Finance Ministry Declares ICEGATE and ACES-GST as 'Protected Systems' under Information Technology Act, 2000

Last updated: 05 January 2026


Quick Summary
The Ministry of Finance has officially declared the ICEGATE and ACES-GST platforms, crucial for customs and GST administration, as 'Protected Systems' under the Information Technology Act, 2000. This designation, effective immediately, restricts access to authorised personnel only, bolstering cybersecurity and data protection for sensitive trade and tax information. The move aims to safeguard these critical digital infrastructures against cyber threats and unauthorised access.

The Ministry of Finance, Department of Revenue, has officially declared key digital platforms of the Central Board of Indirect Taxes and Customs (CBIC) as 'Protected Systems' under the Information Technology Act, 2000.

The declaration was made through Notification S.O. 9(E) issued on January 2, 2026, in exercise of the powers conferred under Section 70 of the IT Act, 2000.

Platforms Declared as Critical Information Infrastructure

As per the notification, the following computer resources and their respective databases have been designated as Critical Information Infrastructure (CII) of CBIC:

Finance Ministry Declares ICEGATE and ACES-GST as  Protected Systems  under Information Technology Act, 2000
  • Indian Customs Electronic Data Interchange Gateway (ICEGATE) Portal, along with its interconnected systems
  • Express Cargo Clearance System (ECCS)
  • Automation of Central Excise and Service Tax (ACES-GST) Portal
  • All associated dependencies connected with these systems

These platforms play a vital role in customs clearance, GST administration, excise compliance, and trade facilitation, making them critical to India's tax and trade ecosystem.

Restricted Access to 'Protected Systems'

With this declaration, the above systems will now be treated as protected systems, and access will be strictly regulated. The notification authorises access only to the following categories of persons:

  • Designated CBIC employees, authorised in writing by the Board
  • Contractual managed service providers or third-party vendors, granted need-based access through written authorisation
  • Consultants, regulators, government officials, auditors and stakeholders, authorised on a case-to-case basis by CBIC

Any unauthorised access to these systems will attract penal provisions under the IT Act.

Strengthening Cybersecurity in Tax Administration

The move reflects the government's focus on strengthening cybersecurity and data protection for critical digital infrastructure handling sensitive trade and tax data. ICEGATE and ACES-GST serve as backbone systems for customs filings, cargo clearance, duty payments, and compliance reporting, handling millions of transactions daily.

Declaring these platforms as protected systems ensures enhanced safeguards against cyber threats, data breaches, and unauthorised access, thereby improving trust and resilience in India's indirect tax administration framework.

Effective Date

The notification comes into force with immediate effect from the date of its publication in the Official Gazette, i.e., January 2, 2026.

Key Takeaway

By declaring ICEGATE, ECCS and ACES-GST as protected systems under the IT Act, the government has taken a significant step toward securing India's digital tax and customs infrastructure, ensuring continuity, integrity and confidentiality of critical national data.

Official copy of the notification has been attached

FAQ :

The Indian Customs Electronic Data Interchange Gateway (ICEGATE) Portal, the Express Cargo Clearance System (ECCS), and the Automation of Central Excise and Service Tax (ACES-GST) Portal, along with their associated dependencies, have been declared 'Protected Systems'.

These systems were declared 'Protected Systems' under Section 70 of the Information Technology Act, 2000.

Access is restricted to designated CBIC employees, authorised third-party vendors, consultants, regulators, government officials, and auditors, all of whom require specific written authorisation.

The purpose is to strengthen cybersecurity and data protection for critical digital infrastructure that handles sensitive trade and tax data, safeguarding against cyber threats and unauthorised access.

The declaration came into force immediately upon its publication in the Official Gazette on January 2, 2026.

Attached File : 671907_26019_269054.pdf



News posted by

Finance news reporter covering taxation, GST, income tax, business compliance, and economy updates. I simplify complex financial topics into easy-to-understand articles for professionals, taxpayers, and business owners on leading finance and tax platforms.

Click here to Login and post comments    OR



More »


Popular News





CCI Pro



Company
ARTICLESHIP 16 July 2026
Article Assistant

Sahil Agarwal & Company

Mumbai

CA Inter

View Details
Company
14 July 2026
Senior Executive/ Manager

H S SHARMA AND CO

Pune

CA Final

View Details
Company
Featured 16 July 2026
CA Inter, CA Intermediate, CA IPCC, CA CPT, CA SemiQualified

Vakilsearch.com

Chennai

CA Inter

View Details
Company
28 July 2026
Senior accountant

RJ Public School

Bengaluru

B.Com

View Details
Company
23 July 2026
Senior Accountant

Felicity Adobe LLP

Bengaluru

CA Inter

View Details
Company
ARTICLESHIP 30 June 2026
Taxation Content Writer Intern

Interactive Media Pvt Ltd.

New Delhi

CA Inter

View Details
Company
06 July 2026
Chartered Accountant (Indirect Taxation)

Gowra Ventures Pvt Ltd

Hyderabad

CA

View Details
Company
ARTICLESHIP 16 July 2026
CA Article

Pipara & Co. LLP.

Mumbai

CA Inter

View Details