The Core Requirement: "SIM Binding"
Messaging platforms, now categorised as "Telecommunication Identifier User Entities" (TIUEs), must ensure that their application only functions on a device that contains the registered, active SIM card. This process is being referred to as "SIM binding." The apps are required to continuously verify the presence of the SIM card. If the SIM is removed, replaced with a different one, or becomes inactive, the messaging service must cease to function on that device.
The directive applies to major app-based communication services, including but not limited to:
📌Telegram
📌Signal
📌Snapchat
📌ShareChat
📌JioChat
For users who access these services via web browsers or desktop applications (e.g., WhatsApp Web), the new rules introduce a mandatory periodic logout. These sessions must automatically end at least every six hours, forcing users to re-authenticate, typically by scanning a QR code with their primary mobile device.
Government officials have stated that this move is intended to bolster cybersecurity and curb cyber fraud. The DoT noted that the current system, which allows apps to continue running even after a SIM card is removed, is being exploited—particularly by actors outside India—to commit financial scams and other telecom-related frauds. By tying every session to a physical, verified SIM, authorities aim to establish a clear traceable link between the user, the device, and the mobile number.
The messaging platforms have been given a deadline of 90 days to implement these technical changes and comply with the new norms set out under the Telecommunication Cybersecurity Amendment Rules, 2025.
This regulation will directly affect how millions of Indians use messaging apps. Users will no longer be able to access their accounts on a phone that does not hold the original registered SIM card. This could create challenges for individuals who use multiple devices, frequently swap SIM cards, particularly while travelling abroad, or in situations where a user's SIM card becomes temporarily inactive. Additionally, the mandatory six-hour logout for web versions will introduce a new layer of fri
ction for desktop users.
Please sign in
Login and share