Skip to content
MUMBAI / NEWS WALLTHE CITY, IN FULL
Tech

India proposes tougher smartphone security standards, including source-code sharing, triggering pushback from global manufacturers

India is considering a wide set of smartphone security requirements that would ask manufacturers to share source code and notify the government of major updates—moves the industry says are unprecedented and could expose proprietary information.

India is proposing a major security overhaul for smartphones that could require device makers to share source code with the government and implement a broad set of software-related changes, according to a Reuters report. The plan is part of a wider push to strengthen protection of user data in a market facing growing online fraud and frequent reports of data breaches.

India proposes tougher smartphone security standards, including source-code sharing, triggering pushback from global manufacturers
Related image

The proposal is said to include a package of 83 security standards. Among the most contested elements is an expectation that manufacturers would provide source code and also alert the government to major software updates—conditions that companies argue could reveal proprietary design choices and create new risks for intellectual property and security.

Global players such as Apple and Samsung have opposed the plan behind the scenes, arguing that requirements of this kind lack global precedent. Their concern is that mandates that go beyond common international security certification approaches could force companies to redesign compliance processes specifically for India, increasing cost and complexity.

The government’s rationale, as described in the report, is anchored in protecting users in the world’s second-largest smartphone market, where the number of devices is estimated in the hundreds of millions. The scale of adoption increases both the impact of security weaknesses and the attractiveness of the ecosystem to criminals.

The debate also reflects a wider global trend: governments want more visibility into how devices and platforms handle sensitive information, while industry argues that forced disclosure can backfire by expanding access to sensitive code. The tension is particularly sharp when policy proposals blend cybersecurity goals with regulatory oversight of updates and device behaviour.

If implemented as described, the standards could reshape how phones are tested and certified for sale in India, and could influence timelines for rolling out software updates. It may also drive negotiations over what can be shared, how it is safeguarded, and whether independent audits can substitute for direct source-code access.

The outcome will matter beyond smartphones: it could set expectations for how India approaches security governance for consumer technology more broadly, including IoT devices and connected services that rely on frequent software revisions.

ORIGIN STATIONS

Sources and reporting record

  1. 01Investing.com (Reuters)Investing.com (Reuters)