BIS Certification for CCTV Cameras in India: CRS Process, Requirements & Documents
CRITICAL 2026 REGULATORY ALERT & MANDATE SUMMARY
Standard Transition (MeitY Order S.O. 4997(E)): Under the Ministry of Electronics and Information Technology (MeitY) notification, the traditional safety standard IS 13252 (Part 1):2010 is being phased out globally and replaced by IS/IEC 62368-1:2023 (Hazard-Based Safety Engineering). While a concurrent transition window remains open until November 1, 2028, manufacturers submitting new applications are advised to test against IS/IEC 62368-1:2023 to avoid secondary transition testing.
Zero-Relaxation Enforcement for CCTV Security (ER 01:2024): MeitY's Office Memorandum effectively withdrew all stock-clearance relaxations. As of April 1, 2026, no CCTV camera can be legally sold, imported, or distributed in India unless it fully complies with the Essential Requirements (ER 01:2024) for CCTV Security.
Analog CCTV Exemption: Per the official BIS circular following MeitY clarifications, standalone Analog CCTV Cameras are explicitly exempt from the Cybersecurity Essential Requirements (ER 01:2024) testing. However, Analog cameras STILL REQUIRE mandatory BIS CRS registration for electrical safety (under IS 13252 / IS/IEC 62368-1).
Mandatory STQC Testing: For non-analog (IP/Digital/Smart) CCTV cameras, cybersecurity ER validation must be conducted by an STQC-empaneled or BIS-recognized cybersecurity testing laboratory prior to final BIS Registration grant.
Does Your CCTV Camera Require BIS Certification?
Yes. All CCTV cameras, Digital Video Recorders (DVRs), and Network Video Recorders (NVRs) sold, imported, or distributed in India must hold mandatory BIS Certification under the Compulsory Registration Scheme (CRS) Scheme II.
Manufacturing, importing, stocking, or selling uncertified CCTV products in India is a direct violation of the Electronics and Information Technology Goods (Requirement for Compulsory Registration) Order (CRO), subjecting non-compliant entities to immediate customs seizures, product recalls, and severe financial and statutory penalties under the BIS Act, 2016.
BIS Certification for CCTV Cameras At a Glance
What is BIS Certification under CRS Scheme II?
The Bureau of Indian Standards (BIS) is India's National Standards Body operating under the aegis of the Ministry of Consumer Affairs, Food and Public Distribution. While industrial products often fall under the ISI Mark scheme (Scheme I, requiring factory audits), electronic and IT products fall under Scheme II: Compulsory Registration Scheme (CRS).
Under CRS Scheme II:
No Factory Inspection is Conducted: Registration is granted strictly on the basis of type testing conducted in BIS-recognized labs in India.
Self-Declaration of Conformity: The manufacturer submits a self-declaration that products manufactured conform to the designated Indian Standard.
Legal Manufacturer Ownership: The BIS license is always issued to the actual manufacturing location/factory, not to a brand, trader, or importer.
Which CCTV Products Require BIS CRS Registration?
The regulatory framework covers all forms of video surveillance capture and processing hardware. Importers and original equipment manufacturers (OEMs) must verify product-specific applicability prior to shipment:
Clarifying the Standard: IS 13252 (Part 1) vs. IS/IEC 62368-1:2023
A major point of confusion across legacy compliance material stems from the transition between Indian safety standards.
OLD SAFETY ARCHITECTURE
IS 13252 (Part 1):2010 / IEC 60950-1
(Prescriptive Rules - IT Focus)
Transition Window Active
(Ending Nov 1, 2028)
UNIFIED MODERN STANDARD
IS/IEC 62368-1:2023
(Hazard-Based Safety Engineering - HBSE)
The Transition Framework Explained
Historical Position: Originally, CCTV cameras were registered under IS 13252 (Part 1):2010 (Information Technology Equipment – Safety).
Current Official Mandate: MeitY notified IS/IEC 62368-1:2023 (Audio/Video, Information and Communication Technology Equipment) as the unified safety standard replacing both IS 13252 (Part 1) and IS 616.
Current Regulatory Status:
Both standards run concurrently until November 1, 2028.
Fresh applications are accepted under IS/IEC 62368-1:2023.
Legacy registrations under IS 13252 must be upgraded to IS/IEC 62368-1:2023 before the November 2028 cutoff.
Essential Requirement for CCTV Security: CCTV Security ER 01:2024
In addition to physical and electrical safety testing, MeitY mandated cybersecurity and hardware-level assurance requirements via CCTV Security ER 01:2024. This framework prevents surveillance equipment from acting as backdoors for network breaches, espionage, or botnet attacks.
The Five Mandatory Technical Security Domains
Hardware-Level Security:
Root of Trust: Hardware-backed Trusted Execution Environment (TEE), Secure Element, or TPM.
Secure Boot: Verification of digital signatures on bootloader and kernel images before execution.
Physical Tamper Protection: Circuit protection against debug interface exposure (JTAG/UART lockout).
Device-Unique Keys: Cryptographic keys burned into OTP memory; shared or hardcoded factory keys are explicitly banned.
Software and Firmware Integrity:
Memory Protections: Implementation of ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention).
Anti-Rollback Protection: Hardware-enforced prevention of firmware downgrades to older, vulnerable versions.
Software Bill of Materials (SBOM): Total transparency of open-source libraries and third-party binaries.
No Hardcoded Credentials: Elimination of default maintenance passwords and hidden backdoors.
Secure Communications:
Encrypted Transport: Default enforcement of TLS 1.2/1.3 for all network streaming and control traffic.
Mutual Authentication: Verification of both server and client endpoints during data exchanges.
Port & Service Lockdown: Disabling of unused network ports and unencrypted protocols (Telnet, HTTP, FTP).
Access Control & Identity Management:
Forced Credentials Setup: Mandatory user password creation during initial installation.
Role-Based Access Control (RBAC): Granular separation of admin, operator, and viewer privileges.
Supply-Chain Security:
Component Provenance: Verification of primary SoC make, model, and origin.
Firmware Hash Binding: Model inclusion series guidelines require all sub-variants in a series to share the same SoC and exact firmware hash.
Analog CCTV Cameras vs. Non-Analog (IP/Smart) CCTV Cameras
A critical regulatory distinction established in official BIS circulars dictates how analog equipment is treated:
Analog CCTV Cameras: Operate over direct coaxial video lines without onboard IP network processing. They MUST obtain BIS Safety CRS Certification (IS 13252 or IS/IEC 62368-1). However, per BIS guidelines, they are EXEMPT from submitting ER 01:2024 Cybersecurity reports.
Other-than-Analog (IP, Digital, Smart CCTV): Network-connected cameras capable of streaming digital data over ethernet, Wi-Fi, or cellular links. They MUST complete BOTH BIS Safety CRS Certification AND Security ER 01:2024 validation.
Who Can Apply for BIS Certification? (Applicant Eligibility & AIR)
BIS CRS licenses are granted exclusively to product manufacturing entities, not trading companies, brand owners, or importers.
BIS CRS Applicant Type
Indian Manufacturing - Facility / Factory - Direct Application - Primary License Holder
Foreign Manufacturing - Facility / Factory - Appoints - Authorized Indian Representative (AIR) - Acts on behalf of - BIS CRS License Execution
The Authorized Indian Representative (AIR) Requirement
Foreign manufacturers with no physical office in India cannot apply directly without appointing an Authorized Indian Representative (AIR).
Who can act as an AIR?
The foreign manufacturer's registered branch/subsidiary office in India.
An authorized Indian importer or distributor operating under a legally executed power of attorney.
An independent regulatory compliance service firm located in India.
Key AIR Qualifications & Obligations:
The AIR must be an Indian entity with a valid GST and PAN registration.
The AIR assumes joint legal liability under the BIS Act for product compliance and market surveillance obligations.
Comprehensive Document Checklist
The following technical and administrative documentation is required for processing a BIS CCTV CRS application:
Step-by-Step BIS CCTV Registration Process
Product Categorization & Model Grouping: Determine whether the device is Analog or IP-based. Evaluate product specifications against BIS Series Guidelines to check if multiple models can be grouped into a single test application.
Lab Reservation & Sample Submission: Submit required production-grade test samples (typically 1 to 2 units per series) to a BIS-recognized testing laboratory in India.
Safety & Security Evaluation: The laboratory subjects the camera to electrical safety testing (overload, heat resistance, insulation) and cybersecurity testing (vulnerability scans, secure boot verification).
Online Application Generation: Upon test report generation, create a profile on the official BIS CRS portal (crsbis.in), upload the required documentation, and submit the complete test report.
BIS Review & Grant: BIS officers scrutinize the technical package. If queries are raised regarding BOM components or label dimensions, the applicant/AIR must submit formal clarifications within specified deadlines. Once satisfied, BIS issues the Registration Certificate (RC) containing a unique 8-digit R-Number (e.g., R-XXXXXXXX).
Cost Structure Breakdown
Realistic Timeline Expectations
BIS Marking & Packaging Requirements
Once registered, every product unit and its sales packaging must display the BIS Standard Mark before being placed on the market.
Essential Marking Rules
Mark Format: Must display the official "Self-Declaration - Conforming to IS..." logo along with the specific standard number and the allotted registration number R-XXXXXXXX.
Product & Box Placement: The mark must be legibly applied directly to the product body via rating label, screen-printing, or etching, as well as on the outer packaging box.
Security Marking Declaration: For products passing ER 01:2024, the outer packaging must state: "Complies with Essential Requirement(s) for Security".
E-Labelling Provision: If the CCTV device features an integrated visual display, software e-labelling is allowed, provided physical packaging markings remain fully compliant.
Handling Multiple Models, Series & Hardware Variants
To reduce certification costs, BIS allows manufacturers to group multiple models under a single registration using Series Guidelines.
Conditions for CCTV Series Grouping
To group secondary models under a lead model in one test application, all variants must share:
The exact same manufacturing location and brand.
The exact same PCB layout and mainboard architecture.
The exact same Main System-on-Chip (SoC) and image sensor architecture.
The exact same Firmware Branch and Security Hash.
Identical enclosure construction class and power adapter ratings.
Warning: If a secondary CCTV camera model utilizes a different SoC, an updated internal PCB trace layout, or a modified base firmware build, it cannot be included in the existing series. It must undergo separate testing as a distinct product family.
14 Practical Reasons for Application Delays & Rejections
Incorrect Safety Standard Selection: Testing against legacy standards after cutoffs or failing to prepare for the IS/IEC 62368-1:2023 transition.
Security ER Omission: Submitting IP cameras without mandatory STQC/ER security test reports.
Mismatched Firmware Hashes: Firmware build numbers on the tested camera failing to match the documentation declared in the security application.
SoC Discrepancies: Declaring a series application where sub-models utilize different SoC part numbers.
Open Debug Interfaces: Leaving JTAG/UART test pads accessible on production PCBs.
Hardcoded Credentials: Uncovered default factory login credentials embedded within camera firmware.
BOM Component Mismatches: Discrepancies between critical components listed on the lab report and actual components inside the camera.
Brand Authorization Deficiencies: Incomplete or unnotarized brand authorization documents from brand owners to manufacturing facilities.
AIR Representation Errors: Appointing an AIR whose registered business address does not match official tax records.
Label Layout Violations: Printing the BIS mark without the R-number or displaying incorrect standard text size ratios.
Testing Sample Failures: Electrical insulation or creepage distance failures during safety evaluation.
Inconsistent Foreign Documents: Address variations across foreign business licenses, manufacturing agreements, and test applications.
Delayed Query Response: Failing to reply to official BIS portal queries within the mandatory 30-day response window.
Insecure Wireless Protocols: Utilizing unencrypted Wi-Fi or deprecated TLS configurations for cloud streaming.
International Certification Comparison
Foreign certifications like CE or FCC validate compliance against overseas regulations, but they carry no legal standing in India.
BIS CRS vs. STQC Certification for CCTV
COMPLIANCE FRAMEWORK DUALITY
BIS CRS REGISTRATION (Bureau of Indian Standards)
• Controls Market Access & Import
• Validates Electrical & Fire Safety
• Issues Final Registration Number
• Mandated for ALL Commercial Sales
STQC EVALUATION (Standardisation Testing Quality)
• Validates ER 01:2024 Cybersecurity
• • Conducts Firmware & Vulnerability Assurance
• Required for Public/Govt Procure
BIS CRS: The overall national mandatory compliance framework under which electronic goods receive clearance for commercial market sale in India.
STQC (Standardisation Testing and Quality Certification): A technical directorate under MeitY that provides cybersecurity testing, software quality verification, and ER validation. An STQC test report or STQC certificate provides the technical proof required by BIS to confirm ER 01:2024 compliance.
Post-Registration Compliance & Ongoing Obligations
Validity & Timely Renewal: BIS CRS licenses are granted for 2 years. Renewal applications must be filed online at least 90 days prior to expiration to maintain unbroken sales authorization.
Handling Modifications: Any hardware change, PCB revision, component swap in the BOM, or base firmware alteration must be declared to BIS via a formal modification application.
Market Surveillance: BIS routinely purchases certified CCTV units directly from commercial retail channels or e-commerce marketplaces and sends them to independent labs for verification testing. Non-compliant units lead to license cancellation, public warning notices, and product recall orders.
2026 Regulatory Update Log
Practical Action Checklist for Manufacturers and Importers
Step 1: Product Classification – Verify whether the target camera operates via Analog signaling or IP/Network interface.
Step 2: Standard Identification – Confirm testing scope against IS/IEC 62368-1:2023 (or IS 13252 within transition window).
Step 3: Security ER Audit – For IP cameras, verify that firmware lacks hardcoded passwords and supports secure boot, signed updates, and encrypted communications.
Step 4: Representative Appointment – (Foreign plants only) Formally execute AIR Power of Attorney with a qualified Indian entity.
Step 5: Document Assembly – Gather PCB layouts, schematics, user manuals, and the full BOM detailing component part numbers.
Step 6: Lab Selection & Testing – Reserve testing slots at a BIS-recognized (and STQC-empaneled) laboratory in India.
Step 7: Portal Submission – File the online application via crsbis.in, upload test reports, pay official fees, and resolve officer queries promptly.
Step 8: Label Verification – Print compliant BIS Standard Mark labels with the allotted R-Number on product bodies and master cartons prior to market entry.
Frequently Asked Questions (FAQs)
1. Is BIS certification mandatory for selling CCTV cameras online in India?
Yes. Major e-commerce platforms (Amazon, Flipkart, etc.) and commercial distributors are legally required to verify valid BIS registration details (R-Number) before listing any CCTV camera or recorder.
2. Can an importer hold a BIS certification in their own name?
No. BIS CRS licenses are granted exclusively to the factory where the product is manufactured. An importer can only act as the Authorized Indian Representative (AIR) for a foreign manufacturing plant.
3. Do analog CCTV cameras require cybersecurity testing under ER 01:2024?
No. Per official BIS circulars, standalone analog CCTV cameras are exempt from ER 01:2024 cybersecurity testing. However, they still require mandatory BIS Safety CRS certification under IS 13252 or IS/IEC 62368-1.
4. Are NVRs and DVRs covered under the same standard as CCTV cameras?
Yes. CCTV recorders (both Digital Video Recorders and Network Video Recorders) fall under the same safety standard (IS 13252 / IS/IEC 62368-1) and require BIS registration.
5. What happens to existing registrations under IS 13252 (Part 1):2010?
Existing licenses remain valid during the concurrent transition period running through November 1, 2028. However, manufacturers must migrate their licenses to IS/IEC 62368-1:2023 prior to that date.
6. Can multiple CCTV camera models be included in one BIS application?
Yes, provided all variants share the same manufacturing plant, brand, enclosure rating, PCB architecture, SoC, and firmware branch according to BIS Series Guidelines.
7. How long is a BIS CRS certificate valid?
An initial BIS CRS registration certificate is granted for 2 years. It can subsequently be renewed for terms ranging from 2 to 5 years.
8. What is the penalty for selling non-compliant CCTV cameras in India?
Selling uncertified equipment can lead to customs seizures, product recall orders, and statutory financial penalties up to ₹5 lakh for a first offense, and up to ₹10 lakh alongside potential imprisonment under the BIS Act.
9. Does STQC certification replace the need for a BIS certificate?
No. STQC testing validates cybersecurity ER compliance. The resulting test report must be submitted to BIS to obtain the mandatory BIS CRS Registration.
10. Can we test foreign samples at an overseas laboratory for BIS certification?
No. All product testing for BIS CRS registration must be conducted at BIS-recognized laboratories located within India.
11. Does solar-powered standalone CCTV require BIS certification?
Yes. If the product functions as a CCTV camera, the core device requires BIS CRS safety registration and cybersecurity ER clearance (if IP/smart) regardless of power delivery method.
12. Must power adapters packed with CCTV cameras carry separate BIS marks?
Yes. External power adapters fall under a separate mandatory BIS CRS category (Power Adaptors for IT/AV Equipment) and must hold their own distinct BIS registration.
13. How can a buyer verify if a CCTV camera's BIS registration is genuine?
Buyers can visit the official BIS portal (crsbis.in), navigate to "Search Registered Manufacturers," and input the 8-digit R-Number printed on the product label to verify active status, manufacturer address, and approved models.
14. What is required if we update the firmware of a certified CCTV camera?
If the firmware update alters core security mechanisms or changes the software bill of materials (SBOM) hash, a modification/declaration filing must be submitted to BIS to ensure ongoing compliance.
15. Is a factory audit required for BIS CRS registration of CCTV cameras?
No. CRS Scheme II operates on type-testing and self-declaration of conformity; no physical factory audit is required prior to license grant.
Conclusion
Navigating BIS Certification for CCTV cameras in India requires careful alignment across safety standards, hardware specs, and cybersecurity mandates. With enforcement of CCTV Security ER 01:2024 active and the transition to IS/IEC 62368-1:2023 underway, manufacturers and importers must verify product scope, prepare technical documentation, and conduct testing through BIS-recognized laboratories.
For expert assistance with testing coordination, document preparation, or Authorized Indian Representative (AIR) support, consult a certified Indian regulatory compliance specialist.

Comments
Post a Comment