Industries
Telecom and ISPs — security testing, TEC MTCTE and regulatory compliance
Carriers, ISPs and equipment vendors face DoT security conditions, mandatory TEC testing for connected equipment and CERT-In obligations across network, OSS/BSS and subscriber data.
Applicable regulations
- TEC Mandatory Testing and Certification of Telecom Equipment (MTCTE)
- DoT licence security conditions and security-audit expectations
- CERT-In directions (incident reporting, logging, empanelled testing)
- DPDP Act 2023 for subscriber personal data; ISO 27001 for the ISMS
Common cybersecurity risks
- Attacks on OSS/BSS, signalling and core network infrastructure
- Subscriber-data exposure across provisioning and billing systems
- Insecure network equipment failing MTCTE security requirements
- DDoS and routing attacks disrupting connectivity
- Supply-chain and vendor remote-access compromise
Audit findings we typically see
- Flat network segments between corporate IT, OSS/BSS and core
- Weak access controls on provisioning and billing platforms
- Equipment shipped without evidence of MTCTE security testing
- Incomplete logging and SOC coverage for network events
- No CERT-In-aligned incident-response and reporting process
Services required
- VAPT across network, OSS/BSS and applications
- Network vulnerability assessment
- ISO 27001 ISMS
- Security architecture review
- DPDP compliance for subscriber data
Our engagement approach
- Discovery. Map network, OSS/BSS and subscriber data flows; confirm DoT, TEC/MTCTE, CERT-In and DPDP obligations.
- Assessment. VAPT and configuration review across network and application layers, with equipment security mapped to MTCTE expectations.
- Remediation. A prioritised roadmap covering segmentation, access hardening and logging, sized for carrier-grade uptime.
- Assurance. Retest, audit-grade reporting and regulator-ready evidence.
Expected evidence
- Network and data-flow inventory across OSS/BSS and core
- VAPT and configuration-review results
- Logging, monitoring and SOC coverage evidence
- Incident-response and CERT-In reporting procedure
Indicative timeline
A typical assessment runs 6 to 10 weeks, depending on network scope and systems in scope.
Deliverables
- Gap assessment across DoT, CERT-In and ISO 27001 expectations
- VAPT reports with closure evidence
- Segmentation and access-hardening recommendations
- Remediation roadmap
Related case study
Free tool
Try it free →Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
