BIS/STQC 2026 for Factory Cameras: What Owners Must Do
By the Mama team — we scope camera projects for Indian factories. Last verified: 17 July 2026, against MeitY S.O. 1652(E), the BIS CRS CCTV guidelines, and the live STQC IoTSCS list.
Short answer: From 1 April 2026, no CCTV camera can be legally sold in India unless it carries both BIS registration (IS 13252 safety) and STQC/ER-01 security certification — the relaxation for pre-April-2025 stock is withdrawn. For a plant owner the practical rule is simple: buy only ER-01-registered models, and get the STQC certificate number for the exact SKU in writing before you pay.
Every installer blog now carries the dates. What they leave out is the part that costs you money after the PO is signed: the "safe Indian brand" that is actually a Chinese JV, the certificate that quietly stops applying the moment a firmware update lands, and the fact that a certified camera does nothing about the worker-footage rules coming at you from a completely different law. This piece is about those traps, not just the calendar.
Key points
- From 1 April 2026 a CCTV camera needs both stamps to be sold in India: BIS (safety) and STQC/ER-01 (cybersecurity).
- Pre-9-April-2025 stock is no longer legally sellable — the sale relaxation was withdrawn.
- A purely private plant's minimum is BIS/ER-01; STQC/IoTSCS becomes decisive only for government/PSU/defence tenders.
- Verify per model, per firmware, not per brand — the certificate is bound to a specific firmware build.
- Most Chinese-chipset Hikvision/Dahua lines are reportedly uncertified; a few non-Chinese-chipset lines passed. Confirm the exact SKU.
When do the BIS/STQC CCTV rules take effect? (key dates)
Two separate government requirements now stack on every CCTV camera in India — an older BIS safety registration under the Compulsory Registration Scheme (CRS), and a newer STQC/ER-01 cybersecurity layer that MeitY notified as an amendment to the Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order, 2021.
| Date | What happens | Source |
|---|---|---|
| 9 Apr 2024 | ER-01 (Essential Requirements for Security of CCTV Cameras) notified via MeitY gazette S.O. 1652(E), amending the CRS Order; transition window opens. | MeitY gazette S.O. 1652(E) |
| 9 Apr 2025 | Transition ends: new CRS registrations for CCTV must pass ER-01 security testing. | BIS CRS CCTV guidelines |
| 16 Jan 2026 | MeitY Office Memorandum withdraws the relaxation that let pre-9-Apr-2025 stock be sold. | MeitY OMs; industry reporting |
| 1 Apr 2026 | No sale permitted of any CCTV camera that does not conform to ER-01. | MeitY OM / industry reporting |
In plain terms: from April 2026, old inventory can no longer be legally sold to you, and a compliant camera needs both stamps — BIS (safety) and STQC/ER-01 (security).
What does ER-01 actually test?
ER-01 is a cybersecurity standard aimed at network/IP cameras and recorders. An STQC lab checks for concrete failure modes a buyer can recognise, not vague "hardening":
- No hardcoded or default credentials — a unique per-device key, not
admin/adminacross a whole production run. - Signed, verifiable firmware — secure boot and tamper detection, so the device won't run an unsigned image.
- Encrypted transport (TLS) end to end between camera, recorder and viewing client.
- Penetration testing against known attack classes, and locked-down debug/management ports.
- Declared origin of critical components — the scheme reportedly requires a declaration on the camera's SoC and critical-component sourcing, which is precisely what strands most Chinese-chipset lines.
Why an owner should care beyond paperwork: an uncertified IP camera is a documented network entry point. Hikvision's own CVE-2021-36260 — an unauthenticated command-injection flaw — was mass-exploited across tens of thousands of exposed devices, and the Mirai botnet was built largely on hijacked cameras and DVRs. ER-01 exists to shut that door before it's on your OT network.
The two certifications, side by side
| BIS CRS (IS 13252) | STQC / ER-01 | |
|---|---|---|
| What it proves | Electrical + fire safety of the device | Cybersecurity of the camera/recorder |
| Standard | IS 13252 (Part 1):2010, harmonised with the legacy IEC 60950-1 basis (internationally superseded by IEC 62368-1, but India still references it here) | ER-01, notified via S.O. 1652(E), 9 Apr 2024 |
| Who tests | BIS-recognised labs | STQC-approved labs only |
| Mandatory since | CRS registration (baseline safety) | New registrations: 9 Apr 2025; all sales: 1 Apr 2026 |
| Covers | Cameras, DVRs, NVRs | Cameras and recorders (network/IP focus) |
| Owner checks | BIS CRS registration (R-number) | Valid STQC/ER-01 certificate for the SKU |
Do you even need STQC, or just BIS ER-01?
This is the question the installer SERP skips, and it sets your minimum spend. A purely private factory's legal minimum is BIS/CRS-registered, ER-01-compliant gear — full stop. STQC's separate IoT System Certification (IoTSCS) passport becomes decisive only when you supply government, PSU, defence or smart-city buyers, or bid regulated tenders that name it.
- Private plant, no government business: buy ER-01-registered models. That is your floor.
- You bid government/PSU/defence tenders: you also present the STQC/IoTSCS certificate, checked line by line.
Knowing which bucket you're in stops you from either under-buying (and failing a tender) or over-paying for a passport you'll never present.
Which CCTV brands are BIS/STQC certified in India?
The certified list names domestic and JV makers; the Chinese-chipset incumbents largely fell out.
| Brand | ER-01 / STQC certified? | Note |
|---|---|---|
| CP Plus (Aditya Infotech) | Yes | Domestic; broad range |
| Prama | Yes | Caveat: this is Prama Hikvision India, a joint venture established with China's Hikvision — check the actual certificate holder and chipset origin; don't read the "Prama" name as independent. |
| Sparsh | Yes | Domestic |
| Matrix (Matrix Comsec) | Yes | Domestic |
| Honeywell | Yes | Multinational |
| Hikvision (Chinese-chipset lines) | Largely not certified | A few non-Chinese-chipset lines reportedly passed — verify the exact SKU |
| Dahua (Chinese-chipset lines) | Largely not certified | Effectively out of legal sale on affected lines |
Certification is per-model and the STQC IoTSCS list changes — a brand appearing here means nothing until you confirm the exact SKU's R-number and certificate on the portal.
The Prama line is the trap worth internalising: it's marketed as a safe Indian alternative, but it is Hikvision's own India JV. And the general lesson is sharper still — a certificate proves one model passed a security lab test on one firmware build. It says nothing about where the mobile-app or cloud traffic terminates, or whether an "Indian" brand rebadges foreign OEM hardware. Certification solves tender-eligibility. It does not automatically solve the espionage worry owners think they're buying their way out of. Certified ≠ sovereign.
The certified shelf is shorter than you think
The real procurement pain in 2026 isn't the headline price bump — it's availability. The certified SKU pool is small and heavily domestic-concentrated, so a large rollout runs into single-source lead-time risk and thin variant choice. Specific PoE, thermal, long-lens or high-count 4K variants may have no certified equivalent yet. Any imported certified stock also carries roughly a 20–40% landed import-duty load, so it competes badly on price and thins the shelf further.
On cost: vendors indicate a rough 10–20% premium at the mid-to-high end (budget lines steadier) — treat it as indicative, not an official survey figure. The drivers are real (per-SKU STQC lab testing and re-certification, non-Chinese-chipset BOM). But plan for lead time and variant gaps, not just +15% on the unit line.
The firmware-hash trap — put it in your PO
Here's the clause nobody writes about. The STQC certificate is issued against a specific firmware build. Ship a 200-camera rollout flashed on a build that differs from the certified one — or let an OTA update roll the fleet onto uncertified firmware six months later — and those cameras are technically non-compliant even though the model name is "certified."
Two lines into the purchase order fix it:
- The vendor warrants that delivered units ship on the exact certified firmware listed in the STQC certificate.
- AMC and OTA updates keep the fleet on certified builds — an update that breaks certification is the vendor's liability, not yours.
Certified device ≠ protected footage (the DPDP stacking trap)
STQC/ER-01 secures the device. It does nothing about the footage. India's DPDP Act, 2023 (rules rolling out through 2026) governs the personal data your cameras capture — worker faces are personal data, which brings retention limits, notice expectations, and a breach-notification duty. An owner who thinks "certified cameras = compliance done" is only half covered: device security is one regime, data protection is another. Certified hardware does not close your DPDP exposure on how long you keep footage, who can view it, and how you secure it.
How do you verify a camera is really certified?
Don't take a vendor screenshot on trust. In our own vendor conversations the pattern repeats: quotes come back with a brand-level compliance claim and no SKU-level certificate number. That gap is the whole game. When we gate a factory's camera BOM, we run two checks per model — you can do the same in five minutes:
- BIS R-number on crsbis.in. Search the BIS CRS portal by the R-xxxxxxx registration number the vendor gives you and confirm it returns that exact model under the correct brand — not a different SKU from the same maker.
- STQC/ER-01 certificate on the IoTSCS list. Open the STQC IoTSCS list and match four fields: model number, certificate holder, validity date, and firmware/product line. A valid entry names the specific model; a brand-level claim with no model is not a certificate.
The five-minute buyer's checklist
Before you release a purchase order, get in writing:
- The BIS CRS registration number (R-xxxxxxx) for the exact model.
- The STQC/ER-01 certificate for that SKU, with the firmware build it certifies.
- Confirmation the model appears on the current STQC IoTSCS list and the R-number resolves on the BIS CRS portal.
- That DVRs/NVRs and recorders are covered too, not just the cameras.
- Written confirmation the stock is post-April-2025 compliant, not old inventory being cleared.
The unusually cheap quote landing this quarter is very often a distributor clearing pre-April-2025 stock before it becomes dead inventory. That discount is his problem becoming yours: the camera is unsellable, and on your floor it's a live liability.
After compliance: placing them right
A certified camera pointed at a blind wall still sees nothing useful. Compliance decides what you may buy; it can't answer how many and where. Record a two-minute phone walk of the floor and Mama returns a placement plan — how many cameras, ceiling or wall, which zones and hazards — plus a plain-language read of the space, with no site survey and no waiting.
FAQ
Do these rules apply to cameras already installed in my factory? The 1 April 2026 restriction targets the sale of non-compliant cameras, not retroactive removal of installed ones. But every replacement, expansion or new site must use ER-01/STQC-certified models. Check the latest MeitY/BIS wording before assuming existing stock is grandfathered.
Is BIS registration enough, or do I also need STQC? Both, to be legally sold. BIS CRS (IS 13252) covers electrical safety; ER-01 (tested by STQC labs) is the cybersecurity layer. If you also bid government/PSU/defence tenders, you additionally present the STQC/IoTSCS certificate per SKU.
Are Hikvision and Dahua banned in India? Not by name — the rule bans the sale of uncertified cameras, and it catches most of their line-up. Reporting in 2026 indicates most Hikvision and Dahua models on Chinese-origin chipsets did not obtain STQC certification and so can't be sold, while a few non-Chinese-chipset lines reportedly passed. Note too that Hikvision operates in India through the joint venture Prama Hikvision India — so a "Prama" certificate is not evidence of independence from Hikvision. Verify the specific SKU.
How much more will compliant cameras cost, and can I get the models I need? Vendors indicate roughly 10–20% more at the mid-to-high end (indicative, not official), driven by per-SKU testing and non-Chinese-chipset BOM. The bigger issue is supply: the certified pool is small and domestic-heavy, so plan for lead time and possible gaps in PoE/thermal/long-lens/4K variants rather than just a price bump.
Does ER-01 apply to DVRs and NVRs too, or only cameras? Cameras, DVRs and NVRs all fall under BIS CRS scope, and ER-01 focuses on network-connected cameras and recorders. Insist on certification covering the recorder as well as the cameras.
