CCTV STQC and BIS certification for government procurement in India

MeitY's security Essential Requirements for CCTV, STQC testing and BIS registration: what each rule requires, when it took effect, and what buyers now ask for.

Ahuva Electronic Technologies · Published

Key points

  • Since 9 April 2025, a CCTV (closed-circuit television) camera other than an analogue camera can hold a Bureau of Indian Standards (BIS) registration only if it has been tested against the Essential Requirements (ERs) for security set by MeitY, the Ministry of Electronics and Information Technology, as well as the safety standard IS 13252 (Part 1):2010.
  • Two separate MeitY instruments apply: a Make in India public procurement notification of 6 March 2024, in effect from 7 June 2024, and an amendment of 9 April 2024 to the Compulsory Registration Order, in effect from 9 April 2025 after one extension.
  • Security test reports for CCTV are issued by the Standardisation Testing and Quality Certification (STQC) Directorate or another agency MeitY notifies, and an STQC test report is valid for three years from its date of issue.
  • MeitY clarified on 12 March 2025 that the security Essential Requirements do not apply to analogue CCTV cameras.
  • Under a MeitY circular of 4 February 2026, one STQC security test report under the Compulsory Registration Order also satisfies the procurement order.
  • The safety standard is changing: IS/IEC 62368-1:2023 supersedes IS 13252 (Part 1):2010, and both run side by side until 1 November 2028.

What do the STQC and BIS requirements for CCTV cameras require?

They require an IP (Internet Protocol) CCTV camera to pass a security test against Essential Requirements set by MeitY (the Ministry of Electronics and Information Technology), on top of the electrical safety test it already needed for registration with the Bureau of Indian Standards (BIS). The security test is done by STQC, a directorate of MeitY, or by another agency MeitY notifies.

Two rules carry the requirement, and they work differently. The first is a notification under the Public Procurement (Preference to Make in India) Order 2017, often shortened to PPP-MII or PPO. It governs what government buyers may procure. The second is an amendment to the Electronics and Information Technology Goods (Requirements for Compulsory Registration) Order, 2021, the CRO, under which BIS runs its Compulsory Registration Scheme (CRS). It governs which products can be registered at all.

Before 2024, a CCTV camera or recorder needed BIS registration against IS 13252 (Part 1):2010, a safety standard for information technology equipment. The 2024 changes added cybersecurity to that product safety route.

When did each rule take effect, and which dates moved?

The procurement rule took effect on 7 June 2024, and the registration rule took effect on 9 April 2025 after MeitY extended it once by six months. MeitY's circular of 4 February 2026 confirms both effective dates.

The registration rule, S.O. 1652(E) of 9 April 2024, applied on the expiry of six months from publication, which was 9 October 2024. On that date MeitY issued S.O. 4378(E), extending the implementation date to 9 April 2025 because industry had asked for more time. BIS then told existing licensees that models not complying after 9 April 2025 would be deleted from the scope of their licence.

CCTV security and registration rules in India, verified dates
DateInstrumentWhat it did
6 Mar 2024MeitY PPP-MII notification, S.O. 1119(E)Local content rules and security ERs for procured CCTV
11 Mar 2024MeitY advisory office memorandumSecurity guidance to all ministries and departments
9 Apr 2024CRO amendment, S.O. 1652(E)Added security ERs for CCTV cameras
7 Jun 2024PPP-MII notification in effectSecurity ERs apply to government procurement
9 Oct 2024S.O. 4378(E)CRO date extended to 9 April 2025
12 Mar 2025MeitY clarificationSecurity ERs do not apply to analogue cameras
9 Apr 2025CRO amendment in effectNo new licence for non-analogue cameras without ERs
29 Oct 2025S.O. 4997(E)IS/IEC 62368-1:2023 supersedes IS 13252 (Part 1)
4 Feb 2026MeitY circular W-18/26/2025-IPHWOne STQC ER report serves both CRO and PPP-MII

What do MeitY's Essential Requirements test?

The Essential Requirements test whether a camera can be tampered with, accessed or altered by someone who should not have access. MeitY's notification sets out five broad requirements: physical security through tamper-resistant enclosures, access control through authentication and role-based access, network security through encrypted transmission, software security through regular updates, disabled unused features and strong passwords, and penetration testing.

The key test areas named by MeitY are exposed network services, device communication protocols, physical access to hardware debug ports such as UART, JTAG and SWD, whether memory and firmware can be extracted, the security of the firmware update process, and how data is stored and encrypted. The detailed schedule also asks the maker for documents, such as the datasheet of the system-on-chip (SoC) used in the camera.

Testing is done per product series. MeitY's series guidelines, published by BIS on 22 October 2024, require every model in a series to share the same SoC and identical firmware with matching hash values. If a maker uses several firmware versions, each is tested as a separate series. For a buyer, the practical point is that the firmware version on the certificate matters.

Do the rules cover analogue cameras, NVRs and DVRs?

Analogue cameras are exempt from the security Essential Requirements, but still need BIS registration for safety. BIS's circular of 1 April 2025 records MeitY's clarification of 12 March 2025, and says that from 9 April 2025 analogue cameras are registered against IS 13252 (Part 1) alone, while all other CCTV cameras need IS 13252 (Part 1) plus the security Essential Requirements.

For recorders the position is narrower. The CRO amendment of 9 April 2024 added the security requirement to the entry for CCTV camera. The procurement notification of 6 March 2024 covers network video recorders (NVRs) and digital video recorders (DVRs) for local content, but said that security norms for DVRs and NVRs would be notified later. This article does not state whether those norms have since been notified; a buyer who needs recorders covered should check the current MeitY and BIS position and write the requirement into the tender directly.

What does the Make in India procurement order add for CCTV?

The procurement order requires government buyers to give purchase preference to locally manufactured video surveillance systems, and sets out how local content in cameras, NVRs and DVRs is calculated. The Class-I and Class-II local supplier definitions come from the Department for Promotion of Industry and Internal Trade (DPIIT) order of 16 September 2020.

MeitY's notification also says it applies to procurement by States and local bodies under Central Schemes and Centrally Sponsored Schemes where the project is fully or partly funded by the Government of India. That brings many municipal and city projects within scope.

  • At bid stage, the local supplier self-certifies that the item meets the minimum local content, and states where the value is added
  • For procurement above Rs 10 crore, the supplier provides a certificate of local content from its statutory or cost auditor, or from a practising cost or chartered accountant
  • Complaints about a local content claim are referred to STQC, which is to dispose of them within four weeks
  • The complaint fee is Rs 2 lakh or 1% of the value of the products being procured, whichever is higher, up to Rs 5 lakh
  • A false declaration is a breach of the Code of Integrity under the General Financial Rules and can lead to debarment

What do government buyers now ask for in a CCTV tender?

Government buyers now ask for proof of BIS registration with the security Essential Requirements, a current STQC security test report, and local content evidence under the procurement order. MeitY's advisory of 11 March 2024 adds a set of security and design expectations that many tenders now copy in.

  • BIS registration number for each camera model, with the security Essential Requirements included in the scope of the licence
  • An STQC security test report or certificate that is less than three years old and names the offered model and firmware
  • Safety compliance to IS 13252 (Part 1):2010, or to IS/IEC 62368-1:2023 as makers migrate
  • Local content self-certificate, and an auditor's certificate above Rs 10 crore
  • Performance parameters set using the BIS Blank Detail Specification for IS 16910, which MeitY's advisory names for CCTV performance
  • Storage of video from government establishments and public places within India, including on cloud platforms, as MeitY's advisory asks
  • Avoidance of brands with a history of security breaches and data leaks, which MeitY's advisory also asks for
  • Network isolation, changed default passwords, firmware updates and restricted remote access through the maintenance period

How can a buyer check a camera's compliance?

A buyer can check the registration on the BIS Compulsory Registration Scheme portal, which lets anyone search a registration by its R-number, and should match the model and firmware against the security test report. BIS has also published a list of registrations and models of CCTV cameras complying with the security Essential Requirements.

STQC's own list of network cameras certified for the procurement order is no longer updated and is kept for historical reference, because MeitY's circular of 4 February 2026 made the single STQC report under the CRO serve both purposes. BIS's guidelines of 22 October 2024 also allow compliant models to carry the line 'This CCTV camera complies with Essential Requirement(s) for Security' on the packaging.

The safety standard is also moving. MeitY's notification S.O. 4997(E) of 29 October 2025 made IS/IEC 62368-1:2023 supersede IS 13252 (Part 1):2010 under the CRO. BIS's guidelines of 9 March 2026 allow both to run until 1 November 2028, after which IS 13252 (Part 1) stands withdrawn for these products. Where moving a registered camera to the new safety standard affects its security compliance, the maker must submit fresh security test reports as well. A tender running past 2028 should accept both standards now and require IS/IEC 62368-1:2023 after that date.

Frequently asked questions

Is STQC certification mandatory for CCTV cameras in India?
For IP CCTV cameras, yes in effect. Since 9 April 2025, BIS registration under the Compulsory Registration Order requires a security test against MeitY's Essential Requirements, and security test reports come from STQC or another agency MeitY notifies.
How long is an STQC test report for CCTV valid?
MeitY's procurement notification of 6 March 2024 sets the validity of an STQC test report at three years from its date of issue.
Do analogue CCTV cameras need the security test?
No. MeitY clarified on 12 March 2025 that the security Essential Requirements do not apply to analogue CCTV cameras, which still need BIS registration against IS 13252 (Part 1).
Does a camera need separate STQC reports for BIS and for government procurement?
Not any more. MeitY's circular of 4 February 2026 says STQC will issue one security test report under the Compulsory Registration Order that also applies for the procurement order.
Which safety standard applies to CCTV cameras after 2028?
IS/IEC 62368-1:2023. BIS allows IS 13252 (Part 1):2010 to run alongside it only until 1 November 2028.

Sources

  1. Forwarding of MeitY's communications regarding CCTVs: PPP-MII notification of 6 March 2024, CRO amendment S.O. 1652(E) of 9 April 2024, and advisory of 11 March 2024 · Ministry of Home Affairs, Government of India
  2. S.O. 4378(E): Extension of implementation timelines of Essential Requirements of CCTV in CRO 2021 · Gazette of India, via Bureau of Indian Standards
  3. Guidelines for implementation of Essential Requirement(s) for Security of CCTV · Bureau of Indian Standards
  4. Non-applicability of Security ER to Analog CCTV Cameras · Bureau of Indian Standards
  5. Clarification on testing requirements under PPP-MII for CCTV Cameras, circular W-18/26/2025-IPHW · Ministry of Electronics and Information Technology
  6. Guidelines for Implementation of Migration to IS/IEC 62368-1:2023 · Bureau of Indian Standards
  7. IoT System Certification Scheme (IoTSCS): Certified product list as per the Essential Requirements · STQC Directorate
  8. Compulsory Registration Scheme public dashboard · Bureau of Indian Standards

Scoping a system like this? Talk to the team that designs, builds and maintains it.

Contact us