On November 28, 2025, India’s Department of Telecommunications (DoT) issued a formal directive mandating active SIM linkage for application-based communication platforms. The order applies to services such as WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat, and Josh.
- Commonly referred to as SIM binding, this requirement enforces a one-to-one association between a user account and an active mobile SIM.
- In practical terms, access to these platforms is permitted only when the registered SIM is present in the device and operational, thereby restricting anonymous usage and limiting unrestricted multi-device access.
- The objective of the directive is to improve user traceability across digital communication channels while aligning application ecosystems with India’s national security, lawful interception, and data protection frameworks.
In the sections ahead, we break down what is SIM binding and why the DoT has made it mandatory for application-based communication platforms.
What is SIM Binding?
SIM Binding is a mobile app security technique that cryptographically ties an installed app to a specific SIM card on a device. By validating SIM identifiers during runtime, the app ensures requests originate from the same subscriber identity, reducing fraud, account takeover, and bot abuse. If the SIM changes, sensitive actions are blocked or re-verified.
Example: a banking app binds login sessions to the user’s SIM; when a fraudster clones credentials but uses a different SIM, transactions fail until step-up verification completes. This makes SIM Binding effective against SIM-swap attacks while preserving seamless user experience for legitimate users, globally scalable.
Department of Telecommunication’s Directive on SIM Binding
The directive was issued under the Telecommunications (Telecom Cyber Security) Amendment Rules, 2025, and is applicable to entities designated as Telecommunication Identifier Entities (TIEUs).
This designation brings certain over-the-top communication platforms, such as WhatsApp, Telegram, etc., within the regulatory scope, insofar as they generate, manage, or authenticate telecommunication identifiers as defined under the Rules. As a result, these platforms fall under the compliance obligations set out by the Department of Telecommunications (DoT).
- Meeting the requirements of the directive would necessitate app-based communication services to technically validate the presence of a user’s SIM by accessing the International Mobile Subscriber Identity (IMSI) associated with the SIM card.
- This enables enforcement of active SIM linkage and ensures that user access remains tied to a valid and verifiable telecom identifier.
The directions require app-based communication services to implement the following mandatory controls:
- Continuous SIM linkage: The application must remain persistently bound to the SIM card associated with the mobile number used for user identification, service provisioning, or delivery. Access to the service must be technically restricted if that specific SIM is not installed and active in the device, thereby preventing usage independent of the linked SIM.
- Periodic web session termination: Where a web or desktop version of the mobile application is offered, such sessions must be automatically logged out at defined intervals, no later than every six hours. Users may be permitted to re-establish access only through a fresh device re-linking process, such as QR code-based authentication, to ensure continued verification of SIM presence.
Note:
- The mandated controls must be implemented within 90 days from the date of issuance of the directions. And a formal compliance report detailing the measures adopted must be submitted to the relevant authority within 120 days.
- For users travelling internationally, service continuity will not be affected provided the SIM card linked to the account remains physically present in the handset and is operating on international roaming.
Need for Department of Telecommunication’s SIM Binding Directions
The DoT observed that certain app-based communication services utilising mobile numbers (Indian) for user identification, service provisioning, or delivery continue to remain accessible even when the associated Subscriber Identity Module (SIM) is not present in the device on which the application is operating.
This architectural gap enables users to consume services without an active, in-device SIM and has been increasingly misused to carry out cyber-frauds, particularly by entities operating from outside India. The DoT’s SIM-binding mandate directly addresses this structural mobile app security gap.
- Currently, accounts on messaging and calling applications often remain active even after the associated SIM is removed, deactivated, or used abroad.
- This enables anonymous and large-scale fraud operations, including remote scam campaigns, Digital Arrest frauds, and impersonation of government authorities using Indian mobile numbers.
- Compounding the risk, long-lived web and desktop sessions allow fraudsters to retain control of compromised accounts without access to the original SIM or device. An account can be authenticated once on a device within India and then continue operating indefinitely from overseas locations, without any subsequent verification. This significantly weakens traceability, delays enforcement action, and makes coordinated takedowns far more complex.
By enforcing active SIM linkage, the DoT aims to ensure that continued access to communication platforms remains tied to a valid, present SIM, thereby reducing anonymity, curbing cross-border misuse, and strengthening the overall integrity of India’s digital communication ecosystem.
SIM Binding: Indian Landscape
In India, SIM binding is not a new security concept. For instance, SIM Binding RBI Guidelines, the detailed directives laid out by the Reserve Bank of India (RBI), mandate Device & SIM binding for mobile banking apps.
- Public sector banks such as State Bank of India introduced SIM-linked access controls for their mobile banking applications as early as 2021, with most other banks subsequently adopting similar safeguards.
- The same approach was reinforced at a regulatory level when Securities and Exchange Board of India (SEBI) released a consultation paper in February 2025 proposing SIM binding as a measure to strengthen the security of trading and demat accounts; and reduce the risk of unauthorised transactions.
- Mechanisms such as device binding and automatic session expiry are already standard across banking and payment applications to mitigate threats including account takeover, session hijacking, and access from untrusted or remote devices.
Extending these proven controls to app-based communication platforms is a logical progression, given that these platforms have increasingly become primary vectors for cyber-fraud, social engineering, and identity misuse.
SIM Binding: Global Landscape
Although continuous SIM binding at the application level is not universally mandated, more than 160 countries enforce mandatory SIM registration, requiring users to submit valid identification at the time of SIM issuance.
These measures are designed to reduce telecom-enabled fraud and improve the ability of law enforcement agencies to trace criminal activity. In some jurisdictions, regulators have adopted alternative approaches, including biometric-based user authentication, to achieve similar accountability outcomes.
A frequently cited example is Nigeria, where regulators have mandated the linkage of SIM cards to a subscriber’s National Identification Number. This policy has reportedly strengthened oversight, reduced fraudulent usage, and improved the traceability of crimes facilitated through telecom networks.
While these models differ in implementation from continuous SIM binding enforced within applications, they collectively underscore a global regulatory direction: anchoring mobile identities to verifiable, real-world credentials to limit anonymity, deter misuse, and reduce the scale of illicit digital activity.