14 Sept 2026, 01:21 PM 3 min readtech

India Consults Global Tech Giants to Develop Sovereign Cloud Framework

India has initiated formal consultations with global technology giants, including Amazon Web Services, Google, and Apple, as part of a strategic effort to establish a sovereign cloud framework for government data. The Ministry of Electronics and Information Technology (MeitY) is currently drafting a proposal that aims to reduce the nation's heavy reliance on foreign-owned cloud infrastructure for critical government workloads. While the government seeks to leverage the technical expertise of these US-based firms, officials have emphasized that the final architecture must remain indigenous to ensure national security and data control.

Defining Sovereign Cloud Criteria

The proposed framework is designed to move beyond simple data residency, focusing instead on the control and operational integrity of the infrastructure. According to individuals familiar with the proposal, the government plans to implement approximately 46 distinct safeguards categorized into four broad pillars: legal jurisdiction, technological capability, operational control, and a mandatory Make in India component. The objective is to ensure that the government retains authority over who operates the systems, who accesses the data, and how the underlying supply chain is managed.
NS Nappinai, a Senior Advocate at the Supreme Court and founder of Cyber Saathi, noted that while global technologies can be integrated, the core of a sovereign cloud must be indigenous. She emphasized that data impacting national security should be kept exclusively on sovereign infrastructure, stating that India has the capability to build such systems without relying on external providers for critical control functions.

Existing Infrastructure and Scale

The move toward a sovereign cloud builds upon the foundation of the MeghRaj initiative, which launched in 2014 to provide on-demand computing and storage to government departments. By June 2026, the program had expanded to support 2,323 departments, a significant increase from the 342 departments served in 2015-16. Current infrastructure, managed by the National Informatics Centre (NIC), includes approximately 100 petabytes of storage and 5,000 servers. These systems currently host sensitive datasets, including Aadhaar, UPI transaction records, and DigiLocker documents, which contain information ranging from financial records to criminal databases.

Implementation and Market Participation

MeitY has already empanelled 29 companies eligible to participate in the bidding process for the new framework. This list includes major domestic players such as Jio Platforms, Yotta Data Services, Tata Communications, Sify, and CtrlS. The government intends to classify workloads based on their sensitivity, ensuring that only the most critical data is restricted to the highest-security sovereign cloud tiers.
While the government currently utilizes multi-layered security and ISO 27001-certified data centers, recent cybersecurity incidents, such as phishing campaigns targeting government email services, have highlighted the limitations of relying solely on infrastructure security. The new framework is expected to undergo internal ministry consultations shortly, followed by a broader public consultation phase in the coming months to finalize the regulatory and technical requirements.

Sources & Citations

The Indus Pulse is committed to accuracy and transparency.