Two questions matter more than the text of any Rule. First: what does the DoT actually enforce, and how aggressively? Second: what does the compliance calendar look like month by month? This lesson answers both by walking five enforcement archetypes from the 2024 to 2026 window and closing with a quarterly compliance calendar for a mid-size ISP that keeps you inside the boxes.
Archetype 1: the anti-fraud disconnection drive
The most visible DoT enforcement pattern under the 2023 Act has been the anti-fraud disconnection drive. Over the two years to July 2026 the Department disconnected more than 50 million fake mobile connections [L5-C1]. In a single month (August 2025) the Department blacklisted 40 lakh SIMs, flagged 68 lakh mobile numbers for re-verification, and blacklisted 52,000 Point-of-Sale agents for facilitating fake registrations.
Statutory basis: Section 42(3)(e) of the Telecom Act 2023 (acquiring SIM through deceitful means) read with Section 42(7) (cognizable, non-bailable). Penalty: up to 3 years imprisonment and up to Rs 50 lakh fine and both. Enforcement mechanism: DoT works with telecom operators to disconnect on evidence of fake KYC, works with state police to file FIRs against PoS agents, and works with the Sanchar Saathi ecosystem to source consumer complaints.
Implication for operators: PoS agent verification is now a compliance-critical function. If your operator uses third-party PoS agents to acquire subscribers, the KYC quality of those agents is your Section 42(3)(e) exposure. The August 2025 Vi announcement that it completed PoS agent registration by 31 January 2025 (per DoT deadline) illustrates the operator-side response.
Archetype 2: the Sanchar Saathi pre-install directive and its withdrawal
In November 2025 the Central Government issued a directive requiring the Sanchar Saathi app to be pre-installed on all mobile devices sold in India by original equipment manufacturers. Consumer groups, device manufacturers, and civil-society bodies raised concerns about device tracking, privacy over-reach, and the absence of a clear statutory basis under the Telecom Act. The government issued a press release stating that pre-installation is not mandatory, effectively withdrawing the directive [L5-C2].
The archetype teaches two things. First: even under the 2023 Act, DoT actions must have a defensible statutory basis. The pre-install directive did not cleanly cite a section of the Act as its source of authority. Second: consultative rollback is possible. Where the industry and civil society push back with a coherent legal argument, the Department has shown willingness to withdraw or modify. This is relevant to Module 7 (where you learn to build a BIVS that satisfies the User Identification Rules 2026 without over-reaching into what could invite similar backlash).
Archetype 3: the SIM binding directive to OTT communication apps
On 28 November 2025 the Department issued a formal directive under the TCS Amendment Rules 2025 to WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat and Josh [L5-C3]. The directive mandates SIM binding (the app must periodically verify that the SIM used at registration remains present and active in the device) and a 6-hour mandatory auto-logout for web and desktop versions. Platforms had 90 days for technical implementation and 120 days to submit compliance reports. SIM binding took effect in February 2026.
MediaNama filed Right to Information applications in March 2026 to check which platforms missed the February deadline and what enforcement action followed. The transparency signal is that the Department is actively tracking compliance and that non-compliance leads to visible follow-up. For operators of any OTT communication service in India, the message is unambiguous: implement the technical binding, file the compliance report, keep the audit trail.
Archetype 4: satcom trial spectrum without commercial launch
The satcom regulatory chain (GMPCS licence from DoT, IN-SPACe operational clearance, then trial spectrum, then commercial spectrum) has been slow to deliver a live commercial service. Eutelsat OneWeb received its GMPCS licence in August 2021 and IN-SPACe clearance in November 2023, but had not launched commercially as of June 2026. Jio-SES received its GMPCS licence in March 2022 and IN-SPACe clearance in June 2024; also no commercial launch. Starlink Services India received its Letter of Intent in May 2025, GMPCS licence in June 2025, IN-SPACe clearance in July 2025, and trial spectrum in September 2025 [L5-C4]. VERIFY: whether any of the three has launched commercially by the ship date of this course.
The archetype teaches that regulatory approval is necessary but not sufficient. Satcom operators face additional friction in the trial-to-commercial transition: spectrum pricing not yet finalised after the DCC back-reference to TRAI in September 2025, in-country gateway infrastructure still under construction, distribution and retail readiness. If you advise a satcom applicant, budget 12 to 18 months from trial spectrum to commercial launch, not the 3 to 6 months some optimistic press coverage suggests.
Archetype 5: adjudication under Section 48 with Section 33 mitigation
The Adjudication and Appeal Rules 2025 operationalise Section 48 of the Act. Publicly reported adjudication orders under these Rules are sparse as of 6 September 2026 (the framework is new and the Adjudicating Officer bandwidth is still building), but the mechanism is in force and enforceable. The Second Schedule graded penalty scale runs from written warning through slabs to Rs 5 crore. The Adjudicating Officer chooses the slab having regard to nature, gravity, duration and frequency of the contravention, disproportionate gain, loss caused to affected users, and whether any voluntary undertaking under Section 33 was submitted [L5-C5].
The Section 33 voluntary undertaking mechanism is the most practically important feature of the adjudication framework. An operator that discovers a breach can submit a voluntary undertaking before any show-cause notice, disclosing the contravention and outlining mitigation. Acceptance bars further proceedings. During a hearing, an operator can submit a voluntary undertaking that the AO must consider as a mitigating factor in setting the penalty slab. Module 8 walks the Section 33 template.
The quarterly compliance calendar for a mid-size ISP
What does the year actually look like? Below is a working calendar for an ISP holding an Internet Service Authorisation plus an Infrastructure Provider authorisation, with 50,000 to 500,000 subscribers and 100 to 500 employees.
Q1 (January to March)
- Financial-year opening review of TCS Rules 2024 incident log (year prior). Rebase 6-hour response SLA benchmarks.
- Annual review of CTSO appointment and continuing eligibility (Indian citizen, resident).
- File annual self-certification for registered senders under TCCCPR Second Amendment Regulations 2025 (mandatory for TMs and registered senders).
- Right of Way filing renewals for infrastructure whose original RoW is expiring.
- Digital Bharat Nidhi Universal Service Levy remittance for Q4 of prior FY.
Q2 (April to June)
- Financial-year filings: AGR return to DoT, licence fee remittance, MNP annual fee (if applicable).
- Digital Bharat Nidhi Universal Service Levy remittance for Q1 of current FY.
- Quarterly cyber-security posture review (map to TCS Rules 2024 obligations).
- Board or executive review of pending Rule 25(3) data-localisation architecture work.
- Review of Section 20 suspension order log (year prior) if any were served.
Q3 (July to September)
- Migration status check: if still on legacy UL, decide whether to migrate this quarter via the eServices portal.
- Digital Bharat Nidhi Universal Service Levy remittance for Q2 of current FY.
- Quarterly cyber-security posture review.
- User Identification Rules 2026 audit: BIVS uptime, biometric-match rates, exclusion-mitigation cases, DPDP-consent audit trail.
- Preparation for the annual DoT compliance filing due Q4.
Q4 (October to December)
- Annual DoT compliance filing including cyber-security posture summary, incident log, CTSO continuing eligibility, BIVS metrics, adjudication history.
- Digital Bharat Nidhi Universal Service Levy remittance for Q3 of current FY.
- Year-end board review of Telecom Act compliance risk register (including any pending Section 33 voluntary undertakings).
- Budget planning for the next FY including expected regulatory costs (portal fees, biometric-verification vendor contracts, cyber-audit engagements).
Add designation-triggered items if you are designated CTI (network architecture disclosure refresh, cyber crisis management plan refresh, security audit report submission, government inspection response readiness) and event-triggered items if you receive a Section 20 order (Nodal Officer log, 5-day Committee submission if applicable) or a show-cause notice (Section 33 voluntary undertaking evaluation, defence preparation).
End of Module 1
You now have the 2026 regime change in your head, the section notification map, the 13-rule cascade, the 11-box authorisation grid, and the working compliance calendar. Modules 2 through 8 walk each piece in operational detail.
If you have decided the course is right for you, the paid enrolment gate opens on the next screen. If you are still weighing it, note that Module 2 (the authorisation regime deep-dive) and Module 4 (the cyber security stack including the November 2025 SIM binding directive) are the two most immediately actionable modules for most learners. Module 6 (interception and suspension) and Module 8 (adjudication) are the modules learners come back to most often after enrolment as the operating year unfolds.