There was immediate response in the market following the STQC certification mandate for CCTV cameras by the Ministry of Electronics and Information Technology, India. By the deadline, April 9, 2025, under the IoT System Certification Scheme, only four manufacturers were allowed to legally sell IP-based cameras in the country (Security Update, 2025). As a result, the compliance of CCTV mandates in India has become crucial for the surveillance equipment industry in terms of product design, import and distribution.
What Are the CCTV Compliance Requirements in India?
CCTV compliance norms in India outline the required procedures and processes that surveillance equipment has to mandatorily undergo in its design, development, manufacture and/or import to the country.
Why CCTV compliance has become important
For a long time, video surveillance equipment was treated as simple electronic equipment from a regulatory point of view, if at all. Consequently, such equipment was imported, installed, and used without any consideration for the security and integrity of the systems. Video streams were transmitted in plain text. Firmware and default administrative passwords remained unchanged. Government employees lacked the ability to control and monitor communications. Such equipment is used to monitor and record activities in and around critical and sensitive installations.
What do the new CCTV requirements cover?
The gazette notification dated 9th April 2024 mandates Security Testing and Quoting (STQC) certification for all closed-circuit television (CCTV) cameras manufactured or imported in India. The notification outlines three main requirements. First, cameras must have protective measures for cybersecurity. Second, they must be safe with regard to electrical and mechanical risks, and pose no injury to the user or bystander. Finally, the manufacturer must be able to traceability of the camera.
An assessment of the cybersecurity of a camera does not ensure that the camera is safe to use. There are other considerations, for instance, physical safety and EMI/EMC of the camera. As such, a CCTV camera has to undergo assessment by both the Bureau of Indian Standards (BIS) and the Security and Accreditation Framework Division (SAFD) to establish its compliance with the safety and security requirements, respectively.
What Is CCTV Certification in India?
CCTV certification in India is the formal process by which a camera model is tested and approved against government-notified security and safety benchmarks before it can enter the market.
For manufacturers, STQC-ready camera solutions provide a practical way to address hardware security, firmware controls, documentation, and testing requirements before formal evaluation.
Role of STQC in CCTV certification
The Standardization Testing and Quality Certification (STQC) Directorate, which operates under MeitY, conducts the evaluation. STQC performs a substantial amount of work. STQC's labs validate the encryption and authentication claims made by manufacturers. STQC evaluates and verifies mechanisms used by manufacturers to perform firmware updates over a network. STQC performs a physical evaluation of the device.
One of the major concerns is that compliance documents provide no information about the behavior of a device once it is connected to a live network. STQC evaluates and verifies the hardware and firmware of the device and thereby bridges this gap.
Essential requirements for CCTV cameras
The first essential requirement (ER-01) specifies secure camera design in greater detail. Features of a secure camera include unique, user-assignable, or administrator-assignable, login defaults; encryption of stored media; secure, authenticated, and encrypted, network communications; and secure boot.
STQC-ER certification promotes and requires similar security features (e.g. secure boot, and authenticated network communication and storage) that are documented by security standards and frameworks, including but not limited to, the ISO/IEC 27000 series and the OWASP Top 10. Similar features are included in E.R.s 2 through 6. Each requirement is associated with real-world attacks against cameras that are generally deployed without security features.
What Is an STQC Camera?
An STQC camera is a CCTV unit that has passed the Essential Requirements testing and received formal approval from the STQC Directorate for sale in India.
What does STQC certification mean?
Being certified means a hardware and firmware combination has been tested and cleared. If the combination changes (e.g. different chipset, firmware, storage encryption), that will require a new review and clearance.
Due to this, two cameras made by the same company can have different compliance statuses. For example, a camera made last year by Company A can have a different status than a camera made this year by Company A depending on the components used in each.
Which CCTV cameras need STQC certification?
The requirement applies broadly. Network cameras, DVRs, and NVRs sold for government projects, commercial installations, and general retail all fall under the scope of the Compulsory Registration Order.
From June 6, 2024, under an amendment to the Public Procurement Order, security cameras bought by the government must be Made-in-India CCTV cameras that conform to Electronic Rating (ER) standards that are certified by the Standard Testing and Quality Council of India (STQC). It has been reported that this amendment would apply to the private sector as well. Hence, a security camera bought for a government building, a shopping mall, or a society would be subject to the same certification.
These requirements are especially important for IP cameras and surveillance systems used in government, commercial, industrial, and public-facing environments, where security, traceability, and long-term support are closely reviewed.
What Are the Key CCTV Compliance Requirements?
The core CCTV compliance requirements in India break down into three practical categories that manufacturers must address before submitting a product for testing.
Hardware and security requirements
Hardware needs to be able to support secure boot at the chipset level in order for the processor to be able to check the integrity of firmware. Storage components must support encryption of video in order for it to be recorded. Networking components must support authenticated connections. None of this can be retrofitted through a software patch alone. It has to be designed into the board and the component selection from the start.
Firmware and software requirements
On the software side, the camera needs a mechanism for signed firmware updates, so a device cannot be pushed malicious code disguised as a legitimate update. Default credentials are not allowed. Each unit must force a unique password on first setup. Remote access needs to be restricted and logged, and the system must include a way to trace which firmware version and hardware batch a given unit belongs to.
Testing and documentation requirements
Beyond the engineering work, manufacturers must submit test reports, a compliance declaration, and documentation describing how each Essential Requirement is met technically. CCTV cameras and recorders fall under IS 13252 Part 1 for safety compliance and must be registered under Scheme-II of BIS Regulations 2018, which runs in parallel with the STQC security review. Paperwork gaps are one of the most common reasons applications stall, often as much as the technical testing itself.
How Does the CCTV Certification Process Work?
The certification process moves through preparation, formal lab testing, and remediation if gaps are found, typically over a span of several weeks depending on lab capacity.
Preparing the camera for testing
Before submission, a manufacturer needs a stable firmware build, complete technical documentation, and internal test results showing the device already meets ER-01 on paper. Submitting a camera that has not been internally validated first almost always leads to failed test cycles and repeated resubmissions, which extends the timeline and cost.
STQC testing and evaluation
Testing labs authorized by STQC carry out additional evaluation tests on the notified Essential Requirements. This includes assessment of implemented encryption, presence of default/hardcoded credentials, secure boot and update chain of trust, and mechanisms to prevent bypass of firmware updates. As the testing of CCTV products by STQC takes a considerable amount of time, usually in weeks, and labs have a limitation on the number of tests they can undertake, Manufacturers wanting to meet a time bound CCTV product compliance should estimate the testing window appropriately.
Resolving compliance issues
When a check is failed for a given device, the reason for failure is captured. Sometimes the reason may require changes at the firmware level by the equipment manufacturer. If the reason is for example, the device does not implement adequate data encryption, the equipment manufacturer should provide an enhanced version of the device that implements data encryption, and request the same test be performed. If the equipment does not meet the test requirements, the product may be removed from the STQC evaluation or lead to the equipment license being revoked.
How Can OEMs Build a Compliant CCTV Camera?
OEMs that treat compliance as a late-stage checklist item consistently face longer timelines and costlier redesigns than those who build toward ER-01 from the first hardware revision.
Designing for compliance from the start
Secure boot and encrypted storage are chipset and board-level decisions. Choosing a processor without hardware root-of-trust support, for example, can make later ER-01 compliance nearly impossible without a full redesign. The practical path is to select components and reference designs that already support the required security primitives before the first prototype is built.
Developing STQC-ready hardware and firmware
Firmware teams need to build authenticated update mechanisms and credential management in from version one, not add them after a product has already shipped to early customers. Documentation should be written alongside development, so the technical justification for each Essential Requirement is ready when the device goes to testing rather than reconstructed after the fact.
Maintaining compliance through product updates
Compliance is an ongoing process. Continuous changes in hardware or firmware require repeat evaluations. Original Equipment Manufacturers (OEMs) must define a procedure to track the certified configurations of their products and ensure that changes do not break compliance. For example, changes may break a product’s secure boot feature or encrypted storage. It is more cost-effective to proactively control version changes to maintain compliance rather than lose compliance and bear the cost of re-certifying an entire product line.
Manufacturers preparing for formal evaluation can also review how to prepare IP cameras for STQC testing before freezing the hardware, firmware, and documentation package.
Conclusion
Meeting CCTV compliance requirements in India now shapes product roadmaps, not just paperwork. Silicon Signals is a camera design company specializing in camera development, helping OEMs build STQC-ready hardware and firmware from the ground up. Talk to Silicon Signals to plan your next compliant camera design.
Top comments (0)