Amazon and Walmart-owned Flipkart have begun reviewing internet-connected security camera listings on their Indian storefronts after a Reuters analysis found that the overwhelming majority of those products are not on the Bureau of Indian Standards register of approved models. The review began this week, six months after a certification mandate that was supposed to clear uncertified cameras off the Indian market entirely.
The scale of the gap is the story. Reuters examined roughly 770 internet security camera listings across the two platforms and found more than 700 of them were for models that did not appear on the BIS public database of approved brands or cameras, according to the report published on October 2. That is more than nine in ten listings for a product category that India placed under a hard sale ban on April 1, 2026.
Both companies have started pulling listings. At least a dozen have come down since Tuesday, September 29, including at least two models sold under Hikvision’s EZVIZ brand, which Amazon’s Indian site now shows as currently unavailable. For a $4.4 billion category in which Chinese vendors hold roughly a third of the market, a serious enforcement push would reset who is allowed to sell cameras in India at all.
In short
- More than 700 of roughly 770 internet security camera listings on Amazon India and Flipkart were for models absent from the BIS approved-products database, per the Reuters analysis published October 2, 2026.
- The rule took full effect on April 1, 2026, after MeitY withdrew the remaining Essential Requirements exemptions in a January 16, 2026 office memorandum. It binds manufacturers, importers and distributors alike.
- Enforcement has started at the listing layer, not the border. At least a dozen products came down from Tuesday, including EZVIZ models, with platform-led reviews rather than a regulator-ordered sweep.
- The exposure runs through the BIS Act, 2016, where a first contravention carries up to two years imprisonment or a fine of at least INR 200,000, and repeat breaches reach ten times the value of the goods.
- India is now the strictest large market on surveillance hardware sold to consumers, going further than the US federal procurement bans and the UK guidance that cover government buyers only.
What the Reuters analysis actually found
The finding is narrow and verifiable, which is what makes it awkward for the platforms. Reuters reporters Aditya Kalra and Munsif Vengattil matched roughly 770 live listings for internet-connected security cameras against the BIS public database of registered brands and models. More than 700 did not match.
That does not automatically mean every one of those 700 models is illegal to sell. A model can be in testing, can be registered under a parent entity name that does not match the storefront brand, or can be mislabelled on the listing itself. What it does mean is that a buyer, or a regulator, cannot confirm compliance from the public record, which is the entire point of a compulsory registration regime.
The examples named in the reporting are not fringe sellers. Maizic Smarthomes, an Indian smart-home brand, had 138 WiFi camera offerings live on Amazon. A Dahua wireless dome camera was listed at INR 779 after a 70% discount, which works out to about USD 8.10 at roughly 96.3 rupees to the dollar on October 2. Cameras at that price point are exactly the volume segment that compliance testing was meant to clean up.
Maizic co-founder Santosh Kumar Singh said the brand is committed to full compliance with government laws and regulations, and that the company has removed WiFi connectivity from affected units and will enable direct mobile device access only after government approval. That is a revealing workaround: stripping the network radio out of a camera moves it outside the Essential Requirements perimeter, because the perimeter is defined by connectivity.
Indian enforcement against uncertified goods has historically been physical. BIS officers raid a warehouse, seize cartons, and open proceedings against the entity whose name is on the paperwork. That model works for kettles and water heaters and it has been used against both platforms before.
Connected cameras break the model, because the compliance object is the firmware and the cloud link, not the plastic housing. A seized carton tells an inspector nothing about whether the device encrypts its video stream or ships with a hardcoded password. The listing database, cross-referenced against the registration database, is a faster and cheaper detection method than any raid.
That is why the Reuters method is likely to be copied. Any journalist, competitor or regulator can now run the same join against the public register. Platform compliance teams should assume this check becomes routine rather than exceptional.
What India’s CCTV rule actually requires
India did not pass one law on surveillance cameras. It stacked two separate regimes on top of each other, and the second one is the binding constraint.
The Compulsory Registration layer
Through a gazette notification dated April 9, 2024, CCTV cameras were brought under the Compulsory Registration Order, the framework administered by the Bureau of Indian Standards. Under a Compulsory Registration Scheme category, a product cannot lawfully be sold, stored or displayed for sale in India unless the model is registered and carries the standard mark.
Registration is model-specific, not brand-specific. A vendor with fifteen SKUs needs fifteen registrations, and a firmware or hardware revision can require a fresh submission. This is the mechanical reason a brand can be legitimate and still have most of its catalogue unregistered.
The Essential Requirements layer
On top of registration sits a cybersecurity test. The Ministry of Electronics and Information Technology defines a set of Essential Requirements covering secure firmware, encrypted communication and tamper protection, and the Standardisation Testing and Quality Certification directorate validates compliance under the IoT System Certification Scheme.
Exemptions to this layer were progressively withdrawn. A MeitY office memorandum dated January 16, 2026 removed what remained, and from April 1, 2026 only cameras that meet the Essential Requirements and hold valid certification may be sold in India. The memorandum applied the rule uniformly across domestic manufacturers, importers and distributors, which closed the usual argument that a local assembler sits outside an import rule.
The sequencing explains the confusion in coverage of this story. The category was added to the compulsory framework in 2024, but the cybersecurity test only became unavoidable in April 2026, which is the “six months ago” marker in the Reuters report. Readers checking the registration status of a camera can query the registered-products database on the Bureau of Indian Standards site directly.
| Date | Instrument | What it changed |
|---|---|---|
| April 9, 2024 | Gazette notification | CCTV cameras added to the Compulsory Registration Order; model-level BIS registration becomes the baseline |
| 2024 to 2025 | Phased exemptions | Essential Requirements testing applied with carve-outs, allowing significant volumes to continue shipping |
| January 16, 2026 | MeitY office memorandum | All remaining Essential Requirements exemptions withdrawn |
| April 1, 2026 | Hard compliance date | Sale of non-conforming cameras prohibited for manufacturers, importers and distributors |
| October 2, 2026 | Reuters analysis | 700+ of roughly 770 listings found outside the approved-model database; platform reviews begin |
Why the compliance gap survived six months
Six months is a long time for a near-total compliance failure to persist in a category this visible. Three structural reasons are doing most of the work.
Certification throughput versus catalogue size
Security camera catalogues on Indian marketplaces run to thousands of SKUs across hundreds of brands, many of them white-labelled from the same handful of Shenzhen contract manufacturers. Each one needs its own test cycle through a conformity assessment body, and testing capacity does not scale on demand. A regime that requires model-level certification against a long-tail catalogue will generate a backlog unless the enforcement date is pushed, and in this case it was not.
The economics make it worse at the bottom of the price curve. A camera retailing near INR 779 cannot absorb much testing cost per model, so the rational move for a thin-margin seller is to keep listing and hope detection is slow. Until this week, that bet was paying off.
Marketplaces are not the importer of record
On a marketplace model, the seller imports and the platform lists. The platform’s duty under the Consumer Protection (E-Commerce) Rules, 2020 is to verify seller details, obtain undertakings that product descriptions are accurate, and exercise due diligence, not to independently certify every SKU. That division of labour has been contested for years and it is the same fault line running through India’s broader marketplace rulemaking, including the 30-day price test that Amazon and Flipkart face under the amended e-commerce rules.
The weakness is that a seller undertaking is a piece of paper. If a seller attests that a camera is compliant and it is not, the platform has nominally done its job while the uncertified device still reaches a consumer. A register-matching check closes that gap, and nothing in the current rules required the platforms to run one.
The third reason is the most banal and probably the most important. The approved-model register and the live catalogue are both public, and until someone ran the join at scale the mismatch was invisible to everyone except the sellers who knew their own status.
Listing velocity compounds all three. Indian marketplaces onboard new camera SKUs continuously through the run-up to the festive quarter, and a seller can create a variant listing in minutes while a certification cycle runs for weeks. A compliance process that moves slower than the catalogue it governs will drift out of alignment by default, not by intent.
What the platforms have done since Tuesday
The response so far is measured rather than wholesale. At least a dozen listings have been removed since Tuesday, September 29, out of a set of more than 700 flagged. Two of the confirmed removals are EZVIZ models, the consumer sub-brand of Hikvision, which Amazon’s Indian storefront now marks as currently unavailable.
Neither platform has announced a blanket delisting of unregistered models, and neither has published a compliance deadline for sellers. Reuters reported that a confidential email from July touched on the certification issue, which suggests internal awareness predated the public finding by several months.
The gradualism is commercially rational and legally risky in equal measure. Pulling 700 listings at once would strip a large share of a $4.4 billion category off two of India’s biggest storefronts ahead of the festive quarter. Leaving them up after a published finding of non-compliance makes any later claim of ignorance harder to sustain.
The arithmetic of a full sweep is worth stating plainly. If more than 700 of roughly 770 listings are unmatched, a complete removal leaves a camera category of perhaps 70 live products across both platforms combined, concentrated in whichever brands certified early. That is not a trimmed catalogue; it is a different market, and it would hand an immediate share advantage to the handful of vendors that treated the April deadline as real.
A partial sweep carries its own problem. Removing only the models named in press coverage invites the reading that the trigger was publicity rather than compliance, which is a weaker position to hold if a regulator later asks why the other listings stayed up for another quarter.
What the exposure looks like in rupees
The penalty architecture here is not trivial, and it applies to sellers, importers and distributors rather than only to manufacturers.
The BIS Act penalty ladder
Section 17 of the BIS Act, 2016 prohibits the sale, storage or display for sale of goods in a mandatory category without the standard mark. Section 29 supplies the penalties. A first contravention carries imprisonment of up to two years, or a fine of not less than INR 200,000, or both.
Repeat exposure escalates sharply. For a second and subsequent contravention the fine is not less than INR 500,000 and can extend to ten times the value of the goods, alongside the imprisonment exposure. On a warehouse of low-cost cameras, the ten-times multiplier is the number that matters, because it detaches the penalty from a fixed cap and ties it to inventory value.
| Breach | Fine floor | Fine ceiling | Custodial exposure |
|---|---|---|---|
| First contravention | INR 200,000 (about USD 2,080) | Discretionary | Up to 2 years |
| Second and subsequent | INR 500,000 (about USD 5,190) | Up to 10x the value of goods | Up to 2 years |
| Aggravated cases under Section 29(3) | Reported at up to INR 1,000,000 | Up to 10x the value of seized goods | Up to 3 years |
Dollar conversions use roughly 96.3 rupees to the dollar as of October 2, 2026. The practical risk for a large platform is rarely the fine itself; it is the seizure, the proceeding, and the executive named in it.
Safe harbour and the e-commerce rules
The second exposure is reputational and procedural. A marketplace entity cannot rely on the intermediary safe harbour in Section 79(1) of the Information Technology Act, 2000 unless it has observed the due diligence obligations that attach to it. The Consumer Protection (E-Commerce) Rules, 2020 layer on verification duties, including seller identity and GST registration, and undertakings on the accuracy of product descriptions.
A published finding that more than nine in ten listings in a regulated category sat outside the approved register is the kind of fact a consumer regulator can build a due diligence case around. Indian authorities have shown appetite for exactly this: the same regulatory current is visible in the way India’s e-commerce rules are being pointed at quick commerce ahead of the 2027 compliance dates.
Precedent: BIS has raided these warehouses before
This is not the first time either platform has been found carrying uncertified goods in India. In February and March 2025, BIS officers ran search and seizure operations at warehouses used by both companies.
At an Amazon facility in Lucknow on March 7, 2025, officers seized 215 toys and 24 hand blenders, all lacking BIS certification. A Gurugram operation the previous month took 58 aluminium foils, 34 metallic water bottles, 25 toys, 20 hand blenders, 7 PVC cables, 2 food mixers and 1 speaker. At a Flipkart-linked Instakart Services warehouse in Gurugram, officers seized 534 stainless steel vacuum-insulated bottles, 134 toys and 41 uncertified speakers.
Tracing those products upstream led BIS to a Delhi supplier, Techvision International, where officers seized 7,000 electric water heaters, 4,000 electric food mixers, 95 electric room heaters and 40 gas stoves. BIS said at the time that it had initiated proceedings under the BIS Act, 2016 to hold responsible entities accountable.
The pattern is instructive. Enforcement reached the warehouse and the upstream supplier, not the listing. Cameras invert that, because the defect is in software and the evidence is in a database.
How India compares with the US, UK and EU
Western restrictions on Chinese surveillance vendors are better known than India’s rule but considerably narrower in who they bind. Almost all of them are procurement rules aimed at government buyers.
In the United States, Section 889 of the 2019 National Defense Authorization Act bars federal agencies from procuring or obtaining video surveillance equipment produced by Hikvision or Dahua, including OEM-rebadged units, covering the military and overseas missions. In November 2022 the Federal Communications Commission went further on the hardware side, adding both companies to the Covered List and barring new equipment authorizations.
The United Kingdom issued guidance in November 2022, with then-cabinet minister Oliver Dowden instructing departments to stop installing cameras made by companies subject to Chinese security laws on sensitive sites, to disconnect such devices from core networks, and to consider removal. The European Union has no bloc-wide policy; the European Parliament removed Hikvision equipment from its own premises and Denmark has issued national restrictions.
| Jurisdiction | Instrument | Who it binds | Consumer sales affected |
|---|---|---|---|
| India | BIS CRO plus MeitY Essential Requirements, effective April 1, 2026 | Manufacturers, importers, distributors, sellers | Yes, all sales |
| United States | NDAA Section 889 (2019); FCC Covered List and authorization ban (Nov 2022) | Federal procurement; new equipment authorizations | Partially, via authorization bar on new models |
| United Kingdom | Government guidance, November 2022 | Central government departments and sensitive sites | No |
| European Union | No bloc-wide rule; Parliament removal, Danish national restrictions | Specific institutions and member states | No |
India’s rule is the outlier because it is a market access rule rather than a procurement rule, and because it is vendor-neutral on its face. A camera made in Noida fails the same test as a camera made in Hangzhou if the firmware does not clear the Essential Requirements.
Why India wrote the rule, and who it hits
The policy rationale is espionage and network intrusion rather than product safety in the conventional sense. Gulshan Rai, who served as India’s national cyber security coordinator from 2015 to 2019, framed the risk plainly: a compromised camera can become both a surveillance risk and a cybersecurity entry point.
That framing is specific. A connected camera is a persistent inbound video feed and an always-on device inside a home or office network, which makes it attractive both for direct surveillance and as a foothold for lateral movement. Unlike a kettle, it fails in two directions at once.
Indian authorities have a domestic case to point to. Reporting on the 2024 Delhi police investigation into a Pakistan-linked spying network described the use of Chinese-made CCTV cameras positioned near military sites. Whatever the eventual legal outcome, that case is what turned a technical standards question into a national security one.
The concern about hardware sourced from a single geography is not confined to cameras. The same supply-chain logic sits behind the Section 232 drone tariffs that landed on thermal and consumer units in September, where sensor hardware and firmware provenance drove the policy rather than price.
Hikvision and Dahua together held roughly 30% of India’s security camera market in 2025, according to Counterpoint Research, in a category valued at about $4.4 billion. A strictly enforced certification regime does not ban them, but it does force every model through an Indian cybersecurity test and onto a public register.
Two outcomes follow from that. The first is a catalogue contraction: vendors will register their volume SKUs and quietly retire the long tail, because the per-model economics do not work below a certain price. The second is a share shift toward whoever certifies fastest, which favours domestic manufacturers with local testing relationships and larger multinationals with compliance budgets.
The Maizic response hints at a third path. Removing WiFi connectivity moves a device outside the connected-camera perimeter and back into a simpler product class, at the cost of the feature consumers actually buy these cameras for. Expect a wave of stripped-down variants if certification queues stay long.
None of this reads as protectionism on the face of the instrument, which matters for how durable the rule is. A market access measure framed as a cybersecurity standard, applied identically to domestic and foreign producers, is harder to challenge as a disguised trade barrier than a tariff line or an origin-based ban. That design choice is becoming common in hardware categories where the policy concern is firmware rather than price.
For retailers outside India, the signal is the method rather than the market. A government that publishes a machine-readable register of approved models has effectively outsourced detection to anyone willing to run a query, and the cost of being caught on the wrong side of that query falls almost entirely on the listing platform and the seller.
What marketplace and retail operators should do now
The operational lesson generalises well beyond India and beyond cameras. Any category placed under a public registration regime becomes machine-auditable the moment the register is published, and the audit will be run by someone outside the company.
- Run the join yourself. Match every live SKU in a regulated category against the relevant public register, on a schedule, and treat an unmatched listing as a defect rather than an open question.
- Capture the certificate, not the attestation. A seller undertaking that a product is compliant is worth less than a certificate number that resolves in a public database.
- Map the perimeter precisely. Connectivity, firmware version and intended use often define whether a rule bites, and a hardware-only view of a catalogue will miss the trigger.
- Price the compliance cost into category strategy. If per-model certification costs more than the annual margin on a long-tail SKU, that SKU should be retired deliberately rather than delisted under pressure.
- Watch adjacent regimes. Payments, pricing and product compliance rules are arriving on overlapping clocks in India, including the 0.4% UPI merchant fee that starts on October 15.
What to watch next
Three signals will show whether this becomes an enforcement event or a news cycle. The first is volume: whether removals move from roughly a dozen into the hundreds within the next two to three weeks, which would indicate a systematic sweep rather than a targeted response to named examples.
The second is whether BIS or the Ministry of Consumer Affairs opens a formal proceeding against either platform or against named sellers. A warehouse action would follow the 2025 template; a listing-level direction would be new and would set a far more consequential precedent for marketplace liability in India.
The third is timing against the festive quarter. India’s biggest online sales period runs through October and November, and a category-wide delisting during it carries a revenue cost that a January delisting would not. Regulators elsewhere have shown they will press platform cases through commercially inconvenient windows, as the Korea Fair Trade Commission’s escalating Coupang investigation has demonstrated.
For sellers, the practical window is already closing. The compliance date passed on April 1, the public finding landed on October 2, and the defence that nobody knew the register existed is no longer available to anyone.
Frequently asked questions
What did Reuters find on Amazon and Flipkart?
Reuters matched roughly 770 internet-connected security camera listings on Amazon India and Flipkart against the Bureau of Indian Standards public database of approved brands and models. More than 700 of those listings were for models that did not appear on the register. The analysis was published on October 2, 2026.
When did India’s CCTV certification rule take effect?
CCTV cameras were brought under the Compulsory Registration Order by a gazette notification dated April 9, 2024. The binding cybersecurity requirement came later: a MeitY office memorandum of January 16, 2026 withdrew the remaining Essential Requirements exemptions, and from April 1, 2026 only certified, conforming cameras may be sold in India.
Does the rule only apply to Chinese brands?
No. The requirement is vendor-neutral and applies uniformly to domestic manufacturers, importers and distributors. A locally made camera must clear the same Essential Requirements testing as an imported one. In practice the impact concentrates on Chinese vendors because Hikvision and Dahua together held about 30% of the Indian market in 2025, per Counterpoint Research.
How many listings have actually been removed?
At least a dozen since Tuesday, September 29, 2026, according to the reporting. That includes at least two EZVIZ models, Hikvision’s consumer sub-brand, which Amazon’s Indian site now shows as currently unavailable. Neither platform has announced a blanket removal of unregistered models.
What penalties can sellers face?
Under Section 29 of the BIS Act, 2016, a first contravention carries imprisonment of up to two years, a fine of not less than INR 200,000, or both. For second and subsequent contraventions the fine is not less than INR 500,000 and can extend to ten times the value of the goods. Section 17 separately prohibits sale, storage or display for sale without the standard mark.
Are the marketplaces themselves liable?
That is the open question. Under the Consumer Protection (E-Commerce) Rules, 2020 a marketplace must verify seller details and obtain undertakings on product accuracy, and it cannot claim the intermediary safe harbour in Section 79(1) of the IT Act, 2000 without observing due diligence. Whether a register-matching check is part of that due diligence has not been tested.
How does this compare with the US and UK bans on Hikvision and Dahua?
The US and UK measures are procurement rules. NDAA Section 889 bars federal agencies from buying Hikvision and Dahua video surveillance, and the FCC added both to its Covered List in November 2022, barring new equipment authorizations. UK guidance from November 2022 covers government departments and sensitive sites. India’s rule is broader in reach, because it governs all commercial sales rather than only public buyers.
Can a camera be sold if the manufacturer removes WiFi?
Potentially, because the Essential Requirements regime is scoped to connected devices. Maizic Smarthomes said it removed WiFi connectivity from affected units and will enable direct mobile device access only after government approval. The trade-off is that a camera without network connectivity loses the remote-viewing feature most consumers buy it for.
How can a buyer check whether a camera is certified?
The Bureau of Indian Standards maintains a public database of registered products and brands. Buyers can look up the specific model, not just the brand, because registration is granted model by model and a manufacturer can have some SKUs registered and others not. A listing that quotes a brand name without a resolvable model registration is the pattern the Reuters analysis flagged.