
Abstract
Electronics and semiconductor supply chains form the bedrock of India’s Viksit Bharat 2047 vision and Make in India initiative. The global supply-chain architecture and electronics governance have been shaped by paradigm shifts in the geopolitical landscape that account for the sovereign vulnerabilities of import-dependent states. India’s exposure to hardware Trojans, malicious firmware, counterfeit components, and foreign supply-chain infiltration reveals a structural asymmetry that existing domestic laws have not fully addressed. This chapter examines the evolution of India’s legal framework for semiconductor and hardware security and proposes a sovereignty-centric “trusted electronics” architecture that aligns with the Make in India initiative and supply chain resilience. The research aims to fill three regulatory gaps: (1) inadequacies in Indian statutes governing dual-use technologies and hardware cybersecurity; (2) the unresolved interface between constitutional protections under Article 21, Union defence powers under Article 73, seventh schedule and India’s export-control commitments amid a geopolitical tense environment; and (3) the underserved legal relationship between Special Chemicals, Organisms, Material Equipment and Technologies (SCOMET) controls, India Semiconductor Mission initiatives, and national supply-chain resilience. The objectives of this research include: (i) mapping the alignment of India’s cybersecurity laws (Information Technology Act, CERT-In: Indian Computer Emergency Response Team, DPDP: Digital Personal Data Protection Act with defence powers and Wassenaar obligations; (ii) evaluate limitations within SCOMET Category 7 relating to reserved categories of semiconductors; (iii) assess institutional strengths of the India Semiconductor Mission (ISM); and (iv) propose a legal and institutional[AS1] blueprint “India Trusted Silicon Chain.” Through doctrinal analysis, the chapter argues that escalating hardware-layer threats demand sovereign-centric norms. India is uniquely positioned to lead in securing electronics autonomy, advancing the Viksit Bharat vision, while safeguarding long-term national cyber peace.
Initial Visible Summary of the Argument
The category 7 under the DGFT notification, for the first time brought emerging technologies, semiconductor manufacturing equipment, quantum, cryogenic, avionics, navigation, space-related electronics, software and technology, not just physical goods under the export control ambit. This mirrors Wassenaar’s dual-use categories 3, 6 and 7, especially navigation, avionics, sensors, and electronics which are recognized as civil-military technologies. The outcome is that Category 7 is no longer about trade classification, it is about strategic systems integrity.
The first type of argument suggests that the source of logic is systematic risk and not-item based risk. Wassenaar focuses on preventing destabilising accumulations and diversion risks, not punishing individual transactions. Additionally, Category 7 controls systems, components, software, and know-how, not just finished products. Argument that emerges is that strategic electronics create systematic risk because compromise at one node (chip, sensor, firmware, software update) propagates, across defence, aviation, telecom, and space infrastructure. This is a risk amplification logic, and not criminalisation.
Another set of argument is trust deficit in global electronics supply chains. The source logic is Wassenaar recognises that highly specialised, globally fragmented supply chains create diversion and misuse risks even in civilian contexts. The Category 7 explicitly covers: 1) test & production equipment, maintenance levels, software & technology transfers, and intangible technology (ITT) risks. The argument that emerges is that in advance electronics, origin, maintenance, software updates, and knowledge transfer matter as much as physical export. This sufficiently justifies licensing, end-use scrutiny, and trusted supplier framework.
To add more, hardware is no longer neutral to civil life. To map these outcomes to Article 21 plus Puttaswamy. Instead of saying Article 21 mandates export controls, the logical argument is that hardware-layer insecurity now directly affects the conditions of dignified digital life. The landmark Puttaswamy judgement recognises informational privacy, decisional autonomy, integrity of data ecosystems. But it must be noted that data integrity presupposes hardware integrity. When semi-conductors, sensors, avionics, and embedded systems mediate healthcare, transport, communications, and governance, their compromise threatens the informational and decisional autonomy protected under Article 21. This is a constitutional justification and not an enforcement mandate.
The mapping to the DPDP Act, 2023 assumes lawful processing, data fiduciaries, secure digital environments but remains agnostic to hardware provenance. The argument that emerges from this is that DPDP Act governs data governance, but cannot meaningfully without upstream assurance of hardware integrity in the devices that collect, transmit, and process personal data. Thus, it is safe to argue that SCOMET Category 7 fills a pre-legislative security gap. It complements the DPDP. This avoids jurisdictional conflict.
The map to Seventh Schedule (Union competence): The technologies in Category 7 touch defence, foreign trade, space, telecommunications, and international obligations and lie within the Union List. The argument that emerges is that because Category 7 technologies are dual-use, transboundary, and strategically sensitive, their regulation cannot be meaningfully decentralised without undermining the national security and international commitments. The Seventh Schedule thus legitimises union placement, pre-empts federal objections and grounds executive action. The mapping to Article 73 is executive authority. The invoking of Article 73 is indispensable because Wassenaar is politically binding, not self-executing, SCOMET updates are executive instruments and parliament has not enacted a single omnibus “hardware security law”. Article 73 enables the Union to operationalise international export control commitments and manage strategic technology risks through executive action, where legislative frameworks are necessarily adaptive and incomplete. This is textbook Article 73 use.
A part of the argument is the integration of sections 45-48 of the IT Act, 2000 coherently. It positions them as ex post, liability-based mechanisms. There is an addition of historical evolution narrative using the Indian Telegraph Act, 1885.
“Sections 45 to 48 of the Information Technology Act, 2000 collectively establish a remedial and adjudicatory framework designed to address contraventions and damages arising from unauthorised access to, or interference with, computer systems and digital networks. These provisions are fundamentally ex post in character: they presuppose the occurrence of a contravention, followed by adjudication, imposition of penalties, or compensation for loss. While this liability-based architecture plays an important role in cyber accountability, it is structurally ill-suited to address systemic and pre-emptive risks arising at the hardware and supply-chain level.
Section 45, in particular, functions as a residual penalty provision, capturing contraventions not otherwise specified under the Act. Its inclusion underscores the legislative intent to provide broad remedial coverage for digital misconduct; however, it remains anchored in a post-facto enforcement paradigm. Sections 46 to 48 further reinforce this orientation by institutionalising adjudication mechanisms, appellate review, and civil remedies, rather than preventive regulation.
The limitations of this approach become evident in the context of strategic electronics, semiconductors, and embedded systems, where vulnerabilities introduced upstream—through compromised components, firmware, or technology transfers—may result in large-scale systemic harm that cannot be meaningfully remedied after the fact. In such contexts, reliance solely on adjudicatory and compensatory mechanisms risks treating national-scale security failures as individualised cyber disputes.
Download the complete CWA Research Report, using the link: Trusted Electronics and Supply Chain Security: A Strategic Legal Blueprint for Viksit Bharat 2047


