Mobile App Security

Decoding the Department of Telecommunication’s (DoT) Directive on SIM Binding

India’s DoT mandates SIM binding for over-the-top communication platforms. Learn what is SIM binding, compliance timelines, and security implications.

By · · 5 Min

Decoding the Department of Telecommunication’s (DoT) Directive on SIM Binding

On November 28, 2025, India’s Department of Telecommunications (DoT) issued a formal directive mandating active SIM linkage for application-based communication platforms. The order applies to services such as WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat, and Josh.

In the sections ahead, we break down what is SIM binding and why the DoT has made it mandatory for application-based communication platforms.

What is SIM Binding?

SIM Binding is a mobile app security technique that cryptographically ties an installed app to a specific SIM card on a device. By validating SIM identifiers during runtime, the app ensures requests originate from the same subscriber identity, reducing fraud, account takeover, and bot abuse. If the SIM changes, sensitive actions are blocked or re-verified.

Example: a banking app binds login sessions to the user’s SIM; when a fraudster clones credentials but uses a different SIM, transactions fail until step-up verification completes. This makes SIM Binding effective against SIM-swap attacks while preserving seamless user experience for legitimate users, globally scalable.

Department of Telecommunication’s Directive on SIM Binding

The directive was issued under the Telecommunications (Telecom Cyber Security) Amendment Rules, 2025, and is applicable to entities designated as Telecommunication Identifier Entities (TIEUs).

This designation brings certain over-the-top communication platforms, such as WhatsApp, Telegram, etc., within the regulatory scope, insofar as they generate, manage, or authenticate telecommunication identifiers as defined under the Rules. As a result, these platforms fall under the compliance obligations set out by the Department of Telecommunications (DoT).

The directions require app-based communication services to implement the following mandatory controls:

Note:

Need for Department of Telecommunication’s SIM Binding Directions

The DoT observed that certain app-based communication services utilising mobile numbers (Indian) for user identification, service provisioning, or delivery continue to remain accessible even when the associated Subscriber Identity Module (SIM) is not present in the device on which the application is operating.

This architectural gap enables users to consume services without an active, in-device SIM and has been increasingly misused to carry out cyber-frauds, particularly by entities operating from outside India. The DoT’s SIM-binding mandate directly addresses this structural mobile app security gap.

By enforcing active SIM linkage, the DoT aims to ensure that continued access to communication platforms remains tied to a valid, present SIM, thereby reducing anonymity, curbing cross-border misuse, and strengthening the overall integrity of India’s digital communication ecosystem.

SIM Binding: Indian Landscape

In India, SIM binding is not a new security concept. For instance, SIM Binding RBI Guidelines, the detailed directives laid out by the Reserve Bank of India (RBI), mandate Device & SIM binding for mobile banking apps.

Extending these proven controls to app-based communication platforms is a logical progression, given that these platforms have increasingly become primary vectors for cyber-fraud, social engineering, and identity misuse.

SIM Binding: Global Landscape

Although continuous SIM binding at the application level is not universally mandated, more than 160 countries enforce mandatory SIM registration, requiring users to submit valid identification at the time of SIM issuance.

These measures are designed to reduce telecom-enabled fraud and improve the ability of law enforcement agencies to trace criminal activity. In some jurisdictions, regulators have adopted alternative approaches, including biometric-based user authentication, to achieve similar accountability outcomes.

A frequently cited example is Nigeria, where regulators have mandated the linkage of SIM cards to a subscriber’s National Identification Number. This policy has reportedly strengthened oversight, reduced fraudulent usage, and improved the traceability of crimes facilitated through telecom networks.

While these models differ in implementation from continuous SIM binding enforced within applications, they collectively underscore a global regulatory direction: anchoring mobile identities to verifiable, real-world credentials to limit anonymity, deter misuse, and reduce the scale of illicit digital activity.