India’s National Centre for Communication Security (NCCS) has extended the exemption from mandatory security certification for cloud-implemented IP Routers and Wi-Fi Customer Premises Equipment (CPEs). In a notification dated 13 August 2026, NCCS confirmed that the exemption, previously in force until 31 August 2026, is now extended to 31 December 2026.
For OEMs, importers, and applicants working with these product types, the extension provides additional breathing room, but it also sets a clear new date to plan around. The notification, issued by NCCS under the Department of Telecommunications (DoT), Ministry of Communications, continues an earlier notification dated 30 March 2026 that had granted the exemption until 31 August 2026. The latest notification extends that same exemption for cloud-based IP Routers and Wi-Fi CPEs through to the end of the year.
The extension was issued with the approval of the Senior Deputy Director General, NCCS, and applies to all OEMs, dealers, importers, applicants, and Telecom Security Testing Laboratories (TSTLs), communicated through the NCCS website.
Understanding the Context: NCCS, ITSAR and MTCTE
Security certification in India is governed by the Indian Telecom Security Assurance Requirements (ITSAR), a security framework administered by NCCS. It runs in parallel with the Mandatory Testing and Certification of Telecom Equipment (MTCTE) scheme, which covers broader market-access requirements such as conformance, EMC, and safety.
For many networking products, both frameworks apply: MTCTE provides market access, while ITSAR addresses security assurance, with testing carried out at NCCS-designated TSTLs. In December 2025, NCCS released ITSAR Version 2.0.0 for Wi-Fi CPEs and IP Routers, introducing updated and more comprehensive security requirements for these product categories, including clearer coverage of cloud-native and virtualised deployments.
The exemption now being extended relates specifically to cloud-implemented IP Routers and Wi-Fi CPEs, giving the industry time to align with these evolving requirements.
Why This Matters
For OEMs, the extension is a welcome relief that provides flexibility to prepare products, evaluate their security posture, and align with the updated NCCS framework without an immediate certification cliff.
At the same time, the extension is best treated as a planning checkpoint rather than a pause. With ITSAR 2.0.0 now defining the security requirements for these products, the extended window is an opportunity to assess products against the current standard, identify gaps early, and prepare well ahead of the revised compliance timeline, rather than facing a rush as the deadline approaches.
What OEMs Should Do Now
Manufacturers, importers, and applicants dealing with cloud-based IP Routers and Wi-Fi CPEs for the Indian market should use this window strategically:
- Confirm how their products are classified (Wi-Fi CPE vs. IP Router) and whether their deployment model falls within the exemption.
- Carry out a gap assessment against ITSAR Version 2.0.0, updating security design, evidence, and test plans as needed.
- Build a readiness roadmap aligned to the 31 December 2026 date, factoring in TSTL testing lead times.
- Engage early with NCCS-designated testing laboratories to avoid capacity constraints closer to the deadline.
To read the official notification, access below.
How C-PRAV Can Support You
As one of India’s leading certification service providers, C-PRAV supports OEMs and importers with NCCS security certification and ITSAR readiness. Our India-based experts can carry out ITSAR 2.0 gap analysis and readiness assessments, coordinate testing through NCCS-designated TSTLs, and manage your security certification and MTCTE requirements end-to-end, helping you navigate the compliance journey smoothly and stay ahead of the December 2026 deadline.
Have questions? Reach out to us at India@c-prav.com or contact us here.