India’s Trusted Source Requirement: What BIS, WPC and TEC Do Not Cover

Table of Contents

You have worked through the Indian requirements that apply to your product. BIS registration where it falls under a compulsory scheme. WPC equipment type approval where the radio equipment is in scope. TEC certification under MTCTE where the telecom equipment is covered. Separate regimes, separate timelines, all cleared before shipping.

Then your customer, a telecom operator, asks whether your product is a Trusted Product from a Trusted Source.

That is a different compliance gate. The India trusted source requirement is not a product certification, and passing the other Indian requirements does not by itself establish trusted product status.

Carra Globe acts as importer of record in India, so we have a commercial interest in this subject. What follows is written to be usable whether or not you ever speak to us, including the part where this does not apply to you at all.

What is the India trusted source requirement?

A network procurement and security condition, not another product certificate. Entities in scope may connect covered equipment only where the product and its source have been accepted.

The Cabinet Committee on Security approved the directive in December 2020. Telecom licence conditions were amended in March 2021, and from 15 June 2021 operators have been required to connect only trusted products, and to seek permission from the designated authority to upgrade an existing network using equipment not so designated.

Two terms do the work. A Trusted Source is a source designated by the designated authority, and a Trusted Product is the associated equipment specified in connection with it. Being one does not automatically make you the other.

The designated authority is the National Cyber Security Coordinator. The Trusted Telecom Portal, established by the National Security Council Secretariat, is the operational channel for the process, including operator procurement submissions and the associated vendor and product information. The exact route depends on the equipment category, the vendor’s status and the customer’s authorisation, so confirm it rather than assuming.

The distinction that matters: BIS, WPC and TEC assess the product. The trusted source framework addresses whether the equipment and its source are accepted for procurement into a regulated telecom network. A device can hold every applicable product certification and still be ineligible for procurement or connection on that customer’s regulated network.

Does my equipment need Trusted Product status? Only where it is being procured or connected within a notified telecom network framework and your customer is bound by the applicable conditions. Ordinary enterprise imports are generally outside this particular requirement, but the customer’s authorisation and the equipment category both need checking.

What changed in 2026

Important if you are reading anything written before this summer, because the framework it describes has moved.

The original directive was implemented through amendments to telecom licence conditions. India has since moved from that licensing architecture to a new authorisation framework, while existing licences remain relevant during the transition.

Under the Telecommunications Act 2023, new authorisation rules were notified during 2026 covering both telecom services and telecom networks.

The Telecommunications (Authorisation for Telecommunication Network) Rules were notified on 20 July 2026. The framework arrived in stages, so check the current instruments on the department’s portal rather than assuming a single rule set covers your customer.

Trusted source and trusted product conditions carried across into the new rules. They now sit as conditions on authorised entities rather than only as licence conditions, so the requirement did not go away with the licensing regime. Existing licensees may migrate to the corresponding authorisation or continue under their current licence, which means both frameworks are live at once during the transition.

The network rules create specific network authorisations, and two are worth knowing if you sell into data centres.

  • Digital Connectivity Infrastructure Provider
  • Cloud-Hosted Telecommunication Network Provider

Those categories can matter in some data centre and telecom infrastructure deployments. Which is why scope should be checked against the customer’s actual authorisation and the function the equipment performs, rather than judged from the label “data centre” alone.

Infographic on India's trusted source requirement, comparing BIS, WPC and TEC product certifications against the NCSC supply chain assessment, with four questions to determine whether the framework applies.

Does this apply to you?

Often not, and it is worth establishing that before anyone spends money on it.

The requirement is tied to the telecom network regulatory framework rather than to every importer. It is not a general import control, which is why it does not appear in customs guidance and why most vendors have never encountered it.

Under the legacy framework it binds licensed telecom service providers. Under the 2026 rules it binds authorised entities. Do not treat “not a traditional telecom operator” as an automatic exemption, because scope also depends on the equipment category and the customer’s authorisation.

Who your customer isDoes the framework apply?
A telecom operator, whether a legacy licensee or an authorised entityYes, where the authorisation and the equipment category bring it into scope
An enterprise buying networking kit for its own officesGenerally outside this regime, unless another telecom authorisation applies
A data centre or colocation operatorDepends on its authorisation status and the network function involved. Do not assume either way
A reseller or systems integratorNot normally the regulated entity, but its customer may be

Row three is the one worth checking rather than assuming.

India’s data centre buildout is substantial, and the 2026 network authorisation categories changed how that question is answered. The authorisation follows the function rather than the building, so start with four questions to the customer.

  • Do you hold a telecom licence or network authorisation? The most direct question, and often the only one needed.
  • Do you provide connectivity to third parties, or only house their equipment?
  • Do you operate network infrastructure yourself, as opposed to providing space, power and cooling?
  • Do you offer cloud or hosted services over your own network? This is the function the cloud-hosted network category addresses.

A colocation facility that only provides space, power and cooling may fall outside these particular network authorisations, but confirm the operator’s regulatory status rather than relying on the business model alone. An operator answering yes to any of the last three is worth checking properly before you quote.

How the process works, and what is not public

Worth separating what the framework states from what vendors have to find out for themselves, because a good deal of the operational detail is not published.

What the framework establishes. The designated authority notifies the categories of equipment for which trusted source requirements apply, and notifies the trusted sources together with their associated trusted products. Operators and vendors provide details of the products intended for the network, the vendor, and the sources of critical components. Those are then assessed, and the outcome is communicated to the vendor and the operator concerned.

So the assessment reaches past the product to the vendor and its component supply chain. That is the structural difference from BIS, WPC and TEC, and it is why a product certificate cannot substitute for it.

What is not publicly specified is just as important. Processing times, validity periods, whether designation attaches per product or per product family, and the precise documentary set are not published in the way BIS or TEC timelines are. Anyone quoting you a confident duration for this is guessing. Treat it as a dependency with an unknown length and start it early.

Which makes the practical instruction straightforward. Do not plan a deployment around an assumed designation timeline. Establish with the OEM whether status already exists for that product, because an existing designation removes the uncertainty entirely and a fresh one introduces it.

The maintenance question vendors get wrong

The licence amendment indicated the directions would not affect ongoing annual maintenance contracts, or updates to equipment already inducted into a network. That sounds like a clean exemption. It is not, because the boundary is not drawn in detail.

A firmware update to installed equipment sits comfortably inside the wording. A like-for-like replacement part under an existing contract is arguable. An expansion module that adds capacity, or a hardware refresh onto a newer model, starts to look like new equipment rather than maintenance of old.

That gradient is where expensive assumptions get made. If you are selling support, upgrades or replacement hardware into an existing Indian network, get the operator’s own reading in writing rather than relying on the exemption sounding broad.

How it sits alongside the other three

Four separate questions, answered through separate processes. None substitutes for another.

RegimeBodyWhat it assesses
BIS registrationBureau of Indian StandardsDoes the product comply with the applicable Indian requirements for its category?
WPC equipment type approvalWireless Planning and Coordination wingDoes the wireless equipment meet the applicable Indian requirements for use of radio frequency spectrum?
TEC certification under MTCTETelecommunication Engineering CentreDoes the covered telecom equipment meet the applicable essential requirements?
Trusted source and trusted productNational Cyber Security CoordinatorIs the source and product accepted for procurement into a regulated telecom network?

Our guide to importing IT equipment into India covers the first three in detail, including which products fall under BIS rather than MTCTE, and the timelines each one runs on.

Worth noting that international marks do not substitute either. CE and FCC are complements to the Indian regimes, not replacements for them.

What it means commercially

This is the part that catches vendors, and it is a sales problem before it is a compliance one.

You can import the equipment lawfully and still be unable to sell it to that customer. Import clearance and network connection are different gates. Goods that clear Indian customs without difficulty can sit in a warehouse because the operator cannot lawfully connect them.

Which means the question belongs in the sales conversation rather than the logistics one. Asking a telecom customer early whether trusted product designation is required is a short conversation. Discovering it after the hardware has landed is not.

Alongside the trusted list, the designated authority may notify sources from which no procurement may be made at all. India’s framework operates through designated trusted sources and associated trusted products rather than relying only on a prohibition list, so an unassessed vendor should not assume automatic acceptance.

The framework was introduced with supply chain security as its stated purpose. Because it examines the vendor and aspects of its supply chain, vendors should raise ownership, manufacturing and critical-component questions with the OEM early rather than treating designation as a formality.

Four questions before you quote an Indian telecom customer

  1. What telecom licence or authorisation do they hold? This helps determine whether the trusted source and trusted product framework applies.
  2. Is the equipment being connected to their network, or used in a way that falls outside it?
  3. Is it new equipment, or an update to something already inducted?
  4. Has the relevant Trusted Source and Trusted Product information been submitted or designated through the applicable process, and can the OEM provide supporting evidence?

Question four usually goes to your manufacturer rather than to you. A reseller should not assume it can obtain or transfer the designation in its own name. Where an OEM is not registered in India, the process provides for it to nominate an India-registered entity as its authorised representative for portal interactions.

Practically, that means a foreign reseller should ask the OEM two things: whether the product already carries trusted product status, and if not, whether the OEM has an India-registered entity able to act for it. The answer decides whether this is a short conversation or a long one.

Worth knowing that the nominated entity is the OEM’s representative for this purpose, not necessarily your importer of record. They can be the same company in some structures and frequently are not, so do not assume that appointing an importer solves the representation question, or that the OEM’s representative will handle your customs entry.

How Carra Globe helps

The boundary first. We are not a certification body and we do not obtain trusted source designation. That sits between the OEM, the operator and the designated authority, and no importer of record can shortcut it.

What we do is the import side, and flag this before it becomes a problem.

  • Acting as importer of record in India where you have no local entity, covered in our India IOR services.
  • Screening the approval picture before shipment, including BIS, WPC and TEC, so a certificate gap is known at quotation rather than at the border.
  • Telling you when the framework is likely to apply, so the question reaches your customer early rather than after the hardware arrives.

Our note on importer of record for telecom equipment covers the wider picture, and our India server import case study shows what a properly sequenced deployment looks like.

Shipping networking hardware to an Indian customer? Send the equipment list, the end customer and what they do. We will map the Indian import and telecom compliance requirements, and tell you whether the trusted source framework is likely to be in scope.

Importer of Record · India

We handle the import side. The trusted source question belongs to your OEM.

Being straight about the boundary: we do not obtain trusted source designation, and nobody offering it as part of an import service should be taken at their word. What we do is act as importer of record in India, screen the BIS, WPC and TEC picture before shipment, and tell you when the trusted source framework is likely to be in scope.

Free tools HS Code Finder Volumetric Weight Calculator Pallet Calculator

Selling networking hardware into India? Send the equipment list, the end customer and what they actually do. We will map the import requirements and tell you whether the trusted source framework is likely to apply before you quote.

Check if trusted source applies

Frequently asked questions

Is trusted source approval the same as TEC certification?

No. TEC certification under MTCTE tests the equipment against essential requirements. Trusted source designation assesses the vendor and supply chain, and is administered by a different authority.

A product can hold TEC certification and still not be a designated trusted product.

Does this apply to enterprise IT equipment?

Generally not. The requirement attaches to the telecom network regulatory framework rather than to general imports, so an enterprise buying kit for its own offices is usually outside it.

Confirm the customer’s authorisation status rather than assuming, since the 2026 network rules created categories that some data centre operators fall within.

Can my importer of record obtain trusted source designation for me?

No. An importer of record cannot substitute for the OEM or source in the trusted source process. That sits between the vendor, the operator and the designated authority.

Anyone offering to obtain it as part of an import service is worth questioning closely.

Will customs stop my shipment if the product is not designated?

Not for that reason alone. Trusted product status is a network procurement condition rather than a standalone customs requirement, so it primarily arises at the procurement and deployment stage.

That is not a guarantee of clearance. Missing BIS, WPC, TEC, licensing or documentation requirements can still stop or delay a shipment. It simply means this particular gate sits later, which is why goods that clear customs can still be unusable by the customer who ordered them.

Sources and verification

  • The directive: the National Security Directive on the Telecommunication Sector, approved by the Cabinet Committee on Security in December 2020, implemented through telecom licence amendments in March 2021 and effective from 15 June 2021, with the Trusted Telecom Portal established by the National Security Council Secretariat as the operational channel.
  • The 2026 framework: authorisation rules notified during 2026 under the Telecommunications Act 2023, covering telecom services and telecom networks, including the Telecommunications (Authorisation for Telecommunication Network) Rules 2026 notified on 20 July 2026. Confirm the exact instrument and rule applicable to your customer on the department’s portal. Trusted source and trusted product conditions carry across as conditions on authorised entities, and existing licensees may migrate or continue under their current licence.
  • The authority: the National Cyber Security Coordinator is the designated authority, notifying the categories of equipment in scope together with trusted sources and associated trusted products. The Department of Telecommunications and its Act and Rules portal publish the current instruments.
  • Scope changes. Both frameworks are live during the migration period, and notified equipment categories can change. Check the current position against the applicable rules and the portal before each deployment rather than relying on an article.


Disclaimer: This guide is for informational purposes only and does not constitute legal, regulatory or customs advice. The scope of the National Security Directive, the categories of equipment notified and the designation process are set by the Indian authorities and change over time. This article reflects publicly available information as at 11 September 2026. Always confirm the current position with the relevant authority, your customer or a qualified adviser before shipping.

Facebook
Twitter
LinkedIn
WhatsApp
Email

Request a Quote