The National Cyber Security Policy is a comprehensive policy framework, not a binding act, released by the Department of Electronics and Information Technology (DeitY), which was then under the Ministry of Communications and Information Technology. It was India's first such framework, released on July 2, 2013. The policy was created against the backdrop of escalating cyber intrusions and the global anxiety caused by the Edward Snowden disclosures in 2013, which highlighted the need to safeguard national security and citizen data.
The policy’s legal foundation is rooted in the Information Technology Act, 2000, specifically the 2008 amendments that inserted Section 70A and Section 70B. Its mechanism designated the Indian Computer Emergency Response Team (CERT-In) as the national nodal agency for coordinating incident response and crisis management. It also mandated the creation of the National Critical Information Infrastructure Protection Centre (NCIIPC), formally notified under Section 70A, to protect sectors like power and banking. Key provisions included encouraging all organizations to designate a Chief Information Security Officer (CISO) and setting an ambitious goal to train 500,000 cyber-security professionals within five years.
While the NCSP 2013 remains the existing policy, it is considered outdated, and a new National Cybersecurity Strategy developed by the National Security Council Secretariat (NSCS) is awaited. However, the institutional framework has seen recent operational changes, such as the 2022 directions issued by CERT-In requiring organizations to report specified cyber incidents within six hours and maintain logs for 180 days. The recently enacted Digital Personal Data Protection Act, 2023 (DPDPA) also connects to and transforms the broader data protection landscape.