📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Defence & Government Cyber Law Advisory in India | NCIIPC, DAP 2026 — SIRI Law LLP
Defence & Government Cyber Advisory · Hyderabad, India

Defence & government cyber advisory in India — legal authority where national security meets cyber compliance.

Confidential advisory for PSUs, defence contractors, and government technology vendors navigating NCIIPC compliance, classified system procurement, security clearance pathways, and contractor liability frameworks under India's evolving defence acquisition and critical infrastructure regime.

10 yrsMaximum imprisonment for unauthorised access to a Protected System
60%Indigenous content threshold proposed under draft DAP 2026
₹2,000 CrContract value above which offset obligations apply
2Disciplines under one privilege: government law + cyber advisory
The defence & CII clock
Live tracking · scroll to see every relevant development
Statutory
IT Act §70/70A
Empowers the central government to designate any computer resource a Protected System; established NCIIPC as the nodal CII authority in 2014.
Standing
2018 Rules
Information Security Practices and Procedures for Protected System Rules — the operative governance, audit, and reporting rulebook for designated entities.
Draft
FEB 2026
Draft Defence Acquisition Procedure 2026 released by the Ministry of Defence for stakeholder feedback, to replace DAP 2020.
Raised
DAP 2026
Indigenous content threshold under Buy (Indian-IDDM) proposed to rise from 50% to at least 60%, phased across programme lifecycles.
New
DAP 2026
Buy (Global) category — previously with no indigenous content requirement — would require 30% indigenous content for the first time.
Budget
FY26–27
Capital procurement budget of approximately ₹2.19 lakh crore, with roughly 75% earmarked for domestic industry procurement.
Caution
Ongoing
DAP 2026 remains in draft; its treatment of offset obligations shows inconsistent references across published volumes — confirm current status before relying on specifics.

What "critical infrastructure" actually means legally

Designation depends on what the system does, not how big your company is.

A common assumption among mid-sized government technology vendors is that NCIIPC obligations are something only large PSUs and defence primes need to think about. That assumption is wrong in a specific, legally material way. Under Section 70 of the IT Act 2000, the central government can designate any computer resource a "Protected System" if its incapacitation or destruction would have a debilitating impact on national security, the economy, public health, or public order. The designation criterion is functional criticality — not the size, turnover, or corporate structure of the entity that operates it.

That means a smaller vendor running a system with genuine systemic importance can find itself inside the Protected System regime alongside much larger contractors, subject to the same Section 70(3) strict-liability exposure: unauthorised access carries imprisonment of up to 10 years. The operative day-to-day obligations sit in the Information Technology (Information Security Practices and Procedures for Protected System) Rules 2018 — appointment of a Chief Information Security Officer, an Information Security Steering Committee, an ISMS aligned to recognised standards, and annual internal and external audits, with the Protected System itself reassessed at least every two years.

"Made in India" is becoming "Owned by India"
The draft Defence Acquisition Procedure 2026, released by the Ministry of Defence to replace DAP 2020, shifts the policy emphasis from domestic manufacture to Indian ownership and control of design, source code, and core intellectual property — a materially different compliance target for technology vendors than simply meeting a manufacturing-content percentage.

The procurement side is moving in the same direction. Draft DAP 2026 proposes raising the indigenous content threshold under the Buy (Indian-IDDM) category from 50% to at least 60%, and — for the first time — would require 30% indigenous content even in the Buy (Global) category, which previously carried no such requirement at all. With a FY 2026-27 capital procurement budget of roughly ₹2.19 lakh crore and about 75% of that earmarked for domestic industry, the practical stakes of getting indigenous-content classification right have grown substantially. One caution worth flagging plainly: DAP 2026 remains in draft, and its treatment of offset obligations has drawn scrutiny for inconsistent references across its own published volumes — a vendor structuring a bid today should confirm current offset treatment rather than assume DAP 2020's terms still apply unmodified.

Government technology procurement advisory at SIRI Law LLP

Confidentiality from the first call

Every engagement in this practice runs under attorney-client privilege from the initial consultation.

Where government and defence vendors get exposed

Four ways this work carries sharper stakes than commercial contracting

Government and defence engagements don't just carry higher financial exposure — they carry criminal, reputational, and eligibility risks that a standard commercial contracts review doesn't screen for.

01 — SCOPE

CII designation can apply without warning

A system doesn't need to look like "critical infrastructure" to be designated a Protected System — functional criticality is the test, and vendors are sometimes designated after the fact, with governance obligations that then apply retroactively to how the system was already being run.

02 — LIABILITY

Strict liability, not negligence-based exposure

Section 70(3)'s criminal penalty for unauthorised access to a Protected System is a strict-liability provision. Contractor liability clauses drafted for commercial breach scenarios don't map cleanly onto this exposure, and often leave individual officers under-protected.

03 — CLASSIFICATION

Indigenous content classification errors are costly

Misclassifying a bid's indigenous content percentage under DAP categories can disqualify a bid outright or trigger post-award compliance disputes — errors that are avoidable with the right legal structuring before submission, not after.

04 — SUPPLY CHAIN

Vendor and subcontractor obligations extend downstream

Supply chain vendors and service providers connected to CII operators can themselves fall inside compliance scope by dependency — shared infrastructure like Active Directory or jump hosts is a common point examiners flag as in-scope but unaddressed.

What we cover

Defence & government legal services at the intersection of security and compliance

Legal advisory for organisations operating at the intersection of national security, technology procurement, and regulatory compliance under India's NCIIPC and defence acquisition frameworks.

01 / CII

NCIIPC Compliance

Legal advisory on NCIIPC critical information infrastructure protection obligations, compliance audit frameworks, incident reporting requirements, and nodal agency liaison.

  • Protected System designation risk assessment
  • 2018 Rules governance structure (CISO, ISSC, ISMS)
  • Annual audit and biennial reassessment support
  • NCIIPC advisory closure documentation
02 / PROCUREMENT

Classified System Procurement

Legal due diligence for technology procurement in classified environments — supplier security vetting, NDAs with national security provisions, and contract risk allocation.

  • Supplier security vetting support
  • National-security-grade NDA drafting
  • Contract risk allocation structuring
  • Procurement due diligence
03 / CLEARANCE

Security Clearance Pathways

Legal guidance for companies seeking government security clearances — documentation, eligibility assessment, MHA and MoD liaison, and clearance maintenance compliance.

  • Eligibility assessment and documentation
  • MHA and MoD liaison support
  • Clearance maintenance compliance
  • Ongoing eligibility monitoring
04 / LIABILITY

Contractor Liability Frameworks

Liability structuring for government and defence contractors — indemnification caps, data breach responsibility allocation, IP ownership, and sovereign immunity analysis.

  • Indemnification cap structuring
  • Data breach responsibility allocation
  • IP ownership and design authority terms
  • Sovereign immunity analysis
05 / PROCUREMENT POLICY

Defence Procurement Regulations

Advisory on the Defence Acquisition Procedure (including draft DAP 2026), Make in India defence provisions, offset obligations, Technology Transfer agreements, and DPSU regulatory compliance.

  • DAP 2026 category and indigenous content advisory
  • Offset obligation structuring above ₹2,000 Cr
  • Technology Transfer agreement drafting
  • DPSU regulatory compliance
06 / AI IN DEFENCE

AI in Defence Legal Advisory

Legal framework for AI deployment in defence and government — autonomous system liability, algorithmic decision accountability, and AI ethics compliance under the NCIIPC framework.

  • Autonomous system liability structuring
  • Algorithmic decision accountability
  • NCIIPC-aligned AI supply-chain due diligence
  • AI ethics compliance documentation

Evidence, not guesswork

DAP 2020 vs. draft DAP 2026 — what's actually changing for vendors

DAP 2026 remains a draft as of publication. Here's how its proposed terms compare to the current DAP 2020 framework vendors are still operating under today.

Provision DAP 2020 (current) Draft DAP 2026 (proposed)
Buy (Indian-IDDM) indigenous content 50% minimum At least 60%, phased across programme lifecycles
Buy (Global) indigenous content No requirement 30% required for the first time
Policy emphasis Domestic manufacture and assembly Ownership and control of design, source code, and IP
iDEX / Make procedures Peripheral to mainstream acquisition Formal acquisition paths with spiral development and assured orders
Offset policy treatment Applies above ₹2,000 crore contract value Referenced inconsistently across draft volumes — confirm before relying on it
Status In force Draft, released for stakeholder feedback

Sources: Ministry of Defence draft DAP 2026 publication (February 2026); Press Information Bureau release on DAP 2026; industry analysis of indigenous content and offset provisions. DAP 2026 remains subject to revision before final notification — verify current status before relying on any specific provision for an active bid.

What this scale actually looks like

Four numbers that frame the stakes in defence and CII work

10 yrs
Maximum imprisonment

Under Section 70(3) of the IT Act for unauthorised access to a Protected System — a criminal, strict-liability exposure distinct from civil penalty regimes.

₹2.19 L Cr
FY26-27 capital procurement budget

Roughly 75% earmarked for domestic industry — a substantial share of national defence spending now tied to indigenous content compliance.

Annual
CII audit cadence

Protected Systems require annual internal and external security audits, with the designation itself reassessed at least every two years.

2
Regulatory channels in one engagement

NCIIPC and CERT-In cohabit the incident response landscape — a single breach can trigger obligations to both simultaneously.

Why SIRI

Government work demands legal and security expertise together

No other firm in India combines attorney-client privilege with technical execution across cybersecurity and government-facing law — assessed inside the same engagement, under the same confidentiality standard.

SIRI Law LLP defence and government advisory team
01 — Procurement

Government procurement fluency

Our team has advised on GFR, CVC guidelines, and defence procurement regulations — we understand the regulatory environment government contractors operate within, including how draft DAP 2026 changes bid classification.

02 — Classified work

Security-conscious process capability

Our integrated legal-security model allows technical assessments alongside legal advisory in environments requiring confidentiality and structured information-handling protocols.

03 — Regulatory fluency

NCIIPC and CERT-In regulatory literacy

We track NCIIPC, CERT-In, and MeitY regulatory developments continuously and translate them into what they actually require of a specific Protected System or defence contractor — not generic policy summaries.

04 — Documentation

Policy development support

We draft cybersecurity policies, incident response procedures, and vendor management frameworks built to satisfy government audit requirements and the 2018 Protected System Rules' governance structure.

Who we work with

PSUs, contractors, and technology vendors across the government supply chain

From prime defence contractors to the mid-sized technology vendors supplying them — CII and defence procurement obligations reach further down the supply chain than most vendors expect.

PSUs & DPSUs Defence contractors Government technology vendors Critical infrastructure operators iDEX & defence startups Telecom & power sector Banking & financial CII AI & deep tech in defence

How we work

From confidential intake to a defensible compliance posture

01

Confidential intake

A privileged initial consultation to understand your system, contract type, and current CII or procurement exposure — before any scope is agreed.

Day 1
02

Exposure assessment

We map your specific obligations under NCIIPC, the 2018 Protected System Rules, and applicable DAP categories, ranked by regulatory and contractual priority.

Weeks 1–2
03

Structuring & advisory

Contract structuring, indigenous content classification support, clearance documentation, or governance policy drafting — executed with confidentiality as the default.

Engagement-specific
04

Standing counsel

Ongoing advisory as NCIIPC guidance, DAP provisions, and audit cycles evolve — so your compliance posture doesn't go stale between formal reviews.

Ongoing

Frequently asked

Defence & government cyber advisory, answered directly

What makes a system "Critical Information Infrastructure" under Indian law?

Under Section 70 of the IT Act 2000, the central government can designate any computer resource a Protected System if its incapacitation or destruction would have a debilitating impact on national security, the economy, public health, or public order. Designation is based on functional criticality, not the size or turnover of the entity operating it — a mid-sized vendor can be in scope if the system it runs qualifies.

What are the penalties for unauthorised access to a Protected System?

Under Section 70(3) of the IT Act, unauthorised access to a Protected System is a criminal offence punishable with imprisonment up to 10 years and a fine — a strict-liability provision, not a civil penalty schedule. This sits alongside the Information Technology (Information Security Practices and Procedures for Protected System) Rules 2018, which set out the operative governance, audit, and reporting requirements for designated entities.

What changes under DAP 2026 for defence technology vendors?

The Defence Acquisition Procedure 2026, released in draft by the Ministry of Defence to replace DAP 2020, raises the indigenous content requirement under the Buy (Indian-IDDM) category from 50% to at least 60%, and for the first time requires 30% indigenous content even in the Buy (Global) category, which previously had none. It also shifts emphasis from manufacture to ownership of design, source code, and core IP, and brings iDEX and Make procedures into the mainstream acquisition pipeline rather than treating them as peripheral innovation tracks.

At what contract value do offset obligations apply?

Under the existing offset policy, offsets are mandatory for contracts above ₹2,000 crore, requiring foreign vendors to invest a specified percentage of contract value in India through direct purchase, FDI, or technology transfer. DAP 2026's treatment of offsets has drawn scrutiny for inconsistent references across its published volumes, so vendors should confirm current offset treatment for a specific procurement category before relying on the older DAP 2020 framework.

Can a mid-sized technology vendor be subject to NCIIPC obligations?

Yes. Designation as a Protected System depends on the functional criticality of the specific system, not the size of the company operating it. Supply chain vendors and service providers connected to a designated CII operator can also fall inside compliance scope by dependency — shared infrastructure like Active Directory, jump hosts, or a shared logging platform is a common point examiners flag as in-scope but frequently unaddressed.

How does confidentiality work for a government or defence engagement?

Every engagement in this practice operates under attorney-client privilege from the initial consultation. For matters requiring structured information handling, our integrated legal-technical model allows assessments to proceed within the confidentiality protocols your contract or clearance status requires, without needing to bring in a separate, uncoordinated technical vendor.

Ready when you are

Working on government or defence technology?

SIRI provides confidential advisory services to PSUs, defence contractors, and government technology vendors. Contact us to discuss your requirements.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes and does not constitute legal advice. References to draft DAP 2026, NCIIPC guidance, and IT Act provisions reflect publicly available information as of publication; DAP 2026 remains in draft and subject to change before final notification, and specific procurement, classification, or clearance decisions should be verified against current official sources. No lawyer-client relationship is formed by viewing this page. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top