Blog

SASE compliance in India: Telecom, CERT-In, and DPDP guide for security teams

Author(s): 
Hai Chi Nguyen
 (Legal & Compliance Manager)
, 
 ()
Compliance
Back to previous
Business guest using a smartphone beside a laptop, with a blue connection illustrating guest Wi-Fi authentication.
October 9, 2026
  |  
Last updated: 
October 9, 2026
  |  
  5 min

Secure Access Service Edge (SASE) compliance in India rests on three regulatory frameworks: telecommunications rules on user authentication, the Indian Computer Emergency Response Team (CERT-In) Directions of 2022, and the Digital Personal Data Protection (DPDP) Act, 2023. Any provider that manages network access or handles personal data needs a clear answer to each. For organizations adopting SASE in India, those answers belong in the selection process from day one.

The topic came up often at Zenith Live in Mumbai, where Cloudi-Fi took part as a Gold sponsor. As Cloudi-Fi expands its presence in India, this article explains how the platform addresses each requirement and what organizations should look for when evaluating a SASE provider.

‍

Where Cloudi-Fi fits in SASE

Guests, contractors, and unmanaged devices pass through the Cloudi-Fi identity layer, which sends identity to the SASE stack and ties each session to a verified user in connection records
Cloudi-Fi identifies users and devices as they join the network, passes that identity to the SASE stack, and keeps connection records that support both visibility and compliance.

‍

SASE is a cloud-delivered architecture that combines software-defined wide area networking (SD-WAN) with security service edge (SSE) technologies. These include secure web gateway (SWG), cloud access security broker (CASB), Zero Trust network access (ZTNA), and firewall-as-a-service (FWaaS), all delivered from a single platform.

Most SASE deployments assume that users and devices are already known when they connect. Guests, contractors, and unmanaged devices create a blind spot, because their connections arrive without a verified identity. Cloudi-Fi closes that gap at the point of connection, identifying users and devices as they join the network and passing that identity to the SASE stack.

In India, that identity layer is also a compliance asset. The records that give security teams visibility are the same records regulators expect organizations to keep.

‍

Telecommunications rules and Wi-Fi authentication

India's telecom framework, now anchored by the Telecommunications Act, 2023, has long required that public Wi-Fi users be authenticated before they get access. Authentication is typically done through a one-time password (OTP) sent to a mobile number, and usage records must be retained.

These obligations generally fall on the organization operating the network, such as a venue, campus, or enterprise offering guest access. Cloudi-Fi's role is to give that operator the tools to meet them. The Cloudi-Fi Captive Portal supports OTP-based authentication, and every session is tied to a verified user in the connection records.

‍

CERT-In Directions of 2022

Issued under the Information Technology Act, 2000, the CERT-In Directions set two core obligations for service providers: reporting cyber incidents and maintaining logs.

CERT-In obligations: report cyber incidents within six hours and keep ICT system logs on a rolling 180-day basis, with Cloudi-Fi’s incident and log retention policies
The CERT-In Directions require incident reporting within six hours and rolling 180-day log retention. Cloudi-Fi’s business continuity, backup, and log retention policies address both.

Reporting cyber incidents

Service providers must report specified cyber incidents to CERT-In within six hours of noticing them or being notified. On request, they must also take protective or preventive action, share information, and assist CERT-In in its response.

Cloudi-Fi builds incident readiness into daily operations. Its internal policy to ensure business continuity defines preventive and protective measures that keep the service running and limit the impact on clients. Together with the policy for backing up data, its internal procedures set out a clear process for reporting incidents promptly and protecting clients, their networks, and the wider public.

Maintaining logs

Service providers must enable logs for all information and communications technology (ICT) systems, retain them securely on a rolling 180-day basis, and provide them to CERT-In when reporting an incident or on request. The Directions state that logs should be kept within Indian jurisdiction. CERT-In's FAQs clarify that logs may be stored outside India, provided they can be produced within a reasonable time.

Cloudi-Fi's log retention policy requires logs to be kept securely for at least six months, or longer where local regulations require, depending on local regulatory requirements. This meets the CERT-In requirement of a rolling 180-day retention period and ensures that logs remain readily available to be provided to CERT-In in a timely manner whenever required.

‍

DPDP Act, 2023 and DPDP Rules, 2025

Together, the DPDP Act and its Rules establish India's framework for protecting digital personal data. Its pillars are lawful processing, based on consent or specific legitimate uses defined by law; rights for individuals, including access, correction, and erasure; and obligations for organizations, including security safeguards, breach notification, and limits on retention.

How the DPDP Act compares to GDPR

Organizations familiar with the EU's General Data Protection Regulation (GDPR) will recognize much of the DPDP Act. Both laws apply beyond national borders, distinguish between organizations that control data and those that process it on their behalf, require clear and informed consent, and grant individuals core rights. According to international law firm Latham & Watkins, the DPDP Act follows principles broadly similar to those of the GDPR.

The differences still matter. The DPDP Act requires breach notification requires breach notification to every affected individual, not only when risk is high. It treats anyone under 18 as a child, which requires verifiable parental consent, and it introduces consent managers, registered entities that help individuals manage consent across services.

Cloudi-Fi's approach to the DPDP Act

Cloudi-Fi built its privacy program to GDPR requirements from the start, one of the most demanding data protection standards worldwide. Its practices around consent, data minimization, security, retention, and individuals' rights already reflect the core principles of India's framework.

For guest and user data, Cloudi-Fi typically acts as a processor on behalf of its clients, who are the Data Fiduciaries under the DPDP Act. Infrastructure providers, including its hosting provider, are managed as sub-processors under the same framework. Cloudi-Fi is mapping its processes to the Act's India-specific requirements ahead of full enforcement in May 2027, so clients can rely on it to support their own obligations.

DPDP Act roles: the individual’s data flows to the client as Data Fiduciary, Cloudi-Fi as processor, and the hosting provider as sub-processor, above the Act’s three pillars
Under the DPDP Act, clients are the Data Fiduciaries, and Cloudi-Fi typically processes guest and user data on their behalf, with hosting providers managed as sub-processors.

‍

What to look for in a SASE provider in India

Compliance should be part of provider selection from the start. Before signing, organizations should check whether a provider:

  • Understands and follows Indian cybersecurity requirements, including the CERT-In Directions
  • Supports user authentication and record-keeping for network access
  • Protects personal data in line with the DPDP Act and international privacy laws
  • Is transparent about its security, hosting, and data handling practices
  • Can support clients in meeting their own compliance obligations

Ready for India with Cloudi-Fi

Cloudi-Fi brings identity-based access at the point of connection, established incident response and business continuity processes, a structured log retention policy, and a privacy program built to international standards. Together, these help organizations adopt SASE in India with confidence as the regulatory landscape evolves.

Request a demo to see how Cloudi-Fi completes your SASE deployment.

Cloudi-Fi white logo

Start your Journey with Cloudi-Fi

Cloudi-Fi white logo
Cloudi-Fi white logo

Start your Journey with Cloudi-Fi