India’s new CCTV rules mark a decisive shift from cheap, large-scale deployments to security-first surveillance. As STQC certification kicked in from April 1, 2026, non-compliant systems are now on a path of salvation, and the industry is rethinking the ‘seeing’ ability.
Upar wala sab dekh raha hai! For years, this line was popularised in CP Plus TV advertisements. It was widely regarded as an ironic reminder of surveillance in everyday life, but now it raises a more uncomfortable question: Who exactly is doing the watching?
CCTV cameras that connect to the internet are now everywhere; they are part of our homes, offices, shops, and public infrastructure. As a result, concerns about data access, remote control, and overseas dependencies have grown.
Global cybersecurity incidents have shown that poorly secured IoT devices, including IP cameras, can become entry points for unauthorised access and network breaches. Recorded footage is now connected, networked, and, in many cases, remotely accessible.
The policy reset
EFY raised the alarm about this issue in December 2023 and discussed how open CCTV ports can harm the country’s security, an assessment that proved to be an eye-opener. Against this backdrop, the government has now tightened the rules.
From April 1, 2026, the government has effectively barred any CCTV or surveillance system that does not meet the notified essential requirements from being manufactured, imported, or sold.
Certification is now mandatory through the Standardisation Testing and Quality Certification (STQC) Directorate, and the process extends far beyond basic performance checks.
Devices are evaluated for their ability to resist tampering, secure communications through encryption, maintain firmware integrity, and avoid exposing vulnerable interfaces. In several cases, testing includes simulated cyberattacks and attempts to access hardware ports, replicating real-world threat scenarios. If a device fails these tests, it cannot enter the market.
In Delhi, Public Works Department (PWD) Minister Parvesh Verma said on April 1 that CCTV cameras sourced from Chinese firm Hikvision would be gradually replaced across the city.
The enforcement is already visible in the national capital, as authorities have begun phasing out nearly 140,000 cameras linked to Hikvision, with approximately 50,000 units cleared for replacement in the first phase.
A computer with a lens
The concern begins with a simple but often overlooked reality: a modern CCTV camera functions much like a computing system. It runs firmware, communicates over networks, processes data through onboard chipsets, and often connects to cloud platforms for storage and remote access. That layered architecture introduces risk at every level.
Co-founder and Managing Director of product engineering company Silicon Signals, Rutvij Trivedi, explains why this matters in practical terms.
“There have been several times when CCTV has been used to break into places. This is serious; weak surveillance systems can put important areas like finance and even defence at risk,” he says. Rutvij is clear that this is not about ticking compliance boxes.
“This is not a checklist. This is real engineering, secure boot, firmware integrity, encrypted communication, blocking hardware access. It will not pass if it is not made right from the start,” he adds, underlining the shift from surface-level compliance to deep system design.
Rebuilding from the silicon up
Shashwath T.R., Co-founder and Chief Executive Officer of Mindgrove Technologies, a Chennai-based fabless semiconductor startup, notes that the shift was anticipated well in advance.
“We knew this was coming for two years. It gained a lot more prominence last year—it was openly signalled,” he says.
Rather than focusing solely on assembling end products, companies are beginning to address deeper layers of the system. “We are a chip company, we are addressing it at that level. The chip handles everything,” Shashwath explains.
His point highlights where real control resides. In a surveillance system, the processor governs how data is captured, processed, compressed, and transmitted. It also determines how securely the system operates and responds to potential threats. However, building this capability domestically is complex.
India’s semiconductor ecosystem is still evolving, particularly in specialised areas such as surveillance-grade chips and optoelectronics. “Eventually, if you are making cameras here, it makes sense to build the full stack here,” he says, adding, “we are moving in that direction, but we are not fully there yet.”
The cost of doing it right
Certification under the STQC framework is applied to individual product models rather than entire brands, meaning companies with extensive product portfolios must undergo repeated testing cycles.
This increases costs, extends development timelines, and may render some existing products non-compliant.
Rutvij acknowledges this reality. “There will be a short-term supply adjustment because the market is moving towards compliant products,” he says, noting that the transition will take time to stabilise.
However, he frames this disruption as a necessary correction rather than a setback. “This change takes the industry from ‘jugaad’ to genuine, secure engineering. That is a good thing,” he adds.
Larger players such as Sparsh CCTV, CP Plus, and Prama India are better positioned to adapt due to their scale, resources, and established processes. Smaller manufacturers, on the other hand, may find it more challenging to meet the new requirements.
Security: The new differentiator
For companies already aligned with the evolving framework, the policy shift represents both a challenge and an opportunity. Sparsh Sehgal, Chief Growth Officer at Sparsh CCTV, describes it as a necessary evolution in the industry’s priorities.
“Earlier, the conversation was largely about availability and price. Today, the focus is rightly shifting to cybersecurity, trusted supply chains, and long-term reliability,” she says.
The scope of certification reflects this broader shift. “Any camera that connects to a network, whether wired, wireless, 4G, or 5G, is being certified under the same security lens,” Sehgal explains, highlighting the comprehensive nature of the framework.
Sparsh has already begun adapting, with some products certified and others expected to launch in the near term. While acknowledging short-term market adjustments, she emphasises the long-term benefits. “The policy creates some near-term transition for the market, but over time it will strengthen compliant manufacturers, protect end users, and build a more secure domestic ecosystem,” she says.
She also points to the next phase of evolution, noting that stronger audits and more stringent supply-chain validation will further reinforce the framework.
Scale came easy; control did not
India’s surveillance expansion over the past decade was driven by scale and accessibility. Global manufacturers such as Hikvision and Dahua supplied affordable, feature-rich systems that made large-scale deployments viable.
Cities rapidly expanded camera networks, housing societies standardised installations, and businesses integrated surveillance into everyday operations.
The model worked efficiently from a cost and availability perspective, but it also created layered dependency. Hardware, firmware, and chipsets were often sourced from interconnected global supply chains, making it difficult to separate the product from its ecosystem.
Even Indian brands such as CP Plus scaled within this structure, building strong distribution networks and brand recognition while relying on external sourcing to meet demand. It was not a flaw in execution; it was simply how the market evolved.
However, as concerns about data control, cybersecurity, and supply-chain trust intensified, that model began to appear increasingly fragile.
Beyond the device
The next phase of regulatory and industry focus is likely to extend into lifecycle security, continuous validation, and deeper supply-chain transparency.
India’s CCTV reset represents a deeper shift in how surveillance is understood and managed in a connected world. What was once a matter of visibility is now a matter of control, trust, and accountability.
The future of surveillance lies not in watching more, but in understanding faster and responding smarter—a reality captured in Little Brother, where Cory Doctorow writes, “You can’t defend. You can only detect and respond.”
Pratyush Kumar has a background in TV reporting and a keen interest in electronics, technology, emerging gadgets, and market trends.




