The practical effect: Hikvision and Dahua, the two vendors that had been quietly running a substantial share of Indian commercial surveillance for the last decade, lost the ability to sell internet-connected cameras into the Indian market on that date.

80% Indian market share.

That is the share Indian domestic camera brands now hold, as of early 2026. Bosch and Honeywell sit in specialized premium enterprise. The Indian SI or MSP putting cameras on the wall for a BFSI branch, a manufacturing yard, a smart-city corridor, or a hospital corridor is picking from a meaningfully different shortlist than they were eighteen months ago.

The procurement decision that arrives with the ban is not "which camera to buy." It is closer to "the surveillance network you just bought is now an IT network, and the IT team owns it."

Surveillance isn't a CCTV problem.

It's a network problem.

But first, some catch-up on infra this week.

🚨 Cameras Are First-Class IP Citizens Now

For the last two decades, the IP camera lived in a low-voltage cable run, on a VLAN someone in facilities created once, talking to a network video recorder that someone in physical security maintained.

That arrangement is finishing.

Cameras are first-class IP.

Three architectural reasons this matters for the Indian IT lead reading this.

Bandwidth. A modern enterprise IP camera streaming H.265 at 4K and 30 fps carries roughly 8 to 12 Mbps per stream. A campus with 200 cameras feeding a central NVR is moving 1.6 to 2.4 Gbps just for surveillance, before any user traffic, IIoT telemetry, or VoIP. For most Indian BFSI branch backhauls, that is a meaningful share of the total available capacity. The bandwidth-planning question stopped being "do we have enough for the cameras" and became "what is the cameras' share of the backhaul, and what does it crowd out at 11am."

Segmentation. Camera streams have a different threat profile than user traffic. The camera is a credentialed device that should only talk to specific VMS endpoints. If a compromised camera starts beaconing outbound to a non-VMS IP, the segmentation policy is what catches it. Most enterprise networks today either run cameras on a flat surveillance VLAN with too-permissive egress, or run them on a properly segmented VLAN that nobody is monitoring.

NDR (Network Detection and Response). Per multiple NDR vendor architectures, enterprise NDR uses out-of-band monitoring for broad coverage, often paired with inline sensors at chokepoints. The camera VLAN is the canonical low-visibility segment NDR was designed for. ML-based behavioral baselines flag cameras whose traffic pattern shifts (firmware update at an unscheduled hour, outbound connection to an unexpected destination, anomalous frame-rate or bitrate). Most Indian deployments today do not run NDR against the camera VLAN. Most also do not know what their cameras' baseline traffic pattern is supposed to look like.

The third reason is where the post-April-1 procurement decision gets sharper. The new STQC-certified Indian camera fleet ships with cybersecurity controls that did not exist in the previous vendor stack. The IT team needs to know what those controls assume about the network they are sitting on, and what gaps the network has to close to make those controls effective.

For the procurement-side checklist:

✔ What is the per-camera average and peak bandwidth at the codec, resolution, and frame rate you plan to deploy?

✔ Which VLAN do the cameras sit on, and what is the egress policy from that VLAN to anything other than the VMS endpoints?

✔ What is the baseline traffic pattern for each camera in normal operation, and what tooling alerts on deviation?

✔ Is the NVR or VMS server hardened against the same baseline as your other production servers?

✔ When the camera firmware updates, is the update channel authenticated and the artefact validated?

Half of those questions used to be physical-security questions. They are network-team questions now.

How we plug in: Our Cyberdefense practice treats the camera VLAN as a first-class managed segment, not a facilities afterthought. NDR for camera streams, baseline traffic profiling per device class, segmentation policy that maps to BIS ER-01 expectations, and incident-response runbooks that include the surveillance plane. We have done this work across Indian BFSI, manufacturing, and smart-city engagements where the camera fleet sits on the same IP backbone as the rest of the business.

🔍 The VMS Vendor Lineup, Read Honestly

Four VMS stacks dominate the post-April-1 Indian procurement conversation. Each is selling a different operational story.

Genetec Security Center is the heavy-enterprise option. Per Gartner peer reviews and multi-source vendor comparison work, Genetec is the recommended pick when the deployment is government, transit, public safety, or any environment with more than 5,000 cameras and a need to unify video + access control + automatic license plate recognition into a single operating plane. Genetec's Omnicast SaaS extension brought cloud-managed video into the portfolio without abandoning the on-prem story. For an Indian smart-city or transport-authority deployment, Genetec is usually on the shortlist; for a 50-camera retail rollout, it is usually overkill.

Milestone XProtect is the integrator-led option. Strong third-party camera ecosystem, broadest support across camera makes and models, mature partner network. Milestone explicitly lacks native AI capabilities, which matters: if the buyer's RFP assumes the VMS ships with analytics, Milestone forces a decision between bundled VMS+AI from another vendor or an external analytics layer on top of Milestone. For the Indian SI running a diverse-vendor camera deployment, often the right fit.

Avigilon Alta Aware Cloud is the AI-first cloud option. Advanced built-in analytics, recently expanded into a fully cloud-managed VMS. The catch: closed ecosystem. Avigilon's AI features assume Avigilon-class hardware. For an Indian buyer mid-migration to a domestic camera fleet (post-Hikvision-ban), the closed-ecosystem trade-off is a procurement decision, not a footnote.

Indian domestic VMS / camera stacks are the fourth category and the one that materially changed in 2026. Hi-Focus has aggressively expanded the IP-camera portfolio. Matrix Comsec ships STQC-certified products across the camera + VMS + access-control range. VMukti positions as an enterprise VMS with multi-vendor camera support. Bosch and Honeywell remain in premium enterprise. The shortlist for any deployment funded by the central or state government, defence, railways, smart-city projects, PSUs, or critical infrastructure must include at least one STQC-certified Indian vendor under the Public Procurement Order, regardless of the buyer's preference for a global brand.

The four-vendor decision matrix, in one summary:

👉 Genetec for >5k cameras, multi-system unification, government / transit / public safety.

👉 Milestone for diverse camera fleet, integrator-led, partner-ecosystem-driven.

👉 Avigilon for AI analytics priority, single-vendor camera commitment.

👉 Indian domestic for STQC-mandated deployments, smart-city, BFSI branch, and any Public Procurement Order context.

For most Indian enterprises post-April 2026, the realistic answer is a hybrid. Indian domestic for the camera fleet (regulatory and price). Genetec or Milestone for the VMS where the scale or integration requirement justifies it. Or full-stack Indian domestic where the scale fits.

The mistake the procurement memo most often makes is assuming the camera vendor and the VMS vendor have to be the same. They do not. They do, however, have to be on the ONVIF-compatible side of the camera-protocol divide.

How we plug in: Our Complete IT Infrastructure Solution practice runs the VMS evaluation framework that sits behind a multi-vendor surveillance RFP. We have done this work across Indian BFSI, manufacturing, pharma, and textile clients, often where the buyer needs to combine an Indian-domestic camera fleet with a global VMS without losing the AI analytics, the audit trail, or the BIS ER-01 compliance posture. The vendor's sales engineer will lead with feature lists. The procurement memo needs the integration-and-compliance matrix the SE deck leaves out.

📌 The Indian Smart-City Surveillance Market Is Reshaping in Real Time

The India CCTV camera market sits at $2.4 billion in 2026 and is projected to reach $8.2 billion by 2033. That is a 19.1 percent compound annual growth rate over seven years.

Inside that headline, the IP / network segment is the fastest-growing category at roughly 21.9 percent CAGR. Analog CCTV is finishing its long sunset. The replacement traffic is IP-native, ONVIF-conformant, and increasingly cloud-or-hybrid-managed.

Three forces are driving the shape.

Smart Cities Mission and state programs. Central-government and state-level surveillance initiatives across transport corridors, public-space safety, traffic management, and critical-infrastructure monitoring are the biggest single demand pump. Any of those deployments funded under the Public Procurement Order must use STQC-certified equipment. The Indian domestic vendors built the certification posture early enough to absorb the demand.

BFSI branch surveillance modernization. Indian banks running 5,000-plus branch networks are mid-cycle on a camera-fleet refresh that was scheduled before the April 1 ban and is now landing into a fundamentally different supplier landscape. The CIOs who locked their procurement before the certification rules clarified are renegotiating contracts; the ones who delayed are now choosing between four Indian-domestic shortlist options where there used to be six global ones.

Manufacturing yard + perimeter security. Indian manufacturing campuses with 24x7 production runs and significant physical-yard footprint (textile, pharma, automotive component, steel, cement) are deploying surveillance that doubles as OT-process observability. Perimeter cameras feed both physical security and the operations control room. The convergence of OT and IT under the same IP backbone makes the camera fleet a shared asset.

For the Indian CIO planning a 2026 surveillance refresh:

✔ Confirm every camera quoted in the RFP carries valid STQC certification. Treat the certificate as the procurement gate, not a checkbox.

✔ Ask the vendor for the SoC origin disclosure. The certification is the floor; the SoC disclosure is the substance.

✔ Sanity-check the vendor's three-year roadmap against the Public Procurement Order. A vendor without an STQC-aligned roadmap will not be eligible to bid into any government-funded deployment.

✔ If the deployment is hybrid (some sites government-funded, some private), maintain a single camera shortlist that meets the highest applicable bar. Two parallel shortlists is operationally expensive.

The opportunity in this market correction is real, but narrow. The Indian domestic vendor lineup is consolidating quickly. The buyer's window to negotiate volume-pricing favors with vendors still aggressive on share-capture is open now and closes when consolidation completes.

How we plug in: Our Complete IT Infrastructure Solution practice has run BFSI branch surveillance refreshes, manufacturing-yard deployments, and smart-city tender evaluations for Indian buyers across thirty-five years. The post-April-1 procurement landscape is different from the one most buyers know. We will help you read the new vendor matrix, sanity-check the STQC posture, and write the contract clauses that protect you through the consolidation cycle.

📋 BIS ER-01, STQC, IS 13252-1: The Cybersecurity Floor for Cameras

The compliance scaffold sitting behind the April 1 ban is worth reading directly, because most procurement memos still summarize it incorrectly.

Disclose the chipset origin.

BIS ER-01 (Essential Requirements) is the mandatory cybersecurity regulation for internet-connected CCTV cameras and smart surveillance systems sold in India. It was issued by MeitY in April 2024 with a two-year transition window that closed on April 1 2026.

The ER framework maps to the IS 13252-1 cybersecurity standard, which sets the technical bar for camera security: secure boot, firmware integrity verification, authenticated update channels, hardened management interfaces, no hardcoded credentials, encrypted local storage, and supply-chain origin disclosure.

The SoC origin disclosure is the structurally most consequential rule. Manufacturers must explicitly disclose the country of origin for the critical System-on-Chip architectures inside the camera. The Government has been actively denying STQC certification to products using Chinese-origin chipsets, even where the camera brand is non-Chinese. The result: a Hikvision model using a non-Chinese (specifically Taiwanese) chipset passed certification and remains legal for sale. A camera from a different brand using a Chinese chipset did not.

The substance of the rule is the supply chain, not the brand.

STQC (Standardisation Testing and Quality Certification) is the certification arm that tests against ER-01 / IS 13252-1 and issues the certificate that the Public Procurement Order requires. Every internet-connected CCTV camera sold in India after 2026-04-01 must hold a valid STQC certificate. Every government-funded deployment must use STQC-certified equipment. Private-sector deployment is technically permitted with non-STQC equipment for non-internet-connected cameras only, which in practice is a small share of modern fleets.

The trigger event that accelerated the timeline was the March 2026 exposure of a Pakistan-linked espionage network operating in Ghaziabad. Investigators found operatives exploiting unsecured CCTV feeds and installing covert cameras at sensitive sites. The pre-existing two-year transition window did not move. The enforcement around it did.

For the Indian CIO managing surveillance procurement: the certification is a hard requirement, not a procurement preference. The SoC disclosure is the document that distinguishes a real STQC certificate from a marketing claim. The vendor's compliance roadmap is the indicator of whether they will still be eligible for your next contract cycle.

How we plug in: Our Cyberdefense practice treats BIS ER-01 + IS 13252-1 compliance as part of the broader managed-security posture, not as a separate physical-security workstream. The camera is a sensor with credentials sitting on your network. The STQC certificate sets the floor. The operational hardening, NDR coverage, segmentation policy, and audit trail sit on top. We have built this for Indian BFSI, manufacturing, and smart-city engagements.

India Bans Chinese CCTV Under New Security Rules
Medianama.
The cleanest primary-coverage read on the April 1 implementation. Includes the SoC-origin disclosure context that most other coverage skips.

BIS ER-01 for CCTV Cameras: India's New Cybersecurity Rules Explained
Absolute Veritas.
The compliance-team-friendly explainer. Read alongside the Matrix Comsec STQC reference for the procurement-side checklist.

Best Video Management Software 2026
Ambient AI.
Independent vendor comparison covering Milestone, Genetec, Avigilon, and emerging cloud-native options. Useful for the buyer mid-evaluation; pair with Gartner peer-review data before signing.

VMS in 2026: Architecture, ONVIF, Vendor Matrix
Forasoft.
The architecture-side read. Read for the cloud / on-prem / hybrid edge-cloud trade-offs before the vendor's deck reads them for you.

India CCTV Camera Market Share & Growth Analysis
Persistence Market Research.
The market-sizing data behind the $2.4B-to-$8.2B trajectory and the IP-segment growth premium.

💡 My Take

For the last decade, surveillance in Indian enterprise IT lived in a quiet corner of the procurement budget. Someone in facilities owned it. Someone in physical security maintained it. The IT team was rarely involved unless a NVR went down or a hard drive filled up.

The April 1 ban changed where the camera fleet sits in the budget, who owns the procurement decision, and what the failure modes look like.

It also changed what kind of asset the camera is.

Treat cameras like servers.

The camera is no longer a dumb endpoint streaming H.265 to a recorder. It is a credentialed device with a network identity, a firmware update channel, an authentication boundary, and a baseline traffic pattern that can be profiled. It is, in operational language, a sensor with credentials.

That reframe changes the procurement memo. The Indian CIO drafting the 2026 surveillance RFP needs to ask the same questions of the camera fleet that they ask of any other server fleet. What is the firmware update cadence and who controls the trust chain. What is the segmentation policy and who alerts when it is violated. What is the baseline traffic pattern and what tooling detects deviation. Who is responsible for incident response when a camera is the breach indicator.

Half of those questions have not been asked of cameras inside Indian enterprises in the past five years.

The other half have been asked, and answered inadequately, because the camera vendor's documentation did not address them.

The post-April-1 vendor landscape is genuinely better positioned to answer them. The STQC certification process forces the camera manufacturer to ship the operational hardening that the regulation requires. The Indian domestic vendors that captured market share through 2026 did so by building those controls in. The buyer's job is to take advantage of it.

VEMIO™ exists because the operational reality of running a sensor fleet of any kind, surveillance or otherwise, lives in the observability plane. The camera vendor will give you STQC compliance on paper. The audit committee needs to see compliance in practice. We instrument the customer side of the deployment so the regulatory floor stays in place twelve months after the contract was signed, not just the day the deployment was certified.

The camera is not an endpoint. It is a sensor with credentials.

Reply to this email with the one surveillance asset you cannot currently account for on your network inventory, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.

Until next time,

Ajay Salvi & the Vinay Enterprises team.

Keep Reading