National Critical Information Infrastructure Protection Centre
The National Critical Information Infrastructure Protection Centre (NCIIPC) is India’s national nodal agency for safeguarding Critical Information Infrastructure (CII). Created under Section 70A of the Information Technology Act, 2000, through a gazette notification on January 16, 2014, it operates as a specialized unit under the National Technical Research Organisation (NTRO) within the Prime Minister’s Office (PMO).
Statutory Framework and Legal Definitions
Critical Information Infrastructure (CII)
Section 70(1) of the Information Technology Act, 2000 defines Critical Information Infrastructure as any computer resource whose incapacitation or destruction would have a debilitating impact on:
-
National security
-
National economy
-
Public health
-
Public safety
Statutory Mandate under Section 70A
Section 70A of the IT Act empowers the central government to designate a national nodal agency for CII protection. It grants NCIIPC the authority to:
-
Issue policy guidance and standard operating procedures for critical systems.
-
Call for information and issue binding directions to entities controlling identified CII assets.
-
Recommend penal actions under Section 70, where unauthorized access to a protected system carries imprisonment of up to 10 years and a fine.
Core Mandates and Functions
Strategic and Advisory Roles
-
Serves as the national nodal agency for coordinating all protective measures against cyber warfare, cyber terrorism, and espionage targeting critical digital assets.
-
Identifies and recommends vital digital assets across public and private domains to the government for formal notification as protected systems.
-
Issues real-time threat intelligence, early warnings, vulnerability advisories, and security guidelines.
-
Runs the Responsible Vulnerability Disclosure Program (RVDP) to facilitate coordinated reporting and patching of security flaws in critical networks.
Operational Distinction: NCIIPC vs. CERT-In
| Parameter | NCIIPC | CERT-In |
| Statutory Provision | Section 70A of the IT Act, 2000 | Section 70B of the IT Act, 2000 |
| Administrative Control | NTRO (Prime Minister’s Office) | Ministry of Electronics and IT (MeitY) |
| Operational Scope | Focused exclusively on designated Critical Information Infrastructure (CII) | Covers the entire Indian cyberspace and general digital infrastructure |
| Core Function | Preventive security, risk mitigation, and continuous threat monitoring for critical assets | Emergency incident response, cyber triage, handling, and reporting across all sectors |
Identified Critical Sectors
NCIIPC classifies India’s critical digital infrastructure into distinct priority verticals:
-
Power and Energy: Electricity grids, nuclear plants, oil and gas pipelines, refinery control systems (SCADA/ICS).
-
Banking, Financial Services, and Insurance (BFSI): Payment gateways, core banking platforms, clearing houses, stock exchanges.
-
Telecommunications: Core routing infrastructure, submarine cable landing stations, satellite communication networks.
-
Transport: Air traffic management, railways signalling, vessel traffic systems, automated port operations.
-
Strategic and Public Enterprises: Defence production networks, space research data centres, key administrative databases.
-
Government: Critical identity repositories, tax collection platforms, national e-governance backbones.
Key Facts for Quick Reference
-
Establishment Date: January 16, 2014.
-
Headquarters: New Delhi.
-
Parent Organization: National Technical Research Organisation (NTRO), under the Prime Minister’s Office (PMO).
-
Governing Legislation: Section 70A of the Information Technology Act, 2000 (amended in 2008).
-
Primary Responsibility Principle: The primary operational responsibility for securing individual CII systems remains with the specific organization or agency operating that asset, while NCIIPC provides national-level oversight, standards, and intelligence.
-
Incident Reporting Desk: Operates a dedicated 24×7 help desk and reporting portal for CII security incidents.