The Exim Roof
The Exim Roof
Compliance • Trade • Growth
STQC Certification — The Exim Roof

STQC Certification

Standardisation Testing and Quality Certification support for electronics, IT and cyber security products.

Standardisation Testing and Quality Certification (STQC) is the Government of India's conformance-assessment body under the Ministry of Electronics and Information Technology (MeitY). STQC operates a national network of test laboratories that evaluate electronics, IT, IoT and cybersecurity products against Indian and international standards. STQC certifications carry heavy weight for government procurement, defence purchase, banking-sector products, cybersecurity approvals and IoT devices intended for Indian public infrastructure.

The Exim Roof runs an STQC advisory practice that helps hardware manufacturers, IT product companies, IoT startups, cybersecurity software vendors and payment-terminal manufacturers navigate the STQC ecosystem. From gap analysis and evaluation-scope planning to sample dispatch, test coordination and certificate delivery, we manage every step.

STQC evaluation streams we work on

  • Common Criteria (ISO / IEC 15408) evaluation up to EAL4+ for cybersecurity products, HSMs and secure operating systems.
  • IoT Device Security certification against the STQC IoT security guidelines and TEC IoT ER.
  • Payment terminal (POS) certification against RBI and PCI standards.
  • Digital Signature Device evaluation for CCA-approved usage.
  • Electronics and IT product testing for MeitY empanelment and government procurement.
  • Software testing services — performance, security, load and functional testing.

Regulatory framework and lab network

STQC operates seven Electronics Testing and Development Centres across India (ETDCs) — Bangalore, Kolkata, Trivandrum, Mumbai, Delhi, Hyderabad and Pune — each with specialised competencies. The Directorate of STQC coordinates evaluations, issues certificates and represents India in the international Common Criteria Recognition Arrangement (CCRA).

The evaluation process — Common Criteria as an example

A Common Criteria evaluation begins with definition of the Security Target — a formal document describing the product, its security functions and the assurance level (EAL) sought. The Security Target is submitted to STQC along with the product samples and supporting evidence. STQC evaluates the product against the ISO 15408 Assurance Class requirements — development, guidance documents, life-cycle support, tests, vulnerability assessment. On successful evaluation STQC issues the Common Criteria Certificate, which is internationally recognised under CCRA.

IoT device security

STQC has published a set of IoT security guidelines aligned with the ETSI EN 303 645 baseline. Devices intended for Indian government or public-infrastructure procurement are increasingly required to demonstrate STQC IoT security certification, which covers no-default-passwords, software updates, secure communication, personal-data protection and vulnerability disclosure among many other controls.

How The Exim Roof helps

  • Gap analysis against the target STQC standard.
  • Security Target and Protection Profile drafting for Common Criteria.
  • Evidence preparation across development, testing and vulnerability streams.
  • Sample dispatch and STQC ETDC liaison.
  • Clarification response and certificate maintenance.

STQC Certification Process — Step by Step

  1. 1

    Step 1: Free Consultation

    A no-obligation 20-minute call to understand your product, project, market and the exact approvals you need.

  2. 2

    Step 2: Document Preparation

    Our specialists prepare, review and vet every document so your application clears the portal in the first submission.

  3. 3

    Step 3: Portal Filing & Fee Payment

    We handle the online application, government fee payment and coordinate with test labs / auditors where required.

  4. 4

    Step 4: Department Liaison

    Continuous follow-up with the concerned authority, response to queries and any additional information sought.

  5. 5

    Step 5: Certificate / Approval Grant

    Once approved, the certificate is delivered to you along with a compliance calendar for renewals and returns.

Documents Required for STQC Certification

  • PAN of the applicant / company
  • GST registration certificate
  • Certificate of Incorporation / partnership deed
  • Product details, technical write-up or project report
  • Authorised signatory ID proof (Aadhaar / passport)
  • Address proof of manufacturing unit or office
  • Product datasheet, block diagram and architectural documentation
  • Security Target (for Common Criteria evaluations)
  • Design specification, source-code access (where applicable) and test evidence
  • ISO 9001, ISO 27001 or equivalent QMS / ISMS certificates
  • User guidance documents and secure-installation manual

Why Choose The Exim Roof for STQC Certification

  • Common Criteria
  • IoT & IT product testing
  • End-to-end handholding

Frequently Asked Questions

  1. How long does the entire process take?

    Most approvals are granted in 30–90 days once documentation is in order. Timelines vary by department, product category and testing requirements — we share a milestone-based plan on day one.

  2. Do you handle end-to-end filing?

    Yes. Our team drafts the application, uploads it on the government portal, pays the fee (against invoice), coordinates with labs / auditors and follows up till the certificate is granted.

  3. Will you help with renewals and post-approval compliance?

    Absolutely. We share a compliance calendar with due dates for renewals, annual returns and periodic filings. You will never miss a deadline.

  4. Is STQC certification recognised internationally?

    STQC Common Criteria certificates are recognised under the CCRA in more than 30 countries. Other STQC evaluations are recognised primarily in India but carry the weight of a Government of India conformance-assessment body.

  5. How long does a Common Criteria EAL4+ evaluation take?

    A first-time EAL4+ evaluation typically takes 6–9 months from Security Target acceptance to certificate grant. Timelines depend on product complexity and evidence readiness.

  6. Do we need STQC to sell to government of India?

    Government procurement tenders often specify STQC certification as a mandatory qualification, particularly for cybersecurity, HSM, digital-signature and IoT device categories.

Let's Talk Now!

Need more information about STQC Certification?

Fill in the form below and our compliance team will get back to you within one business day.

You may also need

All services →

From our blog

All articles →