Review of India’s Joint Doctrine for Cyberspace Operations
- Chinmayee R Srinath
- Jul 13
- 5 min read

The doctrine should be complemented by a comprehensive implementation plan that includes timelines and the necessary institutional responsibilities says Chinmayee R Srinath in a review.
Introduction:
The Joint Doctrine for Cyberspace Operations, released in August 2025 by the Headquarters Integrated Defense Staff (HQ IDS), India, is a comprehensive tri-service cyberspace doctrine that expands the applications of cyberspace beyond Information Technology to the military domain. The doctrine elaborates on the rationale for including cyberspace in the military, recognizing cyberspace as an operational domain alongside land, maritime, and air spaces, and providing a common framework for operations across the three services.
Summary:
The doctrine emphasizes Jointness, that is, the field of cyberspace should not be limited to a specific sector but must include the entirety of armed forces (Tri-services). The doctrine further comprises six chapters covering cyberspace operations, organizations, development of cyberspace ecosystems, and Human Resources and Skill development. The primary objective in establishing a cyberspace doctrine is to ensure India gains ascendancy in Non-Contact warfare, while acknowledging that cyberspace as a domain is relatively new and evolving. (Headquarters Integrated Defense Staff [HQ IDS], 2025), notes that cyberspace blurs the distinction between war and peace while aiming for ‘Cyberspace Military Superiority’ wherein future warfare would extend beyond conventional battlefields into cyberspace, information, and electromagnetic domains. This would benefit India in achieving self-sufficiency, or ‘Atma Nirbharta’, at the earliest. The domain of cyberspace in the military is corroborated by dynamic applications, such as physical attacks, logical attacks (including network control and information flow), and cognitive attacks, in which the decision-making process is influenced by information gathered with the assistance of cyber networks.
The doctrine identifies the primary threat to India's population; due to the numbers, threats in the digital space multiply manifold, with the highest level of targeted threat being a Nation State-enabled Kinetic attack (HQ IDS, 2025). The doctrine has called for the National Security Organizations and the Indian Armed Forces to focus on CEMA situational awareness (electronic warfare capability). While the doctrine does not identify specific adversaries, its rationale could be attributed to the changing dynamic of conflicts worldwide, in which adopting the same would benefit India immensely. The doctrine addresses the lack of International consensus regarding definitions and treaties, while acknowledging the ambiguity of declaring a cyber-attack unilaterally. The doctrine provides limited guidance on addressing these challenges.
The doctrine builds upon the existing legislations such as the National Cyber Security Policy 2013 and organizations such as Defence Cyber Agency (DCA), the National Critical Information Infrastructure Protection Centre (NCIIPC), the Indian Computer Emergency Response Team (CERT-In), and defence innovation initiatives like Innovations for Defence Excellence (iDEX) on cyberspace security focus on protecting critical digital infrastructure, and developing cyber awareness. Together, these institutions provide the framework for the doctrine which seeks to expand India’s military cyber capabilities. To achieve this, the doctrine recommends the Public-Private Partnership Model, a secure supply chain, defense cooperation with friendly countries, and skill development, while integrating civilian and military cyberspace ecosystems. The doctrine establishes a framework intended to guide future military cyber policies.
Analysis:
The Joint Doctrine for Cyberspace Operations is elaborate in terms of the definitions and terms relating to cyberspace, operational mechanisms, nodal agencies, and limitations. The doctrine is well organized and comprehensible. The doctrine does not create military capability in itself, but provides a conceptual framework for institutions within the Indian Armed Forces to operate, plan, and implement cyberspace. The doctrine being a recent advancement in the field of cybersecurity, only an early assessment can be made based on how many policies and organizations have been shaped by the framework.
Early Assessment:
Given the doctrine’s recent release, any assessment indicates policy developments broadly aligned with the framework outlined in the doctrine. Organizations that predate the doctrine, such as the DCA and NCIIPC, have expanded their scope. The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025 (Press Information Bureau, 2025), are a civilian data protection policy governing digital ecosystems and have been consistent with the doctrine, in terms of integrating civilian and military ecosystems. However, this cannot be categorized as the direct implementation of the doctrine.
Similarly, India’s defense partnerships with the European Union (EU) and France act as examples for defense cooperation with like-minded countries. The India-EU security defense partnership, signed in January 2026 (European Union External Action, 2026), reflects the objectives set out in the doctrine, such as CEMA situational awareness, cyber defense, and the development of critical infrastructure, particularly by integrating the civil and military domains. The India-France special strategic partnership, announced in February 2026 (PM India, 2026), focuses on cybersecurity and skill development, reemphasizing India’s security and defense partnership with France. Mission Sudarshan Chakra, a broader national defense strategy rolled out in August 2025 (Press Information Bureau, 2025), is also in line with the objectives of the doctrine, with a particular focus on anti-cyber warfare and cyber-resilient defense infrastructure. The opening of the United Nations Convention against cybercrime signing process in Hanoi, Vietnam, in October 2025 (United Nations Office on Drugs and Crimes, 2025) is a step toward developing an international consensus on cyberspace, as the doctrine notes the lack of such consensus in cyberspace treaties and agreements. These developments suggest that the broader objectives of the doctrine are already taking shape in the form of the aforementioned policies and agreements.
Conclusion and Way Forward:
The doctrine should be complemented by a comprehensive implementation plan that includes timelines and the necessary institutional responsibilities. India should continue deepening cyber cooperation with friendly countries and develop the necessary cyber ecosystems indigenously. The Joint Doctrine for Cyberspace Operations represents a significant step in India’s approach to military cyberspace, by providing a unified framework for the tri-services. Given the recent release, the doctrine's long-term effectiveness cannot be determined. Nevertheless, early assessments have suggested various developments and policy initiatives that are complementary to the broader objectives stated in the doctrine.
References
European Union External Action. (2026, January 27). Security and Defence: EU and India sign security & defence partnership. Retrieved from European Union External Action.
Headquarters Integrated Defense Staff (HIDS). (2025). Joint Doctrine for Cyberspace Operations. Headquarters Integrated Defense Staff (HIDS).
PM India. (2026, February 17). India – France Joint Statement. Retrieved from PM India.
Press Information Bureau. (2025, November 17). DPDP Rules, 2025 Notified. Retrieved from Press Information Bureau, Government of India.
Press Information Bureau. (2025, August 15). PM Modi’s 79th I-Day Address: A Vision for a Viksit Bharat 2047. Retrieved from Press Information Bureau.
United Nations Office on Drugs and Crimes. (2025, October ). Overview of the signature and ratification processes of the United Nations Convention against Cybercrime. Retrieved from United Nations Office on Drugs and Crimes.



Comments