BDIA identifies Seven critical digital dependencies for India
Assessment across 29 technology domains finds India has indigenous capability in several areas but remains dependent on foreign-proprietary supply at foundational hardware and materials layers
The Bharath Digital Infrastructure Association (BDIA) has released a national assessment of India’s digital infrastructure capabilities, identifying seven foundational areas where the country remains dependent on foreign-proprietary supply and calling for a control-based approach to digital sovereignty.
Titled Securing India’s Digital Foundations: A National Capability Assessment of Bharat’s Digital Infrastructure Stack and Sovereign Readiness, the assessment evaluates India’s capabilities across 29 technology domains. It finds that India builds the defining capability in six domains and builds competitively on foreign foundations in 11 and can deploy sovereignly through open-source technologies in five, while seven domains remain dependent on foreign proprietary supply.
The report’s central finding is that all seven dependencies are concentrated in hardware and materials rather than software. These include semiconductor fabrication and tooling; subsea cable manufacturing; speciality materials such as germanium; enterprise storage media; advanced compute and memory silicon; merchant network silicon; and secure cryptoprocessor silicon at the root of trusted systems.
Sovereignty is about control, not data location
BDIA argues that India’s digital sovereignty challenge is not simply about increasing domestic technology participation or storing data within the country. Instead, it proposes assessing who ultimately controls critical capabilities.
The report distinguishes between data residency, local presence and control, with control encompassing factors including ownership, board control, source code, cryptographic key material, update mechanisms and commercial continuity.
Its argument is reinforced by several technology dependencies documented during 2025–26. These include the suspension of services to Nayara Energy; demonstrated restrictions on access to foreign AI models; concentration of India’s cloud market among foreign hyperscalers; the potential acquisition of emerging Indian capabilities; foreign cryptographic specifications appearing in government procurement; and tender conditions that can disadvantage domestic technology providers.
According to the assessment, foreign hyperscalers account for more than 90% of India’s cloud market and approximately 60% of government cloud expenditure. At the IaaS level, the three largest foreign providers account for approximately 87% of the market, while domestic providers hold around 3%.
The report therefore argues that data localisation alone cannot eliminate strategic exposure when the underlying provider remains under foreign jurisdiction.
India already has significant indigenous capability
The assessment does not characterise India as broadly technology-dependent. Instead, it identifies significant indigenous capabilities across the digital stack, including optical fibre manufacturing, the indigenous 4G/5G telecommunications stack, digital public infrastructure, cybersecurity products, data centre hardware and semiconductor design.
The report notes, for instance, that India’s indigenous telecom stack involving C-DOT, Tejas Networks and TCS has been deployed across approximately 97,000 BSNL sites. It also identifies a native hardware security module with a patented quantum random number generator and a growing fabless semiconductor design ecosystem with more than 70 design-linked incentive-supported firms and multiple commercial tape-outs.
However, capability does not necessarily translate into market share. The report describes this as a market-realisation gap, noting that demonstrated Indian capability is not yet converting into sufficient adoption, competitiveness and scale.
Seven areas require long-term industrial policy
BDIA’s framework identifies the seven foreign-proprietary dependencies as areas requiring a longer-term industrial response rather than simply procurement intervention.
For merchant network silicon, for example, the assessment identifies merchant switch and router ASICs as a major dependency, with approximately 90% held by Broadcom. It proposes developing an indigenous forwarding ASIC or establishing an India-specific design and manufacturing partnership.
At the security layer, the report identifies the secure cryptoprocessor die at the core of hardware security modules as one of the most sensitive dependencies. It proposes a domestically fabricated implementation of OpenTitan or a compound-semiconductor ASIC partnership, with manufacturing rather than intellectual property identified as the principal constraint.
Similarly, the assessment notes that Indian OEMs can build server systems, but the CPU, GPU and memory silicon inside them remains foreign. It identifies domestic storage media and accelerator silicon as potential targets for capability development.
Procurement reform becomes a key part of the agenda
BDIA’s recommendations extend beyond building new technology capabilities. The report argues that existing Indian technology must also be given a fair opportunity to compete.
It points to procurement conditions, including excessive turnover thresholds, certifications linked to specific foreign cloud brands, qualifications through private foreign analyst publications and global deployment requirements. According to the assessment, such requirements can exclude Indian alternatives even when they have relevant technical capabilities.
The report proposes 14 recommendations, including a forensic audit of cryptographic specifications in government RFPs, mandatory technology access risk assessments before new foreign AI government contracts, threshold-based FDI screening for strategic technology acquisitions, brand-neutral procurement criteria, portability and exit-assistance clauses, and a National AI Sovereignty Framework.
BDIA describes the strategic capability programme for the seven RED domains as its most important long-term recommendation, arguing that these dependencies cannot be addressed through procurement reform, FDI screening or open-source adoption alone and require sustained industrial policy over a decade-scale horizon.
From indigenous capability to sovereign capability
The report’s methodology uses a five-layer, 29-domain taxonomy covering physical and hardware infrastructure, connectivity and networks, compute and cloud platforms, applications and services, and data, security and governance.
It then applies a three-question assessment to determine whether a capability is genuinely indigenous: whether an Indian entity builds it, whether it can be operated without foreign proprietary permission, and whether the vital component’s origin is Indian.
The framework categorises domains as GREEN, AMBER, BLUE or RED, rather than treating sovereignty as a binary condition. GREEN represents genuine indigenous capability, AMBER indicates capability built on foreign foundations, BLUE represents areas where an open-source alternative enables sovereign operation, while RED identifies dependence on foreign proprietary supply without a current alternative.
The assessment builds on the Bharat Digital Samvad, a national consultation held in New Delhi on 20 May 2026 with approximately 125 participants from government, industry, academia and the startup ecosystem. The consultation concluded, among other things, that digital sovereignty is an evolving journey rather than a binary state and that claims of indigenous capability must be supported by evidence at the component level.
Abhishek Bhatt, Secretary General, Bharath Digital Infrastructure Association, said, “India’s digital sovereignty must move from principle to practice. True sovereignty requires shifting from downstream assembly to mastering the foundational layers of our technology stack.”
He added that the assessment aims to provide an evidence-led view of India’s indigenous capabilities and remaining dependencies while creating greater opportunities for domestic technology and infrastructure companies to scale.
The assessment is based on primary product data contributed by 12 BDIA member enterprises and consortia, supplemented by secondary research using patent registries, regulatory certification databases, company filings and independent trade and academic publications. BDIA explicitly notes that this constitutes a sample rather than a national census.
The broader message from the assessment is that India’s digital sovereignty challenge is shifting from whether the country can build digital capabilities to whether those capabilities can scale, compete and remain under Indian control.