Understanding STQC Certification Requirements for CCTV Cameras

Table of Contents

Introduction

Offering a CCTV camera in India today is not as simple as proposing a resolution or a night vision range. STQC certification now decides whether a CCTV camera can legally be sold, installed, or replaced in the country.

From April 2026, cameras without this clearance cannot enter the Indian market at all. This guide explains what STQC certification considers, why it exists, and how it connects with a BIS certified camera.

What Is STQC Certification?

STQC certification is the government process that checks whether a CCTV camera meets India’s cybersecurity and quality standards before it can be sold. It applies to the camera hardware, the firmware running on it, and the way it communicates over a network.

Without this certification, a camera simply cannot be marketed, imported, or supplied for new installations in India. Put simply, and STQC ready camera is one that has already cleared this government testing process, and no CCTV product can claim to be a BIS certified camera without going through it first.

What Does STQC Stand For?

STQC stands for Standardisation Testing and Quality Certification. It is a directorate under the Ministry of Electronics and Information Technology, commonly known as MeitY. STQC has been testing electronic products since 1991, but its role in surveillance equipment became critical only after the government introduced Essential Requirements for CCTV cameras in 2024. The STQC camera testing process now sits at the centre of India’s surveillance compliance framework.

Why STQC Certification Matters for CCTV Cameras?

A camera connected to the internet is also a device that can be attacked. Weak firmware, default passwords, and unencrypted video feeds have all been used in the past to break into surveillance systems. STQC certification matters because it forces manufacturers to close these gaps before the product reaches the market. For buyers, it means the camera has actually been tested against real attack methods rather than just marketed securely.

STQC Certification vs BIS Certification: What’s the Difference?

STQC certification and BIS certification differ from one another. STQC testing looks at components of cybersecurity behavior, like the management of passwords, signing firmware, and the transmission of encrypted communication. BIS certification, seen under the Compulsory Registration Order, requires product registration and safety compliance of a product against certain standards, such as IS 13252.

In practice, a camera needs to pass STQC testing before it becomes eligible for BIS registration. So a genuinely compliant CCTV camera carries both approvals, not just one, and is correctly described as a BIS certified camera only once both processes are complete.

Why STQC Certification Has Become Mandatory in India

To address emerging security issues and fortify cybersecurity and supply chain transparency, India has made STQC certification for CCTV cameras compulsory. This protects critical infrastructure for surveillance.

Government Regulations Driving Compliance

The Essential Requirements for the Security of CCTV Cameras, or ER 01 were introduced in the March 2024 Gazette notification and outline CCTV security standards. This notification was introduced in response to security concerns regarding devices using foreign chipsets security agencies were concerned the chipsets may have allowed the cameras to send data to servers located outside of India.

It was also revealed that about one million CCTV cameras that supply Indian government institutions were sourced from Chinese companies, and this also contributed to the government taking action. STQC certification became the mechanism to verify that new cameras entering the market do not carry these risks.

Impact on CCTV Manufacturers, OEMs, and System Integrators

Manufacturers now have to build cybersecurity into the product from the design stage instead of adding it later. OEMs supplying components must disclose chipset origin, since products with certain foreign-origin chips are being refused certification. System integrators face different pressures. BIS certification and STQC certification must be confirmed prior to quoting on a project, as big losses may occur if non-compliant CCTV cameras are used. One example is an integration company who lost weeks of project time after thousands of their imported CCTV cameras were detained by customs due to a lack of STQC clearance. Compliance is critical to all businesses.

Deadlines and Compliance Requirements

The compliance deadline was a phased deadline. From April 2025, new BIS licenses without ER 01 Cybersecurity compliance started to be issued. The final and most absolute compliance date was set for April 1st, 2026. After this date, CCTV cameras that do not have STQC certificate cannot be produced, imported, or sold.

While compliant cameras can continue to be operational, all new projects and replacements must also include compliant models. By early 2026, only a small handful of manufacturers cleared the STQC certification testing, while a number of large international manufacturers were not on the list of compliant manufacturers, making compliant cameras even more difficult to acquire.

Building an STQC-Compliant Camera?
Design secure, certification-ready surveillance solutions with Silicon Signals' embedded camera engineering expertise.

Which CCTV Cameras Require STQC Certification?

STQC certification regarding surveillance, does not apply to a particular type of camera, but rather across the surveillance category. ER 01, in this sense, would cover any device that connects to the internet, records footage, and transmits it.

Which CCTV Cameras Require STQC Certification
IP Cameras

IP cameras are the primary target of this regulation because they connect directly to networks and often to the cloud. Every IP camera model, including budget and enterprise variants, needs its own STQC camera approval before sale, since certification is granted per model rather than per brand.

PTZ Cameras

PTZ (Pan-Tilt-Zoom) cameras also require STQC certification. Due to their motorized movement, zoom functions, and more complex firmware, they undergo the same cybersecurity evaluation along with additional checks for secure firmware, authentication, and communication protocols.

Dome, Bullet, and Turret Cameras

Dome, bullet, and turret are three types of housing that an IP camera may have, but the requirement for certification stays the same irrespective of the shape. Regardless of whether the camera is installed inside or outside the building or on the perimeter, each of the network cameras – dome, bullet, or turret – has to satisfy the requirements of ER 01 and get STQC certification.

NVRs, DVRs, and Other Surveillance Devices

Recording devices such as NVRs and DVRs are covered as well, since they store footage and often expose remote access features. A fully compliant surveillance setup needs a certified STQC camera paired with certified recording hardware, or the security chain breaks the recorder.

6 Essential STQC Certification Requirements for CCTV Cameras

For STQC certification, CCTV cameras must fulfill a range of requirements concerning cybersecurity and software integrity, as per the framework of Essential Requirements (ER 01).

  1. Cybersecurity Requirements STQC certification mainly verifies the capability of the camera to withstand different types of cybersecurity attacks. This could be tested using default username, unpatched firmware, and exposed network ports that make the device vulnerable for remote attacks.
  2. Secure Boot and Firmware Protection Before executing firmware, the device must ensure that the firmware is genuine. Secure Boot would prevent tamper protection from loading, which stops firmware replacement attacks.
  3. User Authentication and Password Policies Shared or default passwords, such as “admin/admin,” are no longer permissible. Each device must mandate the creation of a unique password during the initial configuration, and the device must implement an active/passive protection mechanism of passwords.
  1. Secure Communication and Data Encryption Video streams and control commands must travel through encrypted channels such as TLS or HTTPS. Unencrypted feeds sitting on a local network, visible to anyone who intercepts traffic, do not meet the requirements.
  2. Vulnerability Assessment and Penetration Testing STQC labs run simulated attacks against the camera to check how it responds. This vulnerability assessment and penetration testing step is where many devices fail, since it exposes weaknesses that basic functional testing would miss entirely.
  3. Logging, Audit Trails, and Software Updates A compliant surveillance camera is required to record tries to access the camera and record changes in the configuration with logs for the admin. It is required to have a mechanism for secure software updates to apply security updates without compromising the device. This is one of the verifications that segregate a real STQC camera hardware design from a device that only claims in the marketing to be compliant.

How BIS Certification and STQC Certification Work Together

While STQC and BIS certifications are meant for different purposes, they are both mandatory for manufacturing, importing, and selling compliant CCTV cameras in India.

Understanding the Role of BIS

BIS, the Bureau of Indian Standards, manages the registration side of compliance. It issues the licence number that allows a product to be legally sold, and it depends on STQC test reports to confirm the cybersecurity portion of that approval.

Why Both Certifications Are Important

STQC certification without BIS registration means the product still cannot be sold legally. BIS registration without valid STQC test results is no longer accepted either, since old BIS certificates for non-compliant models have been withdrawn. Both approvals now move together as one compliance requirement.

Common Reasons CCTV Cameras Fail STQC Testing

Many CCTV cameras fail STQC evaluation due to preventable security weaknesses, outdated software, or incomplete technical documentation that does not meet ER 01 requirements.

Weak Password Management

Many camera models still arrive with shared default logins or allow blank passwords during setup. STQC labs flag this immediately, since it is one of the most common entry points attackers use to take over surveillance systems remotely without any real effort.

Insecure Firmware

Firmware that lacks digital signing or allows unauthorised updates fails the secure boot check. Some manufacturers reuse older firmware builds across models without revalidating them, which means known vulnerabilities carry forward into new products and cause certification failures.

Missing Security Features

Cameras that lack essential features, such as encrypted communication or account lock-out after a specified number of failed login attempts, will not clear STQC testing. In the case of the above cameras, these features are considered basic requirements. The absence of any of these features will result in an automatic rejection during evaluation.

Outdated Software Components

Devices running old operating system libraries or outdated network stacks often carry publicly known vulnerabilities. STQC evaluators check component versions against known vulnerability databases, and outdated software is one of the fastest ways a model gets sent back for correction.

Improper Documentation

Manufacturers can occasionally submit partially filled technical files. Some details like source of chipsets, firmware versions, or hash values can be absent. Documentation to get STQC certification must be exactly how it is in the physical product. Gaps in documentation or mismatches in documentation often result in delays and rejections of applications.

Need Help with STQC-Ready Camera Development?
From hardware to secure firmware, we help OEMs accelerate STQC compliance.

How Manufacturers Can Prepare for STQC Certification

For STQC certification, grasping the importance of cybersecurity is essential for manufacturers. Treatments for cybersecurity risks must be integrated in the entire course of product development, testing, and documenting the product rather than treating compliance as the final step.

Build Security into Product Development

The cost of integrating cybersecurity increases significantly when security is addressed late in the product development cycle. To simplify STQC certification for cameras, manufacturers should incorporate features such as strong authentication, encryption, secure boot, and secure firmware updates from the initial design stage instead of adding them just before.

Perform Internal Security Testing

Identifying vulnerabilities in the product internally helps to address security in the product development early. Many companies have begun to replicate the STQC certification process and assessment within the organization, leading to a reduction in the time for the STQC certification process and submission with reduced rejection rates.

Keep Firmware Updated

Devices must be continually maintained to prevent libraries in firmware and components in firmware from becoming obsolete and unpatched. A device that has been certified today may lose certification tomorrow. Maintaining certification matters as much as the initial certification.

Maintain Complete Technical Documentation

Accurate records of chipset origin, firmware version, and hash values should be maintained from day one. Clean documentation speeds up both STQC certification and BIS registration, and it becomes essential if a manufacturer later applies for series of certification across multiple models.

Conclusion

STQC certification is now a critical mandatory need for all CCTV cameras that are to be introduced in the Indian market. In line with the continuous evolution of cybersecurity regulations, security needs to be integrated into products during the initial phases of product development, while buyers and system integrators need to verify both STQC certification and BIS certification prior to deployment. Silicon Signals provides its expertise in helping OEMs and surveillance product manufacturers design and develop STQC certified camera platforms.

About the Author

Picture of Rutvij Trivedi
Rutvij Trivedi
Rutvij Trivedi is an Architect with Decades of Embedded Product Engineering, Software, and System Development. He has led Fortune 500 projects across Automotive, Consumer Electronics, Aerospace, IoT, Healthcare, and Semiconductor industries and is Upstream contributor in projects like Linux and Zephyr OS for multimedia