On September 1, 2024, drones flying in from the hills above Koutruk village in Manipur's Imphal West district dropped more than fifty bombs over three hours. Two people were killed and nine injured. It was the first time drones had been used to attack Indian civilians on Indian soil.
Fourteen months later, on November 10, 2025, a car bomb detonated near Delhi's Red Fort, killing more than a dozen people. As the National Investigation Agency (NIA) dug into the conspiracy behind it, investigators found something more disturbing than the blast itself: the same terror module had been modifying commercially available drones — larger batteries, heavier payloads, live video feeds — for a coordinated, “Hamas-style” aerial attack across North India.
Neither device involved in either case was certified against any cybersecurity or safety standard. Neither had to be. India has no mandatory certification deadline for drones.
Compare that to CCTV cameras. After a March 2024 gazette notification, the Ministry of Electronics and Information Technology set a hard deadline: from April 1, 2026, any camera that isn't STQC-certified against the government's Essential Requirements cannot be manufactured, imported, or sold in India. Millions of surveillance devices, many built on foreign components, will be legally unsellable overnight.
Drones — which can fly, carry a payload, and cross a border — have no equivalent deadline. Certification remains a choice, not a requirement. And that gap persists despite the fact that the capability to close it already exists: more than 500 STQC-certified drones have already been delivered to the Indian Army. The capability is proven. The deadline isn't.
The market is here. So is the moment
The case for urgency isn't only about the two attacks. It's also about what India stands to gain — or lose — in the next four years.
India's drone (UAV) market was valued at roughly $0.47 billion in 2025 and is projected to reach $1.39 billion by 2030, growing at nearly 24.4% a year, according to MarketsandMarkets. Globally, the drone market is on a similar trajectory, expected to grow from around $73 billion in 2024 to more than $160 billion by 2030 per Grand View Research. The number of drones procured in India alone is expected to roughly double, from about 8,400 units in 2025 to almost 16,800 by 2030.
The government is not standing still. The upcoming Drone Shakti Mission is designed to scale local component production, and the proposed PLI 2.0 scheme targets 30% domestic value in every drone sold in India, cutting import dependence. Aatmanirbhar Bharat's drone ambitions are real, funded, and moving.
But scale without security is just exposure at a larger radius. A market growing 24% a year, built on airframes with no mandatory cyber-hardening, is not a strategic asset — it's a proliferation risk that happens to have a growth chart attached.
Where the risk actually lives
The vulnerabilities aren't hypothetical, and they aren't exotic. They're the same handful of failure points recurring across every uncertified platform in the field:
– GPS jamming and spoofing — false position data that redirects a flight path or forces a controlled crash.
– RF link hijack — a poorly secured control link that lets an attacker inject commands and re-task the payload mid-flight.
– SIGINT and ISR leakage — unencrypted video and telemetry that hands live intelligence to anyone listening, while geo-locating the operator in the process.
– Supply chain backdoors — firmware built on unverified components, with no way to know what was inserted before the device ever left the factory.
Every one of these has already been exploited, somewhere, against a drone that was never certified to resist it.
What certification actually buys you
This is where the STQC/ADB Cybersecurity Framework earns its place in the conversation — not as paperwork, but as a working technical answer to each of those four failure points.
An open-source or commercial-off-the-shelf stack, run unmodified, typically has no code signing, so unauthorised firmware runs unchecked. Its communications are frequently unencrypted or weakly encrypted by default. There's no verified bill of materials, so component provenance is simply unknown. Vulnerabilities get patched reactively, if at all, and there's no mandated testing against GPS denial or spoofing.
A platform certified against the ADB framework is a different proposition. Firmware is signed and verified before every execution. The communications link is tested specifically for encryption strength and jamming resistance. A verified BOM and SBOM make component provenance traceable, not assumed. The vendor is bound to ongoing vulnerability disclosure rather than a one-time compliance stamp. And GPS-denial and anti-spoofing resilience are explicit, tested requirements — not a feature a manufacturer might get around to.
Certification, in other words, isn't a brake on the industry. It's the thing that lets an industry moving this fast actually be trusted at the scale it's trying to reach.
The unlock
Here is the part of the argument that goes beyond compliance. ADB's Cybersecurity Framework is not a copy of an existing international standard — it's a one-of-a-kind certification regime that no other country has built for drones in quite this way. That originality is an asset, not just a domestic requirement.
Implemented immediately and marketed globally, this framework has the potential to become the reference standard other nations look to as they face the same problem India is facing right now. A country that certifies first, and certifies rigorously, doesn't just protect its own skies — it positions its industry to define the terms other buyers eventually adopt. That is precisely the kind of asymmetric advantage a “global drone hub” ambition needs: not just more factories, but the standard the rest of the world ends up building to.
CCTV cameras got their deadline. Manipur and Delhi already showed us why drones can't afford to wait for theirs.
The questions worth debating
None of this resolves cleanly, and it shouldn't. A few questions deserve real argument, not just agreement:
Can certification move as fast as the industry it's meant to protect? Should STQC certification sit at the procurement gate, rather than arrive as a pre-deployment checkbox? Who is liable when a certified platform is compromised through a supply-chain component nobody flagged? And if “global drone hub by 2030” is the actual ambition, what does Bharat's certification regime need to become to make other countries want to adopt it, not just require it?
(The author is the founder and MD of Zuppa Geo Navigation Technologies)
(The opinions expressed in this article are those of the author and do not purport to reflect the opinions or views of THE WEEK)