Sections 88 to 90 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 88 of the Information Technology Act, 2000 requires the Central Government to constitute the Cyber Regulations Advisory Committee. Section 89 lets the Controller make regulations after consulting that Committee and with the previous approval of the Central Government. Section 90 lets a State Government make rules on two matters tied to section 6. Sections 91 to 94 are printed as omitted. This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008); later amendments and the current position should be checked.
The Central Government shall constitute a Cyber Regulations Advisory Committee (section 88), consisting of a Chairperson and official and non-official members. The Controller may, after consultation with the Committee and with the previous approval of the Central Government, make regulations consistent with the Act and the rules (section 89). A State Government may, by notification, make rules to carry out the Act, on the matters in section 90(2). Sections 91 to 94 are printed as omitted.
Section 88: the Cyber Regulations Advisory Committee
Section 88 has four sub-sections:
| Sub-section | What the words say |
|---|---|
| (1) | The Central Government shall, as soon as may be after the commencement of the Act, constitute a Committee called the Cyber Regulations Advisory Committee |
| (2) | It consists of a Chairperson and such number of other official and non-official members representing the interests principally affected or having special knowledge of the subject-matter as the Central Government may deem fit |
| (3) | It shall advise (a) the Central Government either generally as regards any rules or for any other purpose connected with the Act; (b) the Controller in framing the regulations under the Act |
| (4) | Non-official members are paid such travelling and other allowances as the Central Government may fix |
The Act sets out the Committee's task and does not name its members, quorum, or procedure. Whether a Committee has been constituted, and who sits on it, is a question of fact, and nothing about it is in the sources used for this article.
If your business is likely to be affected by rules or regulations under the Act, a legal consultation on how to follow the rule-making process, and how consultation fits in, helps you to plan ahead.
Section 89: the Controller's regulations
Section 89(1) reads: "The Controller may, after consultation with the Cyber Regulations Advisory Committee and with the previous approval of the Central Government, by notification in the Official Gazette, make regulations consistent with this Act and the rules made thereunder to carry out the purposes of this Act."
The Controller is the Controller of Certifying Authorities, defined in section 2(1)(m); our article on sections 17 to 19 explains the office. Three conditions attach to the power: consultation with the Committee, the previous approval of the Central Government, and notification in the Official Gazette. The regulations must be "consistent with this Act and the rules made thereunder".
Section 89(2) lists the matters on which regulations may be made:
| Clause | Matter | Section it serves |
|---|---|---|
| (a) | particulars relating to maintenance of the database containing the disclosure record of every Certifying Authority | 18, clause (n) |
| (b) | conditions and restrictions subject to which the Controller may recognize any foreign Certifying Authority | 19(1) |
| (c) | terms and conditions subject to which a licence may be granted | 21(3)(c) |
| (d) | other standards to be observed by a Certifying Authority | 30(d) |
| (e) | manner in which the Certifying Authority shall disclose the matters specified | 34(1) |
| (f) | particulars of statement which shall accompany an application | 35(3) |
| (g) | manner in which the subscriber shall communicate the compromise of private key to the Certifying Authority | 42(2) |
Clause (a) prints the number of the clause of section 18 in square brackets, "[(n)]". Section 89(3) provides that every regulation made under the Act shall be laid, as soon as may be after it is made, before each House of Parliament, while it is in session, for a total period of thirty days, which may be comprised in one session or in two or more successive sessions. If, before the expiry of the session immediately following, both Houses agree in making any modification in the regulation or agree that the regulation should not be made, the regulation thereafter has effect only in such modified form or is of no effect, as the case may be, without prejudice to the validity of anything previously done under it.
The Act does not set out the content of any regulation, and no regulation is in the sources used for this article. Where this article says a matter is left to regulations, it means that the Act itself prints no form, fee or period for it.
Rules under section 87 and regulations under section 89 are different: rules are made by the Central Government, regulations by the Controller with the Committee and Central Government in the picture. Our article on sections 86 and 87 lists the rule-making clauses.
Section 90: State Government rules
Section 90(1) reads: "The State Government may, by notification in the Official Gazette, make rules to carry out the provisions of this Act."
Section 90(2) says that, in particular, and without prejudice to the generality of that power, the rules may provide for:
- (a) the electronic form in which filing, issue, grant, receipt or payment shall be effected under sub-section (1) of section 6;
- (b) matters specified in sub-section (2) of section 6.
The copy then prints "[ *]", marking omitted words. Section 90(3) provides that every rule made by the State Government under the section shall be laid, as soon as may be after it is made, before each House of the State Legislature where it consists of two Houses, or where such Legislature consists of one House, before that House.
| Point | Section 87 (Central Government) | Section 89 (Controller) | Section 90 (State Government) |
|---|---|---|---|
| Instrument | Rules | Regulations | Rules |
| Made by | Central Government | Controller, after consultation and with previous approval | State Government |
| Laid before | Each House of Parliament | Each House of Parliament | State Legislature |
| Matters | Clause list in 87(2) | Clause list in 89(2) | Two matters tied to section 6 |
Sections 91 to 94: omitted
Sections 91 to 94 are printed as omitted by the Information Technology (Amendment) Act, 2008 (10 of 2009), section 48, with the words "w.e.f. 27-10-2009". This article does not describe what they used to say.
A worked example
Setu Trust Services Private Limited, an invented licensed provider of certificate services, wants to know how it must communicate a compromise of a private key. The Act, in section 42, deals with duties of subscribers; section 89(2)(g) says regulations may provide for "the manner in which the subscriber shall communicate the compromise of private key to the Certifying Authority". The company must therefore look at the regulations made under section 89, which are not in the sources used for this article, and cannot rely on a summary of the Act alone.
Need help with regulations and rules?
If you need to find out which rule or regulation governs a matter and how it fits the Act, our team can help. Begin with a legal consultation.
Key takeaways
- Section 88: the Central Government shall constitute the Cyber Regulations Advisory Committee, which advises the Central Government and the Controller.
- Section 89: the Controller makes regulations after consultation with the Committee and with the previous approval of the Central Government, consistent with the Act and the rules.
- Section 90: a State Government may make rules, in particular on matters tied to section 6.
- Sections 91 to 94 are printed as omitted.
Read next
- Sections 86 and 87 of the Information Technology Act, 2000: removal of difficulties and Central Government rules
- Sections 17 to 19 of the Information Technology Act, 2000: Controller of Certifying Authorities
- Sections 40 to 42 of the Information Technology Act, 2000: duties of subscribers and control of private key
- Cyber Law: Information Technology Act 2000, offences, penalties and adjudication
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
