India has moved to tighten regulations on internet-connected CCTV cameras and related equipment, especially those linked to Chinese companies like Hikvision and Dahua, along with some TP-Link products.
From April 1, all CCTV devices must meet stricter certification requirements under the government’s Standardisation Testing and Quality Certification (STQC) framework. Devices without this approval will not be allowed for sale in India.
According to government rules, security testing for CCTV and Video Surveillance Systems must be carried out by the STQC Directorate or agencies authorised by the Ministry of Electronics and IT. The certification will remain valid for three years.
The move is part of a broader push to strengthen cybersecurity, as connected surveillance devices are seen as potential targets for hacking or unauthorised access.
Reports suggest that some products, especially those using Chinese-origin components, may not receive certification, effectively restricting their entry into the Indian market.Under the new norms, CCTV systems must follow strict security standards, including removal of default passwords, no hidden backdoors, secure software updates, encrypted data transfer, and protection against tampering.
The government has earlier raised concerns about security risks, noting that many cameras used in public institutions were sourced from Chinese firms, with fears of data being sent to servers outside India.
These new rules aim to reduce cyber threats and ensure safer surveillance systems across the country.

