Live Founding Cohort open, limited seats remaining Back to main site →

Five enforcement archetypes and the quarterly compliance calendar

Five real-world enforcement events between June 2024 and August 2026 tell you what DoT actually prioritises. Fifty million disconnections, PoS blacklist, SIM binding directive, Sanchar Saathi withdrawal, satcom trial spectrum. This lesson walks each and hands you a working quarterly compliance calendar for a mid-size ISP.

Free preview 11 min read Verified
Legal basis
Telecommunications Act 2023 primary-source stack current to 6 September 2026. Core: Telecommunications Act 2023 (Act No. 44 of 2023 assented 24 December 2023, published Gazette of India Extraordinary Part II Section 1 same day; sections 1-2, 10-30, 42-44, 46-47, 50-58, 61-62 notified 21 June 2024 effective 26 June 2024; sections 6-8, 48, 59(b) notified 4 July 2024 effective 5 July 2024; sections 3(1) and 3(6) notified 23 June 2026 effective 24 June 2026; sections 4, 5, 9, 31-41, 45, 49, 59(a), 60 unnotified as of 6 September 2026). Rule sets under the Act: (1) Digital Bharat Nidhi Rules 2024 G.S.R. 530(E) dated 20 August 2024 (replaces Universal Service Obligation Fund with 5 percent of AGR Universal Service Levy); (2) Right of Way Rules 2024 dated 17 September 2024 in force 1 January 2025 (single-window online portal sugam.gov.in); (3) Telecom Cyber Security Rules 2024 G.S.R. 720(E) dated 21 November 2024 (6-hour incident reporting plus 24-hour detailed report, Chief Telecommunication Security Officer appointment, IMEI registration); (4) Critical Telecommunication Infrastructure Rules 2024 dated 22 November 2024 (Central Government designation, network architecture disclosure, government inspection access to hardware / software / data); (5) Temporary Suspension of Services Rules 2024 dated 22 November 2024 (Section 20(2)(b) operationalisation, Review Committee 5-day review); (6) Lawful Interception Rules 2024 dated 6 December 2024 (supersedes Rules 419 and 419A of the Indian Telegraph Rules 1951, Nodal Officer regime, Central Review Committee under Cabinet Secretary); (7) Adjudication and Appeal Rules 2025 (draft 18 July 2024, final 2025) with Adjudicating Officer of Joint Secretary or above, complaint fee Rs 5,000, appeal fee Rs 10,000, 30-day appeal filing and 60-day resolution; (8) Telecom Cyber Security Amendment Rules 2025 G.S.R. 771(E) dated 22 October 2025 republished vide G.S.R. 796(E) dated 29 October 2025 (Telecommunication Identifier User Entity category, Mobile Number Validation platform); (9) DoT SIM binding directive dated 28 November 2025 to WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat and Josh with 90-day implementation and 120-day compliance reporting, SIM binding effective February 2026; (10) Principal Telecom Services Rules 2026 G.S.R. 513(E) dated 24 June 2026 (five authorisation categories: Unified Service, Access Service, Wireline Access Service, Internet Service, Long Distance Service; 20-year authorisation validity; Network Service Operator or Virtual Network Operator paths); (11) Migration Rules 2026 (portal opens 25 June 2026); (12) Network Authorisation Rules 2026 dated 20 July 2026 (six network authorisations: Infrastructure Provider IP, Digital Connectivity Infrastructure Provider DCIP, Internet Exchange Point IXP, Satellite Earth Station Gateway SESG, Cloud-hosted Telecommunication Network CTN, Mobile Number Portability MNP; Rule 25(3) data localisation; only MNP has annual fee); (13) User Identification Rules 2026 dated 21 August 2026 (live biometric mandatory for SIM issuance / replacement / change / surrender, Biometric Identity Verification System, Aadhaar e-KYC and non-Aadhaar D-KYC parallel paths). Parallel TRAI regulations: Telecom Commercial Communications Customer Preference (Second Amendment) Regulations 2025 dated 12 February 2025 (header authentication, annual self-certification for senders and telemarketers, complaint mechanism effective 13 April 2025); TRAI Recommendations on Satcom Spectrum dated 9 May 2025 (4 percent of AGR, minimum Rs 3,500 per MHz, urban NGSO additional Rs 500 per subscriber per annum, 5-year review; DCC sought back-reference September 2025). Enforcement corpus: DoT anti-fraud drive (50 million fake mobile connections disconnected in the 2 years to July 2026; 40 lakh SIMs blacklisted, 68 lakh flagged for re-verification, 52,000 Point-of-Sale agents blacklisted in August 2025); November 2025 Sanchar Saathi pre-install directive and its withdrawal; MediaNama RTIs filed March 2026 on SIM binding enforcement transparency. Satcom authorisations: Eutelsat OneWeb (GMPCS August 2021, IN-SPACe November 2023), Jio-SES (GMPCS March 2022, IN-SPACe June 2024), Starlink Services India (Letter of Intent May 2025, GMPCS June 2025, IN-SPACe July 2025, trial spectrum September 2025); no commercial launch as of June 2026. Cross-regulator: Information Technology Act 2000 Section 70A (National Critical Information Infrastructure Protection Centre) for CTI overlap, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for dual 6-hour incident reporting, Digital Personal Data Protection Act 2023 Section 8 (reasonable security safeguards) for BIVS overlap, Aadhaar Act 2016 and UIDAI regulations for e-KYC integration. Case law: Anuradha Bhasin v Union of India (Writ Petition Civil No. 1031 of 2019, judgment 10 January 2020, three-judge bench of N.V. Ramana, R. Subhash Reddy and B.R. Gavai JJ) on Section 20 suspension doctrine; Faheema Shirin R.K. v State of Kerala (WP(C) No 19716 of 2019, Kerala High Court 19 September 2019, P.V. Asha J) on right to internet access as part of Article 21. Draft rules requiring watch: Telecommunications (Television, Radio and Associated Services) Rules 2026 (MIB draft 12 June 2026, consultation open until 2 October 2026); Telecommunications (Authorisation for Captive Telecommunication Services) Rules (draft under consideration as of 6 September 2026). Items requiring ongoing verification and flagged inside the affected lessons: exact G.S.R. numbers for the 2026 Rule sets, current status of DCC clarification on TRAI satcom pricing, Starlink commercial launch status, any commercial launch by Jio-SES or OneWeb, finalisation of the Broadcasting Rules 2026 post-consultation, notification of the Captive Services Rules, and any further amendments to the TCS Rules 2024 or the TCS Amendment Rules 2025.

Two questions matter more than the text of any Rule. First: what does the DoT actually enforce, and how aggressively? Second: what does the compliance calendar look like month by month? This lesson answers both by walking five enforcement archetypes from the 2024 to 2026 window and closing with a quarterly compliance calendar for a mid-size ISP that keeps you inside the boxes.

Archetype 1: the anti-fraud disconnection drive

The most visible DoT enforcement pattern under the 2023 Act has been the anti-fraud disconnection drive. Over the two years to July 2026 the Department disconnected more than 50 million fake mobile connections [L5-C1]. In a single month (August 2025) the Department blacklisted 40 lakh SIMs, flagged 68 lakh mobile numbers for re-verification, and blacklisted 52,000 Point-of-Sale agents for facilitating fake registrations.

Statutory basis: Section 42(3)(e) of the Telecom Act 2023 (acquiring SIM through deceitful means) read with Section 42(7) (cognizable, non-bailable). Penalty: up to 3 years imprisonment and up to Rs 50 lakh fine and both. Enforcement mechanism: DoT works with telecom operators to disconnect on evidence of fake KYC, works with state police to file FIRs against PoS agents, and works with the Sanchar Saathi ecosystem to source consumer complaints.

Implication for operators: PoS agent verification is now a compliance-critical function. If your operator uses third-party PoS agents to acquire subscribers, the KYC quality of those agents is your Section 42(3)(e) exposure. The August 2025 Vi announcement that it completed PoS agent registration by 31 January 2025 (per DoT deadline) illustrates the operator-side response.

Archetype 2: the Sanchar Saathi pre-install directive and its withdrawal

In November 2025 the Central Government issued a directive requiring the Sanchar Saathi app to be pre-installed on all mobile devices sold in India by original equipment manufacturers. Consumer groups, device manufacturers, and civil-society bodies raised concerns about device tracking, privacy over-reach, and the absence of a clear statutory basis under the Telecom Act. The government issued a press release stating that pre-installation is not mandatory, effectively withdrawing the directive [L5-C2].

The archetype teaches two things. First: even under the 2023 Act, DoT actions must have a defensible statutory basis. The pre-install directive did not cleanly cite a section of the Act as its source of authority. Second: consultative rollback is possible. Where the industry and civil society push back with a coherent legal argument, the Department has shown willingness to withdraw or modify. This is relevant to Module 7 (where you learn to build a BIVS that satisfies the User Identification Rules 2026 without over-reaching into what could invite similar backlash).

Archetype 3: the SIM binding directive to OTT communication apps

On 28 November 2025 the Department issued a formal directive under the TCS Amendment Rules 2025 to WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat and Josh [L5-C3]. The directive mandates SIM binding (the app must periodically verify that the SIM used at registration remains present and active in the device) and a 6-hour mandatory auto-logout for web and desktop versions. Platforms had 90 days for technical implementation and 120 days to submit compliance reports. SIM binding took effect in February 2026.

MediaNama filed Right to Information applications in March 2026 to check which platforms missed the February deadline and what enforcement action followed. The transparency signal is that the Department is actively tracking compliance and that non-compliance leads to visible follow-up. For operators of any OTT communication service in India, the message is unambiguous: implement the technical binding, file the compliance report, keep the audit trail.

Archetype 4: satcom trial spectrum without commercial launch

The satcom regulatory chain (GMPCS licence from DoT, IN-SPACe operational clearance, then trial spectrum, then commercial spectrum) has been slow to deliver a live commercial service. Eutelsat OneWeb received its GMPCS licence in August 2021 and IN-SPACe clearance in November 2023, but had not launched commercially as of June 2026. Jio-SES received its GMPCS licence in March 2022 and IN-SPACe clearance in June 2024; also no commercial launch. Starlink Services India received its Letter of Intent in May 2025, GMPCS licence in June 2025, IN-SPACe clearance in July 2025, and trial spectrum in September 2025 [L5-C4]. VERIFY: whether any of the three has launched commercially by the ship date of this course.

The archetype teaches that regulatory approval is necessary but not sufficient. Satcom operators face additional friction in the trial-to-commercial transition: spectrum pricing not yet finalised after the DCC back-reference to TRAI in September 2025, in-country gateway infrastructure still under construction, distribution and retail readiness. If you advise a satcom applicant, budget 12 to 18 months from trial spectrum to commercial launch, not the 3 to 6 months some optimistic press coverage suggests.

Archetype 5: adjudication under Section 48 with Section 33 mitigation

The Adjudication and Appeal Rules 2025 operationalise Section 48 of the Act. Publicly reported adjudication orders under these Rules are sparse as of 6 September 2026 (the framework is new and the Adjudicating Officer bandwidth is still building), but the mechanism is in force and enforceable. The Second Schedule graded penalty scale runs from written warning through slabs to Rs 5 crore. The Adjudicating Officer chooses the slab having regard to nature, gravity, duration and frequency of the contravention, disproportionate gain, loss caused to affected users, and whether any voluntary undertaking under Section 33 was submitted [L5-C5].

The Section 33 voluntary undertaking mechanism is the most practically important feature of the adjudication framework. An operator that discovers a breach can submit a voluntary undertaking before any show-cause notice, disclosing the contravention and outlining mitigation. Acceptance bars further proceedings. During a hearing, an operator can submit a voluntary undertaking that the AO must consider as a mitigating factor in setting the penalty slab. Module 8 walks the Section 33 template.

The quarterly compliance calendar for a mid-size ISP

What does the year actually look like? Below is a working calendar for an ISP holding an Internet Service Authorisation plus an Infrastructure Provider authorisation, with 50,000 to 500,000 subscribers and 100 to 500 employees.

Q1 (January to March)

  • Financial-year opening review of TCS Rules 2024 incident log (year prior). Rebase 6-hour response SLA benchmarks.
  • Annual review of CTSO appointment and continuing eligibility (Indian citizen, resident).
  • File annual self-certification for registered senders under TCCCPR Second Amendment Regulations 2025 (mandatory for TMs and registered senders).
  • Right of Way filing renewals for infrastructure whose original RoW is expiring.
  • Digital Bharat Nidhi Universal Service Levy remittance for Q4 of prior FY.

Q2 (April to June)

  • Financial-year filings: AGR return to DoT, licence fee remittance, MNP annual fee (if applicable).
  • Digital Bharat Nidhi Universal Service Levy remittance for Q1 of current FY.
  • Quarterly cyber-security posture review (map to TCS Rules 2024 obligations).
  • Board or executive review of pending Rule 25(3) data-localisation architecture work.
  • Review of Section 20 suspension order log (year prior) if any were served.

Q3 (July to September)

  • Migration status check: if still on legacy UL, decide whether to migrate this quarter via the eServices portal.
  • Digital Bharat Nidhi Universal Service Levy remittance for Q2 of current FY.
  • Quarterly cyber-security posture review.
  • User Identification Rules 2026 audit: BIVS uptime, biometric-match rates, exclusion-mitigation cases, DPDP-consent audit trail.
  • Preparation for the annual DoT compliance filing due Q4.

Q4 (October to December)

  • Annual DoT compliance filing including cyber-security posture summary, incident log, CTSO continuing eligibility, BIVS metrics, adjudication history.
  • Digital Bharat Nidhi Universal Service Levy remittance for Q3 of current FY.
  • Year-end board review of Telecom Act compliance risk register (including any pending Section 33 voluntary undertakings).
  • Budget planning for the next FY including expected regulatory costs (portal fees, biometric-verification vendor contracts, cyber-audit engagements).

Add designation-triggered items if you are designated CTI (network architecture disclosure refresh, cyber crisis management plan refresh, security audit report submission, government inspection response readiness) and event-triggered items if you receive a Section 20 order (Nodal Officer log, 5-day Committee submission if applicable) or a show-cause notice (Section 33 voluntary undertaking evaluation, defence preparation).

End of Module 1

You now have the 2026 regime change in your head, the section notification map, the 13-rule cascade, the 11-box authorisation grid, and the working compliance calendar. Modules 2 through 8 walk each piece in operational detail.

If you have decided the course is right for you, the paid enrolment gate opens on the next screen. If you are still weighing it, note that Module 2 (the authorisation regime deep-dive) and Module 4 (the cyber security stack including the November 2025 SIM binding directive) are the two most immediately actionable modules for most learners. Module 6 (interception and suspension) and Module 8 (adjudication) are the modules learners come back to most often after enrolment as the operating year unfolds.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of Telecommunications Act 2023 + DoT Compliance Practitioner Certification?

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DoT Circular, DoT anti-fraud drive 50 mn disconnections (Enforcement archetype (2024-2026)) L5-C1
DoT reported disconnecting over 50 million fake mobile connections in the two-year anti-fraud drive to July 2026. Complementary actions in August 2025: 40 lakh SIMs blacklisted, 68 lakh mobile numbers flagged for re-verification, and 52,000 Point-of-Sale agents blacklisted for facilitating fake registrations. Underlying legal basis: Section 42(3)(e) (acquiring SIM through deceitful means, 3 years / Rs 50 lakh, cognizable + non-bailable) combined with Section 3(1) authorisation regime enforcement. Foundation case study for Module 1 lesson 5 (enforcement archetypes).
DoT Circular, Sanchar Saathi pre-install withdrawal Nov 2025 (Enforcement over-reach case study) L5-C2
In November 2025 the Central Government issued a directive requiring the Sanchar Saathi app to be pre-installed on all mobile devices sold in India by original equipment manufacturers. Widespread criticism from consumer groups, device manufacturers and civil society (concerns about device tracking, privacy over-reach, absence of a clear statutory basis under the Telecom Act). The government issued a press release clarifying that pre-installation is not mandatory, effectively withdrawing the directive. Case study in enforcement over-reach and subsequent correction; teaches the "reasoned, proportionate, published" doctrine even outside Section 20 suspensions.
DoT Circular, SIM binding directive 28 November 2025 (OTT communication apps SIM binding) L5-C3
On 28 November 2025 the Department of Telecommunications issued a formal directive under the TCS Amendment Rules 2025 mandating active SIM linkage for application-based communication platforms. Applies to WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat, and Josh. App must periodically check that the SIM used at registration is still present and active in the phone. Six-hour mandatory auto-logout for web and desktop versions of the messaging applications. Platforms had 90 days to implement the two technical requirements and 120 days to submit compliance reports. SIM binding effective from February 2026. MediaNama filed RTIs in March 2026 seeking DoT records on which platforms missed the deadline and what enforcement action followed.
IN-SPACe Authorisation, Starlink LOI May 2025 / GMPCS June 2025 (Starlink India authorisation timeline) L5-C4
Starlink Services India Private Limited received a Letter of Intent from DoT in May 2025, the GMPCS licence in June 2025, IN-SPACe operational clearance in July 2025, and trial spectrum allocation in September 2025. Third GMPCS licensee after OneWeb and Jio-SES. Commercial launch pending as of June 2026 in line with the industry pattern of long trial-to-commercial windows. Illustrates the multi-window regulatory chain that satcom applicants must traverse: DoT authorisation, IN-SPACe operational clearance, trial spectrum, commercial spectrum.
Telecom Act 2023, Second Schedule Civil penalties (graded) (Warning to Rs 5 Crore graded scale) L5-C5
The Second Schedule sets a graded scale of civil penalties for contraventions determined by the Adjudicating Officer under Section 48: written warning, penalty up to Rs 25,000, penalty up to Rs 2 lakh, penalty up to Rs 5 lakh, penalty up to Rs 10 lakh, penalty up to Rs 50 lakh, penalty up to Rs 1 crore, penalty up to Rs 5 crore. The AO chooses the slab having regard to nature, gravity, duration and frequency of the contravention, the disproportionate gain, the loss caused to affected users, and whether any voluntary undertaking under Section 33 was submitted.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Telecom Act operator's world
Module 2: The authorisation regime: Principal Telecom Services + Migration
  • From licence to authorisation: what Section 3(1) and 3(6) actually changed
  • Principal Telecom Services Rules 2026: the five service categories
  • NSO vs VNO: choosing between own-network and wholesale-buy
  • Migration Rules 2026: portal open, voluntary path, expiry math
  • The DoT eServices portal: screen-by-screen walkthrough
Module 3: Network authorisations + Right of Way Rules 2024
  • The six network authorisations under the 2026 Rules
  • Rule 25(3) data localisation: architectural implications for every network authorisation
  • MNP authorisation and the two-zone fee structure
  • RoW Rules 2024: single-window portal, deemed approvals, state variations
  • Spectrum: auction default, First Schedule administrative allocation, TRAI satcom pricing
Module 4: Telecom Cyber Security Rules 2024 + TCS Amendment 2025 + SIM binding
  • Telecom Cyber Security Rules 2024: anatomy of G.S.R. 720(E)
  • The 6-hour incident SLA and the CTSO role in operation
  • IMEI registration, CEIR integration, and telecom identifier security
  • TCS Amendment Rules 2025: TIUE and the Mobile Number Validation platform
  • The 28 November 2025 SIM binding directive to OTT communication apps
Module 5: Critical Telecommunication Infrastructure Rules 2024
  • CTI Rules 2024: scope and the designation process
  • Network architecture disclosure + vulnerability and threat and risk analysis
  • Government inspection access: hardware, software, data
  • The CTI + CERT-In + NCIIPC triangle: reconciling three regulators
  • The first 30 days after a CTI designation letter
Module 6: Lawful Interception + Temporary Suspension (Section 20)
  • Lawful Interception Rules 2024: what supersedes Rules 419 and 419A
  • The Central Review Committee: composition, cadence, power to set aside
  • Temporary Suspension of Services Rules 2024: internet shutdown procedure
  • Anuradha Bhasin v Union of India (2020) and the shutdown doctrine
  • The operator SOP when a Section 20 order lands
Module 7: User Identification 2026 + Sanchar Saathi + Anti-spam (TCCCPR)
  • User Identification Rules 2026: live biometric verification for every SIM event
  • BIVS implementation architecture and the exclusion-risk protocol
  • The Sanchar Saathi consumer-facing ecosystem
  • TCCCPR Second Amendment Regulations 2025: header authentication and annual self-cert
  • DLT platform mechanics and consent-based header operations
Module 8: Satcom + Digital Bharat Nidhi + adjudication + operator playbook
  • Satcom authorisation: Fifth Schedule administrative allocation and the OneWeb / Jio-SES / Starlink timelines
  • TRAI satcom pricing May 2025 and the DCC September 2025 back-reference
  • Digital Bharat Nidhi Rules 2024: replacing USOF with the 5 percent AGR levy
  • Adjudication and Appeal Rules 2025: defending a Section 48 proceeding
  • The operator playbook and handoff of all 12 templates