Framework National Cyber & Cloud Schemes
MeitY
In compliance lists "MeitY" refers to the cloud service provider empanelment run by India's Ministry of Electronics and Information Technology under the GI Cloud (MeghRaj) initiative.
A provider that wants to sell cloud services to Indian central and state government bodies applies for empanelment, demonstrates compliance with MeitY's empanelment requirements (which draw on ISO/IEC 27001, 27017, 27018, ISO 20000-1, and Indian requirements on data localization, government access, and exit management), and undergoes an audit by the Standardisation Testing and Quality Certification (STQC) Directorate.
Empanelled providers and their audited service offerings are listed on the MeghRaj portal, and government buyers can procure from the list without repeating foundational security checks. All three major hyperscalers and a dozen or so Indian providers hold empanelment (verify the current list on the MeitY portal).
In writing, a provider needs the ISO certificates and scope statements, a data center and service description with data residency evidence for India, a control matrix against the empanelment requirements, security and privacy policies, incident reporting procedures that meet government and CERT-In timelines, exit and portability terms, and the STQC audit report.
Empanelment is renewed periodically and services added later must be audited before listing.
help
Who has to comply
Cloud service providers seeking to supply Indian government departments, ministries, and public sector bodies, which are directed to procure from empanelled providers. Providers serving only private customers are not required to empanel.
What the assessor asks to see
Application and company information; ISO/IEC 27001, 27017, 27018, and ISO 20000-1 certificates with scopes; data center locations and data residency evidence; service catalog and architecture; control matrix against empanelment requirements; security and privacy policies; access control and logging; incident management and reporting procedures; business continuity and disaster recovery arrangements within India; exit management and data portability terms; STQC audit report and closure of findings.
Assessors
Who assesses MeitY
STQC Directorate auditors (a MeitY body) perform the empanelment audit; supporting ISO certifications come from accredited certification bodies. No private firm can grant empanelment. for the empanelment decision; ISO certificates used in support are issued by bodies accredited by NABCB or other IAF/Global ACI signatory accreditation bodies.
Public register of assessors: https://www.meity.gov.in/
No firm has claimed a MeitY assessor listing yet. Claim yours →
Consultants
Who helps with MeitY
Indian IT consultancies and the local arms of global firms assist with the application, ISO alignment, data center documentation, and STQC audit preparation. Timelines depend heavily on STQC scheduling and can run a year or more.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a MeitY consultant listing yet. Claim yours →
Software
Tools for MeitY
Tools that name this framework in their own material.
No firm has claimed a MeitY tool listing yet. Claim yours →
Related reading
- MeitY empanelmentSets out the empanelment route: MeitY compliance check, STQC audit of the data centres and offerings, then annual surveillance.Amazon Web Services
- MeitY (India) complianceShows which services an empanelment letter actually covers, and the ISO certifications that sit underneath it.Google Cloud
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for MeitY
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with MeitY
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.