India's New IST Rules Create Compliance
India's Department of Consumer Affairs has notified the Legal Metrology (Indian Standard Time) Rules, 2026, mandating IST for all purposes.

India's Department of Consumer Affairs notified the Legal Metrology (Indian Standard Time) Rules, 2026, as G.S.R. 761(E) on August 27, 2026. The rules come into force 180 days after their August 29 Gazette publication, placing commencement in the last week of February 2027, though some reports suggest March.
Rule 7 prohibits any entity from using, displaying, or recording any time reference other than Indian Standard Time for all purposes. The single word record creates significant ambiguity for technology companies. Storing timestamps in Coordinated Universal Time is a global standard practice for databases and server logs, with local time applied upon display. The rules do not clarify if this common technical practice is now banned.
Authorised Sources and User Liability
The rules create a new category of authorised timing source. Control over this category is handed to the Director of Legal Metrology, who may authorise any institution, system, or service subject to unspecified requirements. The Director must also publish and maintain a list of addresses and access protocols for designated time services, including NTP and PTP. This list is not yet public.
Liability rests squarely with end users, not suppliers. Rule 6(4) states that the end entity shall bear the exclusive responsibility for ensuring the accuracy, stability and traceability of the time dependent within its systems. For critical sectors like telecommunications, financial services, energy, and data centres, authorised sources are limited to five options: CSIR-NPL, a Regional Reference Standards Laboratory, a NavIC-based timing reference or device, the National Informatics Centre, or other authorised timing sources. GPS is not on the list.
Technical Requirements and Ambiguities
The rules mandate redundancy for critical infrastructure, a broad category that includes defence, power grids, utilities, telecommunications, banking, transportation, enterprises, broadcasting, and data centres. Rule 9(7) requires all global navigation satellite system timing devices to receive at least one timing reference directly from the NavIC constellation or an authorised source.
A key provision, Rule 9(9), demands uninterrupted timing if a reference input fails. One compliance route is employing highly stable and precise atomic clocks calibrated by CSIR-NPL or an RRSL. The rules define accuracy as conformity to UTC(NPLI) or IST but set no numerical standard. There is no specified millisecond or microsecond tolerance. Rule 10 provides for periodic audits against an unstated standard.
Unresolved Questions from Past Directives
The rules aim to close a gap highlighted in 2022. Back then, CERT-In directed organisations to sync clocks to NTP servers run by NIC or CSIR-NPL. A CSIR researcher, speaking anonymously to MediaNama, noted the foundational problem: What CERT is asking companies to do has no meaning until the Consumer Affairs makes IST the legal time of India. That legal foundation is now established.
However, capacity questions remain. In December 2022, MediaNama's RTI requests revealed CSIR-NPL operated 20 NTP servers from a single Delhi location, while NIC declined to provide a server count citing security. No updated public figures on server capacity or uptime have been released since. The new rules allow for many authorised sources to distribute load, but the authorisation process has not visibly begun.
Penalties for non-compliance are also left undefined. Rule 11 states a breach is punishable under the provisions of the Act, but no specific penalty amount or section is named. The Legal Metrology Act allows for penalties up to five lakh rupees, but the IST Rules do not utilise this power.
Drafting issues add to the uncertainty. Rule 6(4) refers to the time dependent within its systems, which appears grammatically incomplete. Rule 9(4) lacks an operative verb. The scope of some rules, particularly the inclusion of enterprises and an open-ended etc. in critical infrastructure, is difficult to interpret. The rules represent a significant shift for Indian digital infrastructure, with the detailed compliance burden yet to be fully revealed.





