Indian officials have debunked claims about forcing smartphone manufacturers to share source code as part of a proposed overhaul.
The proposal came under scrutiny following reports that it had been circulated in draft form.
Government Clarifies Ongoing Consultations
The Ministry of Electronics and Information Technology has said that there is no such proposal to make source code sharing mandatory.
This was in respect to talks of making source code available for global collaboration for better mobile security standards.
In a release by the Press Information Bureau, the reports that a mandate has already been concluded were denied.
“The Government of India has NOT proposed any measure to force smartphone manufacturers to share their source code,” a release said.
The ministry stressed that it is committed to addressing issues raised by the industry.
It explained the significance of mobile security, given that smartphones are capable of conducting monetary transactions and hold personal data.
Draft Proposals Spark Industry Pushback
There were reports of a proposed framework from the Indian Telecom Security Assurance Requirements that might ask for source code access to check vulnerabilities.
Source code would be analyzed by the labs to see if they could find any malicious or back door code.
Other features of the proposed legislation include the mandatory scanning of malware, software update preview approval, and one-year log retention for applications and logins.
Devices are expected to disable background access for cameras and microphones.
The tech industry, Apple and Samsung among them, sounded the alarm.
Their rationale was that “globally security requirements have not been mandated by any country,” an industry concern recorded by the ministry.
The India Cellular & Electronics Association requested dropping the source code requirement.
There were warnings about-battery drain caused by scans, delays in update distribution.
Cyber Threats Fuel Security Focus
India faced 369 million malware detections across 8.44 million endpoints in the year 2025. Trojans accounted for 43%, followed by infectors at 34%.
Telangana, Tamil Nadu, and Delhi were the states that witnessed the most threats. Mobile malware accounted for 42 percent of the detections.
The market expanded 5 percent year-over-year in shipments during July-September 2025 for yet another record value.
Close to 750 million Indians use smartphones, making them prime targets for fraud.
Data protection is a high priority for the Narendra Modi administration, with officials saying that identity theft and financial loss are significant risks.
Privacy Advocates Highlight Risks
The Internet Freedom Foundation pointed out that the drafts were threatening the citizens’ privacy. It warned that logs would profile users’ lives.
The group argued that requirements violate data protection principles and lack public input, and open consultations are required.
No draft of the smartphone-specific ITSAR apparently has been published, though there are related telecom drafts.
Discussions continue under the National Centre for Communication Security.
How Draft Shifts Tech Landscape in India
If implemented, rules would make development more complex and expensive. Companies are afraid of fragmented global chains of value.
The move echoes similar actions in the past, such as testing cameras over espionage concerns.
Apple and Samsung remain the value leaders, while vivo leads in volume shares.
The policy could set precedents for emerging markets balancing security and innovation.
Timeline of Security Discussions
Drafts were issued in the year 2023. Meetings with companies took place in December 2025.
A session is scheduled for January 13, 2026. Final policy will be further refined upon further input.
No firm deadlines exist. Authorities promised to investigate the concerns.




















