Moneycontrol PRO
LAMF
LAMF

India proposes forcing smartphone makers to give source code in security overhaul

The plan is part of PM Modi's efforts to boost security of user data as online fraud and data breaches increase in the world's second-largest smartphone market
January 12, 2026 / 11:55 IST
The IT ministry added it "refutes the statement" that it is considering seeking source code from smartphone makers
Snapshot AI
  • India proposes strict smartphone security rules, including source code access
  • Apple and Samsung oppose plan, citing privacy and feasibility concerns
  • Govt denies seeking source code, says consultations ongoing

India proposes requiring smartphone makers to share source code with the government and make several software changes as part of a raft of security measures, prompting behind-the-scenes opposition from giants like Apple and Samsung.

The tech companies have countered that the package of 83 security standards, which would also include a requirement to alert the government to major software updates, lacks any global precedent and risks revealing proprietary details, according to four people familiar with the discussions and a Reuters review of confidential government and industry documents.

The plan is part of Prime Minister Narendra Modi's efforts to boost security of user data as online fraud and data breaches increase in the world's second-largest smartphone market, with nearly 750 million phones.

IT Secretary S. Krishnan told Reuters on Saturday "any legitimate concerns of the industry will be addressed with an open mind", adding it was "premature to read more into it".

A ministry spokesperson said in an emailed statement on Saturday it could not comment further due to ongoing consultation with tech companies on the proposals.

After the story was published, an IT ministry statement said late on Sunday that the consultations are aimed at developing "an appropriate and robust regulatory framework for mobile security", and it "routinely" engaged with the industry "to better understand technical and compliance burden."

The IT ministry added it "refutes the statement" that it is considering seeking source code from smartphone makers, without elaborating or commenting on the government or industry documents cited by Reuters.

ONGOING TUG OF WAR OVER GOVERNMENT REQUIREMENTS

Apple, South Korea's Samsung, Google, China's Xiaomi and MAIT, the Indian industry group that represents the firms, did not respond to requests for comment.

Government requirements have irked technology firms before. Last month it revoked an order mandating a state-run cyber safety app on phones amid concerns over surveillance. But the government brushed aside lobbying last year and required rigorous testing for security cameras over fears of Chinese spying.

Xiaomi and Samsung - whose phones use Google's Android operating system - hold 19% and 15%, respectively, of India's market share and Apple 5%, Counterpoint Research estimates.

Among the most sensitive requirements in the new Indian Telecom Security Assurance Requirements is access to source code - the underlying programming instructions that make phones work. This would be analysed and possibly tested at designated Indian labs, the documents show.

The Indian proposals also require companies to make software changes to allow pre-installed apps to be uninstalled and to block apps from using cameras and microphones in the background to "avoid malicious usage".

"Industry raised concerns that globally security requirement have not been mandated by any country," said a December IT ministry document detailing meetings that officials held with Apple, Samsung, Google and Xiaomi.

The security standards, drafted in 2023, are in the spotlight now as the government is considering imposing them legally. IT ministry and tech executives are due to meet on Tuesday for more discussions, sources said.

COMPANIES SAY SOURCE CODE REVIEW, ANALYSIS 'NOT POSSIBLE'

Smartphone makers closely guard their source code. Apple declined China's request for source code between 2014 and 2016, and U.S. law enforcement has also tried and failed to get it.

India's proposals for "vulnerability analysis" and "source code review" would require smartphone makers to perform a "complete security assessment", after which test labs in India could check their claims through source code review and analysis.

"This is not possible ... due to secrecy and privacy," MAIT said in a confidential document drafted in response to the government proposal, and seen by Reuters. "Major countries in the EU, North America, Australia and Africa do not mandate these requirements."

MAIT asked the ministry last week to drop the proposal, a source with direct knowledge said.

The Indian proposals would mandate automatic and periodic malware scanning on phones. Device makers would also have to inform the National Centre for Communication Security about major software updates and security patches before releasing them to users, and the centre would have the right to test them.

MAIT's document says regular malware scanning significantly drains a phone's battery and seeking government approval for software updates is "impractical" as they need to be issued promptly.

India also wants the phone's logs - digital records of its system activity - to be stored for at least 12 months on the device.

"There is not enough room on device to store 1-year log events," MAIT said in the document.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Reuters
first published: Jan 12, 2026 11:54 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347