IIoT, IoT

ITSAR for Group VI Devices: The New Security Baseline for Smart Meters & Trackers

For senior executives in India’s IoT manufacturing and deployment sectors, a regulatory deadline is approaching that will reshape product development roadmaps. On March 5, 2026, the Department of Telecommunications India cipublished the Indian Telecom Security Assurance Requirements document, formally establishing Common Security Requirements for Group VI devices. This group includes three categories of IoT products that are already being deployed across India in massive volumes: Vehicle Tracking Devices, Smart Electricity Meters, and Feedback Devices.

This blog explains what ITSAR requires, why it creates a critical business opportunity for compliant IoT product design, and how Cionlabs helps clients meet these requirements with white-label solutions built on Beken chipsets.

Understanding Group VI Devices Under ITSAR

The National Centre for Communication Security formally added Group VI devices to the scope of mandatory security testing on March 27, 2026. This expansion marks a significant shift. Prior groups covered core network equipment, access network infrastructure, transmission equipment, IP networking devices, and terminal equipment. Group VI now brings mass-deployed IoT devices into the same security framework.

The three device types covered under Group VI are:

Device TypeITSAR Reference Number
Vehicle Tracking DevicesITSAR309072504
Smart Electricity MetersITSAR309052504
Feedback DevicesITSAR309042504

Source: NCCS memorandum, March 27, 2026 

“Feedback devices” is a category that encompasses multiple IoT product types that communicate data back to central systems. For most Indian IoT manufacturers and solution providers, this means that products deployed today will require security certification under ITSAR starting in the coming months.

The 16 Common Security Requirements: A Complete Compliance Framework

The ITSAR document establishes Common Security Requirements structured across 16 critical areas. These are not optional guidelines. They represent the mandatory baseline for security certification.

Authentication and Identity Management
Every Group VI device must implement robust authentication mechanisms. The device cannot trust data received from other devices without verification. Connections at all protocol levels must be intentional and protected against unauthorized access.

Authorisation and Access Control
Access to device functions and data must be controlled based on defined policies. Unauthorized access attempts must be prevented or logged.

Secure Storage of Sensitive Information
Any sensitive data stored on the device, including cryptographic keys and personal information, must be protected using approved encryption methods.

Data Protection
Personal data communicated between the device and associated services must be protected for confidentiality. Critical security parameters must be encrypted during transmission.

Secure Communication
All communication channels must implement Transport Layer Security version 1.2 or higher, regardless of the sensitivity of the data being transmitted. For cloud service communications using protocols like MQTT, encryption using Datagram Transport Layer Security version 1.2 or higher is required.

Cryptography
Secure cryptographic controls must be used for the protection of information, including data in transit and at rest. Only cryptographic algorithms and key lengths specified in the official ITSAR cryptographic controls table are permitted.

Vulnerability Management and Incident Management
Devices must have mechanisms to identify, assess, and address security vulnerabilities. Incident response procedures must be defined and implemented.

Software Updates and Software Integrity
Devices must support secure software updates. The integrity of firmware and software must be verifiable at all times.

Firmware and Bootloader Security
The boot process must be secured against unauthorized code execution. Firmware images must be cryptographically verified before loading.

Secure Execution Platform and Log Collection
The execution environment must be protected against common attacks. Security-relevant events must be logged and retained for analysis.

Minimisation of Exposed Attack Surface
Devices must disable or remove unnecessary services, ports, and protocols to reduce potential entry points for attackers.

Level-Based Requirements: Understanding the Security Tiers

The ITSAR framework organizes requirements into security levels. Not all requirements apply equally to all devices. The level applicable to a specific product depends on its risk profile and deployment context.

Level 1 (L1) Requirements
These are baseline security controls that apply to most devices. They include basic cryptographic controls, secure storage for sensitive information, and protection of personal data in communication.

Level 2 (L2) Requirements
These add authentication verification between devices and protection against unauthorized connections at all protocol levels. Devices must verify the identity of other devices on the network before establishing trust.

Level 3 (L3) Requirements
These are advanced controls for higher-risk deployments. They require TLS 1.2 or higher for all communications, X.509 certificate verification, protection against replay attacks, and security for email notifications. Cloud service communications must be encrypted and authenticated using DTLS 1.2 or higher.

For smart meters transmitting consumption data and vehicle trackers sending location information, Level 3 requirements will likely apply due to the sensitivity of the data involved.

How ITSAR Intersects with India’s DPDP Regime

ITSAR does not exist in isolation. It operates alongside the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025. Together, these regulations create a comprehensive framework for data security and privacy.

The DPDP Act applies to any entity processing digital personal data, including automotive OEMs, EV manufacturers, connected vehicle providers, telematics companies, fleet operators, and smart utility providers. For Group VI devices, this creates overlapping compliance obligations.

For Vehicle Tracking Devices:
Connected vehicles routinely collect GPS location, travel routes, speed patterns, braking and acceleration data, journey timing, and charging behavior for EVs. Under DPDP, location data is classified as high-risk because it can reveal home and workplace addresses, daily routines, and even sensitive inferences about religious, medical, or personal activities.

For Smart Electricity Meters:
Energy consumption patterns can reveal when a home is occupied, what appliances are used, and lifestyle details. This constitutes personal data requiring protection under DPDP.

For Feedback Devices:
Any device transmitting operational data that can be linked to an identifiable individual falls under DPDP jurisdiction.

The DPDP Act permits penalties up to INR 250 crore per contravention. For large-scale IoT deployments, non-compliance with ITSAR security requirements could trigger DPDP violations if personal data is exposed.

The Compliance Timeline: What Executives Need to Know

The DPDP Rules, notified on November 13, 2025, establish a phased implementation timeline that directly impacts IoT deployments.

Immediately effective: Definitions, Data Protection Board establishment, and rule-making powers.

By November 13, 2026: Consent manager registration requirements take effect.

By May 13, 2027: Core operational provisions, including consent requirements, Data Fiduciary obligations, and Board enforcement powers, become active.

For ITSAR certification, the NCCS memorandum indicates that testing for Group VI devices will begin as testing laboratories become equipped to validate full Security Assurance Requirements. The current phase uses Common Security Requirements as the basis for certification until specialized labs are available.

The practical implication is that Group VI devices sold or deployed in India must demonstrate compliance with ITSAR security requirements. Non-compliant products risk being barred from sale or facing mandatory recalls.

Why Off-the-Shelf IoT Modules Are Likely to Fail ITSAR Compliance

Many Indian IoT companies currently rely on imported modules or generic off-the-shelf hardware for their products. For Group VI devices subject to ITSAR, this approach carries significant risk.

Secure Boot and Cryptographic Key Storage
Generic modules rarely implement hardware-backed secure boot or protected key storage. ITSAR requires cryptographic keys to be stored using approved security controls. Software-only key storage does not meet this standard.

Communication Security
ITSAR mandates TLS 1.2 or higher for all communications regardless of data sensitivity. Many low-cost modules use older TLS versions or implement custom encryption that would not pass certification.

Replay Attack Protection
Devices must have built-in protection against replay attacks. This requires nonce or timestamp verification in every communication exchange. Generic modules may not include this functionality.

Software Update Mechanisms
Secure over-the-air updates with cryptographic verification of firmware integrity are required. Many imported modules lack robust update frameworks or implement them in ways that cannot be validated.

Certificate Verification
When using TLS, devices must cryptographically verify X.509 certificates. Generic modules often skip certificate validation to reduce processing overhead or simplify implementation.

For Indian companies deploying smart meters, vehicle trackers, or feedback devices at scale, these gaps represent a compliance liability that grows with every unit shipped.

The White-Label Advantage: Building ITSAR Compliance from Day One

Cionlabs has developed design methodologies that embed security at the hardware and firmware level, rather than adding it as an afterthought. For clients seeking white-label IoT products for the Indian market, this approach delivers three distinct advantages.

Advantage 1: Hardware-Level Security on Beken Chipsets
Beken Wi-Fi chips support hardware-accelerated cryptographic operations, secure key storage, and trusted execution environments. Cionlabs configures these capabilities to meet ITSAR cryptographic requirements. The result is a device that passes security audits without expensive redesigns.

Advantage 2: Compliance-Ready Communication Stacks
Every white-label solution from Cionlabs implements TLS 1.2 or higher with proper certificate validation. MQTT connections use DTLS 1.2 or higher as required for cloud communications. Protection against replay attacks is built into the protocol implementation.

Advantage 3: Secure Boot and Update Infrastructure
Cionlabs designs include secure bootloaders that verify firmware signatures before execution. Over-the-air update mechanisms support cryptographic integrity verification, meeting ITSAR requirements for software integrity and firmware security.

Market Opportunity: India’s Smart Meter and Vehicle Tracking Boom

The market context for Group VI devices is defined by rapid growth. India’s smart metering rollout is accelerating, with millions of units scheduled for deployment. Vehicle tracking devices are becoming standard in commercial fleets, logistics operations, and increasingly in personal vehicles for insurance telematics.

The addressable market for compliant Group VI devices includes:

  • Smart electricity meters: Required for state utility AMI (Advanced Metering Infrastructure) projects
  • Vehicle tracking devices: Mandated for commercial fleets, public transport, and logistics
  • Feedback devices: Encompassing industrial sensors, environmental monitors, and infrastructure telemetry

For each of these categories, ITSAR compliance will become a non-negotiable requirement for government tenders and enterprise contracts. Companies that cannot demonstrate certified security will be excluded from bidding.

The Cionlabs Difference: From Concept to Certified Product

Cionlabs has established partnerships with technology leaders, including Fingerprint Cards AB, for biometric security integration. Our experience spans healthcare IoT, industrial monitoring, and smart home devices. For Group VI devices, we bring specific capabilities that matter for ITSAR compliance.

Beken Chipset Expertise
We have deep experience with Beken Wi-Fi and Bluetooth solutions, including the BK7236/7239 and BK7258 series. These chips provide the processing power for cryptographic operations and the connectivity required for Group VI device functionality.

Security-First Design Process
Our design reviews include security requirements mapping against ITSAR controls before hardware development begins. This prevents the costly scenario of discovering compliance gaps after production tooling is complete.

Testing and Certification Support
We work with testing laboratories to validate ITSAR compliance. Our documentation packages include all required security artifacts for certification submissions.

White-Label Delivery
Clients receive complete product designs, firmware, and manufacturing files under their own brand. Cionlabs handles the technical complexity while you own the customer relationship and market positioning.

The Takeaway for Senior Executives

The ITSAR framework for Group VI devices is not optional. It is the new security baseline for smart meters, vehicle trackers, and feedback devices sold in India. The March 2026 publication of requirements and the NCCS testing scope expansion mean that compliance is already on the enforcement horizon.

For companies currently deploying or planning to deploy Group VI devices, the choice is clear. Continue with non-compliant off-the-shelf modules and face potential market exclusion, mandatory recalls, and DPDP penalty exposure. Or partner with a design house that builds compliance into the product from the start.

Cionlabs offers the fastest path to ITSAR-compliant white-label IoT products. With Beken chipsets, security-first design, and India-focused regulatory expertise, we deliver solutions that pass certification and perform reliably in the field.

The compliance window is open. The Indian market for smart meters and connected devices continues to grow. Secure your place in it with products designed for the new security baseline.

Ready to build ITSAR-compliant white-label IoT products? Contact Cionlabs to discuss your Group VI device requirements. We offer reference designs for smart meters, vehicle trackers, and feedback devices with security built in from day one. From concept to certified production, we deliver solutions that meet India’s new security standards.

Cionlabs: Electronics design house specializing in IoT, IIoT, and AIoT solutions. We work with Beken, pioneers in Wi-Fi chips, to deliver white-label products for the Indian market.