organisations may have cybersecurity and data protection obligations under applicable laws and regulations. In addition, customers may impose cybersecurity requirements as part of their contractual or supplier-management processes.

Therefore, it is important to distinguish between mandatory legal requirements and customer-specific certification or assessment requirements.

________________________________________

Does the DPDP Act apply to a manufacturing company that has no consumer business?

Potentially, yes.

A manufacturing company may process personal data relating to employees, contractors, visitors, customers and vendors even if it does not sell products directly to consumers.

The organisation should therefore assess its personal-data processing activities and determine which requirements of the DPDP framework apply to it.

________________________________________

What is the CERT-In six-hour reporting requirement?

The April 2022 CERT-In Directions require specified cyber incidents to be reported to CERT-In within six hours of noticing the incident.

Organisations should therefore establish an internal escalation process, identify responsible personnel and maintain the necessary communication channels in advance.

________________________________________

Does ISO/IEC 27001 certification automatically mean that an organisation is legally compliant?

No.

ISO/IEC 27001 certification does not automatically discharge every statutory obligation.

However, it can provide a structured management system for implementing and demonstrating information-security controls. ISO/IEC 27001 is also specifically recognised in the framework associated with Section 43A's reasonable security practices.

Privacy-related requirements may require additional controls and processes, for which ISO/IEC 27701 can be relevant.

The control families reference covers what a customer assessment asks for, as distinct from what statute requires. ISO/IEC 27001 is the framework named in the rules under Section 43A, and ISO/IEC 27701 extends it to privacy. MSCi works with manufacturers on both. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist gives a starting position.

________________________________________

8. The Practical Approach for Manufacturers

Manufacturers should avoid treating every customer cybersecurity questionnaire as a completely separate exercise.

A better approach is to build a single, structured cybersecurity and data protection programme that addresses:

Legal & Regulatory Requirements

↓

Customer / Contractual Requirements

↓

Information Security – ISO/IEC 27001

↓

Privacy Management – ISO/IEC 27701

↓

Policies, Processes, Controls & Evidence

↓

Customer Assessments & Certification Readiness

This approach can help an organisation use the same policies, procedures, controls and evidence to respond to multiple requirements.

________________________________________

Conclusion

Cybersecurity for a manufacturing company is no longer only a customer requirement.

A manufacturer may have responsibilities arising from applicable data protection laws, cybersecurity regulations and contractual obligations.

The DPDP Act, Information Technology Act, CERT-In Directions, customer cybersecurity assessments and ISO/IEC 27001 address different aspects of the overall cybersecurity and data protection environment.

The objective should therefore not be to create a separate system for every requirement.

Instead, manufacturers can develop an integrated framework that brings together information security, privacy, incident management, data protection, regulatory requirements and customer expectations.

ISO/IEC 27001 can provide the information-security management framework, while ISO/IEC 27701 can help address privacy information management.

For organisations preparing for customer cybersecurity assessments, regulatory compliance or ISO certification, the first step should be to understand which requirements are statutory, which are contractual, and where the same controls can satisfy multiple requirements.

About MSCI

MSCI is a consulting organisation that supports manufacturers and other organisations with cybersecurity, information security and management-system readiness.

MSCI helps organisations prepare for assessments and certification by supporting areas such as gap assessment, documentation, implementation support and audit readiness.

MSCI does not issue certificates and is not an approved or empanelled certification assessor for manufacturers.

Organizations can also use a readiness checklist as a starting point to understand their current position and identify areas requiring attention.


See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles