How Indian Telecom Security Assurance Requirements (ITSAR) Security Testing Works: A Guide for Overseas Manufacturers
How Indian Telecom Security Assurance Requirements (ITSAR) Security Testing Works: A Guide for Overseas Manufacturers
ITSAR security testing is conducted on a model-specific basis. An NCCS-designated Telecom Security Testing Laboratory (TSTL) evaluates each product against the applicable ITSAR requirements within a 16-week testing window before submitting its report to the National Centre for Communication Security (NCCS) for certification.
For manufacturers outside India, understanding the process before testing begins is one of the most effective ways to avoid unnecessary delays.
The first step is identifying the correct ITSAR category for your product. Each device is mapped to one or more ITSAR categories, and selecting the wrong category can result in an incorrect test plan and significant delays. It’s advisable to confirm the appropriate category with a designated TSTL before submitting your application.
Next, the manufacturer—or an authorized Indian representative—registers the product through the MTCTE portal. ITSAR security certification forms part of the broader MTCTE framework, making portal registration a required step.
The next stage is selecting a designated TSTL. While multiple laboratories may be approved for a category, testing capacity is often limited. A designated lab may have a substantial scheduling backlog, so engaging a laboratory early can help protect your certification timeline and product launch.
Before formal testing begins, manufacturers must provide the TSTL with a device hardening guide. Thorough preparation at this stage can significantly reduce remediation during testing. Common issues include legacy services left enabled, weak or shared administrative credentials, software update mechanisms that do not verify digital signatures, and unnecessary packages remaining in production builds.
The formal testing period lasts up to 16 weeks, but that timeframe includes both testing and any remediation required. If issues are identified, manufacturers must implement fixes and return the device for verification, reducing the time available within the testing window. A well-prepared, hardened device therefore has a much greater chance of completing the process on schedule. NCCS may also appoint a validator to oversee technical aspects of the evaluation.
Once testing is complete, the TSTL submits its report to NCCS for review. If the device satisfies the applicable ITSAR requirements, NCCS issues a security certificate that remains valid for 10 years, provided the product continues to comply with any future ITSAR updates.
In practice, testing itself is rarely the primary cause of delays. Most schedule overruns occur during remediation, when failed controls require firmware updates and repeat testing. Each remediation cycle consumes part of the 16-week testing window, making pre-test readiness a critical factor in achieving certification on time.
As a designated TSTL, Compliance International performs pre-test readiness assessments against the applicable ITSAR requirements before formal testing begins. The objective is to identify and resolve issues early, allowing manufacturers to use the formal testing window for certification rather than remediation. Contact us with your product details to discuss the appropriate testing scope and certification pathway.