Defence & government cyber advisory in India — legal authority where national security meets cyber compliance.
Confidential advisory for PSUs, defence contractors, and government technology vendors navigating NCIIPC compliance, classified system procurement, security clearance pathways, and contractor liability frameworks under India's evolving defence acquisition and critical infrastructure regime.
What "critical infrastructure" actually means legally
Designation depends on what the system does, not how big your company is.
A common assumption among mid-sized government technology vendors is that NCIIPC obligations are something only large PSUs and defence primes need to think about. That assumption is wrong in a specific, legally material way. Under Section 70 of the IT Act 2000, the central government can designate any computer resource a "Protected System" if its incapacitation or destruction would have a debilitating impact on national security, the economy, public health, or public order. The designation criterion is functional criticality — not the size, turnover, or corporate structure of the entity that operates it.
That means a smaller vendor running a system with genuine systemic importance can find itself inside the Protected System regime alongside much larger contractors, subject to the same Section 70(3) strict-liability exposure: unauthorised access carries imprisonment of up to 10 years. The operative day-to-day obligations sit in the Information Technology (Information Security Practices and Procedures for Protected System) Rules 2018 — appointment of a Chief Information Security Officer, an Information Security Steering Committee, an ISMS aligned to recognised standards, and annual internal and external audits, with the Protected System itself reassessed at least every two years.
The procurement side is moving in the same direction. Draft DAP 2026 proposes raising the indigenous content threshold under the Buy (Indian-IDDM) category from 50% to at least 60%, and — for the first time — would require 30% indigenous content even in the Buy (Global) category, which previously carried no such requirement at all. With a FY 2026-27 capital procurement budget of roughly ₹2.19 lakh crore and about 75% of that earmarked for domestic industry, the practical stakes of getting indigenous-content classification right have grown substantially. One caution worth flagging plainly: DAP 2026 remains in draft, and its treatment of offset obligations has drawn scrutiny for inconsistent references across its own published volumes — a vendor structuring a bid today should confirm current offset treatment rather than assume DAP 2020's terms still apply unmodified.
Confidentiality from the first call
Every engagement in this practice runs under attorney-client privilege from the initial consultation.
Where government and defence vendors get exposed
Four ways this work carries sharper stakes than commercial contracting
Government and defence engagements don't just carry higher financial exposure — they carry criminal, reputational, and eligibility risks that a standard commercial contracts review doesn't screen for.
CII designation can apply without warning
A system doesn't need to look like "critical infrastructure" to be designated a Protected System — functional criticality is the test, and vendors are sometimes designated after the fact, with governance obligations that then apply retroactively to how the system was already being run.
Strict liability, not negligence-based exposure
Section 70(3)'s criminal penalty for unauthorised access to a Protected System is a strict-liability provision. Contractor liability clauses drafted for commercial breach scenarios don't map cleanly onto this exposure, and often leave individual officers under-protected.
Indigenous content classification errors are costly
Misclassifying a bid's indigenous content percentage under DAP categories can disqualify a bid outright or trigger post-award compliance disputes — errors that are avoidable with the right legal structuring before submission, not after.
Vendor and subcontractor obligations extend downstream
Supply chain vendors and service providers connected to CII operators can themselves fall inside compliance scope by dependency — shared infrastructure like Active Directory or jump hosts is a common point examiners flag as in-scope but unaddressed.
What we cover
Defence & government legal services at the intersection of security and compliance
Legal advisory for organisations operating at the intersection of national security, technology procurement, and regulatory compliance under India's NCIIPC and defence acquisition frameworks.
NCIIPC Compliance
Legal advisory on NCIIPC critical information infrastructure protection obligations, compliance audit frameworks, incident reporting requirements, and nodal agency liaison.
- Protected System designation risk assessment
- 2018 Rules governance structure (CISO, ISSC, ISMS)
- Annual audit and biennial reassessment support
- NCIIPC advisory closure documentation
Classified System Procurement
Legal due diligence for technology procurement in classified environments — supplier security vetting, NDAs with national security provisions, and contract risk allocation.
- Supplier security vetting support
- National-security-grade NDA drafting
- Contract risk allocation structuring
- Procurement due diligence
Security Clearance Pathways
Legal guidance for companies seeking government security clearances — documentation, eligibility assessment, MHA and MoD liaison, and clearance maintenance compliance.
- Eligibility assessment and documentation
- MHA and MoD liaison support
- Clearance maintenance compliance
- Ongoing eligibility monitoring
Contractor Liability Frameworks
Liability structuring for government and defence contractors — indemnification caps, data breach responsibility allocation, IP ownership, and sovereign immunity analysis.
- Indemnification cap structuring
- Data breach responsibility allocation
- IP ownership and design authority terms
- Sovereign immunity analysis
Defence Procurement Regulations
Advisory on the Defence Acquisition Procedure (including draft DAP 2026), Make in India defence provisions, offset obligations, Technology Transfer agreements, and DPSU regulatory compliance.
- DAP 2026 category and indigenous content advisory
- Offset obligation structuring above ₹2,000 Cr
- Technology Transfer agreement drafting
- DPSU regulatory compliance
AI in Defence Legal Advisory
Legal framework for AI deployment in defence and government — autonomous system liability, algorithmic decision accountability, and AI ethics compliance under the NCIIPC framework.
- Autonomous system liability structuring
- Algorithmic decision accountability
- NCIIPC-aligned AI supply-chain due diligence
- AI ethics compliance documentation
Evidence, not guesswork
DAP 2020 vs. draft DAP 2026 — what's actually changing for vendors
DAP 2026 remains a draft as of publication. Here's how its proposed terms compare to the current DAP 2020 framework vendors are still operating under today.
| Provision | DAP 2020 (current) | Draft DAP 2026 (proposed) |
|---|---|---|
| Buy (Indian-IDDM) indigenous content | 50% minimum | At least 60%, phased across programme lifecycles |
| Buy (Global) indigenous content | No requirement | 30% required for the first time |
| Policy emphasis | Domestic manufacture and assembly | Ownership and control of design, source code, and IP |
| iDEX / Make procedures | Peripheral to mainstream acquisition | Formal acquisition paths with spiral development and assured orders |
| Offset policy treatment | Applies above ₹2,000 crore contract value | Referenced inconsistently across draft volumes — confirm before relying on it |
| Status | In force | Draft, released for stakeholder feedback |
Sources: Ministry of Defence draft DAP 2026 publication (February 2026); Press Information Bureau release on DAP 2026; industry analysis of indigenous content and offset provisions. DAP 2026 remains subject to revision before final notification — verify current status before relying on any specific provision for an active bid.
What this scale actually looks like
Four numbers that frame the stakes in defence and CII work
Under Section 70(3) of the IT Act for unauthorised access to a Protected System — a criminal, strict-liability exposure distinct from civil penalty regimes.
Roughly 75% earmarked for domestic industry — a substantial share of national defence spending now tied to indigenous content compliance.
Protected Systems require annual internal and external security audits, with the designation itself reassessed at least every two years.
NCIIPC and CERT-In cohabit the incident response landscape — a single breach can trigger obligations to both simultaneously.
Why SIRI
Government work demands legal and security expertise together
No other firm in India combines attorney-client privilege with technical execution across cybersecurity and government-facing law — assessed inside the same engagement, under the same confidentiality standard.
Government procurement fluency
Our team has advised on GFR, CVC guidelines, and defence procurement regulations — we understand the regulatory environment government contractors operate within, including how draft DAP 2026 changes bid classification.
Security-conscious process capability
Our integrated legal-security model allows technical assessments alongside legal advisory in environments requiring confidentiality and structured information-handling protocols.
NCIIPC and CERT-In regulatory literacy
We track NCIIPC, CERT-In, and MeitY regulatory developments continuously and translate them into what they actually require of a specific Protected System or defence contractor — not generic policy summaries.
Policy development support
We draft cybersecurity policies, incident response procedures, and vendor management frameworks built to satisfy government audit requirements and the 2018 Protected System Rules' governance structure.
Who we work with
PSUs, contractors, and technology vendors across the government supply chain
From prime defence contractors to the mid-sized technology vendors supplying them — CII and defence procurement obligations reach further down the supply chain than most vendors expect.
How we work
From confidential intake to a defensible compliance posture
Confidential intake
A privileged initial consultation to understand your system, contract type, and current CII or procurement exposure — before any scope is agreed.
Day 1Exposure assessment
We map your specific obligations under NCIIPC, the 2018 Protected System Rules, and applicable DAP categories, ranked by regulatory and contractual priority.
Weeks 1–2Structuring & advisory
Contract structuring, indigenous content classification support, clearance documentation, or governance policy drafting — executed with confidentiality as the default.
Engagement-specificStanding counsel
Ongoing advisory as NCIIPC guidance, DAP provisions, and audit cycles evolve — so your compliance posture doesn't go stale between formal reviews.
OngoingFrequently asked
Defence & government cyber advisory, answered directly
What makes a system "Critical Information Infrastructure" under Indian law?
Under Section 70 of the IT Act 2000, the central government can designate any computer resource a Protected System if its incapacitation or destruction would have a debilitating impact on national security, the economy, public health, or public order. Designation is based on functional criticality, not the size or turnover of the entity operating it — a mid-sized vendor can be in scope if the system it runs qualifies.
What are the penalties for unauthorised access to a Protected System?
Under Section 70(3) of the IT Act, unauthorised access to a Protected System is a criminal offence punishable with imprisonment up to 10 years and a fine — a strict-liability provision, not a civil penalty schedule. This sits alongside the Information Technology (Information Security Practices and Procedures for Protected System) Rules 2018, which set out the operative governance, audit, and reporting requirements for designated entities.
What changes under DAP 2026 for defence technology vendors?
The Defence Acquisition Procedure 2026, released in draft by the Ministry of Defence to replace DAP 2020, raises the indigenous content requirement under the Buy (Indian-IDDM) category from 50% to at least 60%, and for the first time requires 30% indigenous content even in the Buy (Global) category, which previously had none. It also shifts emphasis from manufacture to ownership of design, source code, and core IP, and brings iDEX and Make procedures into the mainstream acquisition pipeline rather than treating them as peripheral innovation tracks.
At what contract value do offset obligations apply?
Under the existing offset policy, offsets are mandatory for contracts above ₹2,000 crore, requiring foreign vendors to invest a specified percentage of contract value in India through direct purchase, FDI, or technology transfer. DAP 2026's treatment of offsets has drawn scrutiny for inconsistent references across its published volumes, so vendors should confirm current offset treatment for a specific procurement category before relying on the older DAP 2020 framework.
Can a mid-sized technology vendor be subject to NCIIPC obligations?
Yes. Designation as a Protected System depends on the functional criticality of the specific system, not the size of the company operating it. Supply chain vendors and service providers connected to a designated CII operator can also fall inside compliance scope by dependency — shared infrastructure like Active Directory, jump hosts, or a shared logging platform is a common point examiners flag as in-scope but frequently unaddressed.
How does confidentiality work for a government or defence engagement?
Every engagement in this practice operates under attorney-client privilege from the initial consultation. For matters requiring structured information handling, our integrated legal-technical model allows assessments to proceed within the confidentiality protocols your contract or clearance status requires, without needing to bring in a separate, uncoordinated technical vendor.
Ready when you are
Working on government or defence technology?
SIRI provides confidential advisory services to PSUs, defence contractors, and government technology vendors. Contact us to discuss your requirements.
Related services
Other ways SIRI Law LLP supports regulated technology work
Cybersecurity testing services
Penetration testing and red teaming, including OT/ICS-aware assessment for CII environments.
Data privacy & cybersecurity law
DPDPA compliance, breach response, and CERT-In notification support.
AI & emerging technology law
EU AI Act compliance, algorithmic liability, and AI governance frameworks.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

