Section 66F explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 66F of the Information Technology Act, 2000 defines the offence of cyber terrorism in two limbs, (A) and (B), and prints a punishment of imprisonment which may extend to imprisonment for life. This article sets out the elements of each limb in the section's own words and does not go beyond them. It follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008); later amendments and the current position should be checked.
Section 66F(1) has two limbs. Limb (A) needs an intent to threaten the unity, integrity, security or sovereignty of India or to strike terror, together with one of three listed means and a listed result. Limb (B) concerns restricted information, data or computer database obtained by unauthorised access, with the stated reasons to believe. Sub-section (2) prints imprisonment which may extend to imprisonment for life for committing or conspiring to commit cyber terrorism.
What section 66F says
Sub-section (1) begins "Whoever," and then sets out two limbs, each ending with the words "commits the offence of cyber terrorism". Sub-section (2) reads: "Whoever commits or conspires to commit cyber terrorism shall be punishable with imprisonment which may extend to imprisonment for life."
Limb (A): intent, means and result
Limb (A) is built from an intent, a means and a result.
Intent. The act must be done "with intent to threaten the unity, integrity, security or sovereignty of India or to strike terror in the people or any section of the people".
Means. The intent is to be carried out "by" one of three things:
- (i) "denying or cause the denial of access to any person authorized to access computer resource" (the copy prints "cause" where the grammar calls for "causing"; we flag it and do not correct it);
- (ii) attempting to penetrate or access a computer resource without authorization or exceeding authorized access; or
- (iii) introducing or causing to introduce any computer contaminant.
Result. And by means of such conduct, the person "causes or is likely to cause" one of the following: death or injuries to persons; damage to or destruction of property; disruption, or knowing that it is likely to cause damage or disruption, of supplies or services essential to the life of the community; or an adverse effect on "the critical information infrastructure specified under section 70".
The reader should note the structure: intent, one of the means, and one of the results. The text does not use the word "terrorism" for any other act than the ones that fit this structure.
Limb (B): restricted information
Limb (B) applies to a person who "knowingly or intentionally penetrates or accesses a computer resource without authorization or exceeding authorized access", and by means of that conduct obtains access to either:
- information, data or computer database "that is restricted for reasons for the security of the State or foreign relations"; or
- any restricted information, data or computer database, "with reasons to believe" that it may be used to cause or likely to cause injury to listed interests.
The listed interests are the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, public order, decency or morality, contempt of Court, defamation or incitement to an offence, or the advantage of any foreign nation, group of individuals or otherwise.
| Feature | Limb (A) | Limb (B) |
|---|---|---|
| Starting point | Intent to threaten India or strike terror | Knowing or intentional unauthorised access or exceeding authorised access |
| Requires a result | Yes: one of the listed results | Obtaining access to restricted information, data or computer database |
| Mental element | Intent as stated | "Knowingly or intentionally"; "reasons to believe" for the second part |
| Linked provision | Section 70 (critical information infrastructure) | Restricted for reasons for the security of the State or foreign relations |
Critical information infrastructure and section 70
Limb (A)(iii) refers to "the critical information infrastructure specified under section 70". Section 70(1) lets the appropriate Government declare, by notification in the Official Gazette, a computer resource which directly or indirectly affects the facility of Critical Information Infrastructure to be a protected system, and its Explanation defines Critical Information Infrastructure as a computer resource, the incapacitation or destruction of which "shall have debilitating impact on national security, economy, public health or safety". Our article on sections 70 and 70A explains that section.
An organisation that operates systems on which essential services depend should know the position under section 70 for its own systems. A legal consultation can help map what the notification process in section 70 means for a business.
Punishment as printed
| Element | Printed text |
|---|---|
| Who | "Whoever commits or conspires to commit cyber terrorism" |
| Punishment | "imprisonment which may extend to imprisonment for life" |
| Fine | No fine is printed in sub-section (2) |
The section prints no minimum term. Section 77B, which says offences punishable with imprisonment of three years and above are cognizable, is quoted in our article on sections 77A and 77B; section 77A bars compounding of offences "for which the punishment for life or imprisonment for a term exceeding three years has been provided". Section 78 says a police officer not below the rank of shall investigate any offence under the Act. Sections 84B and 84C deal with abetment and attempt. The copy refers to the Code of Criminal Procedure, 1973; check the current procedural law for the corresponding provisions.
A worked example, at the level of the elements
Take an invented utility operator, Sagar Grid Services Limited, whose control systems are declared a protected system under section 70(1). The question under limb (A) is not whether an incident has happened but whether the person who caused it had the intent in the section, used one of the three means, and caused or was likely to cause one of the listed results, which here includes an adverse effect on the critical information infrastructure. If a person without that intent gains unauthorised access, section 66F(1)(A) is not the provision that fits; other provisions, for example section 43 and section 66, would be read on their own words. For the operator itself, the practical question is its duty to report incidents to CERT-In, covered in our article on cyber incident reporting under the CERT-In Directions of 28 April 2022.
Need help understanding obligations around critical systems?
If your organisation operates systems that may be treated as critical, or you need to understand an incident reporting and security obligation read with this section, our team can help. Begin with a legal consultation.
Key takeaways
- Section 66F(1) has two limbs: (A) intent plus means plus result, and (B) restricted information obtained by unauthorised access with the stated reasons to believe.
- Sub-section (2) prints imprisonment which may extend to imprisonment for life, for committing or conspiring to commit cyber terrorism.
- The reference to critical information infrastructure points to section 70.
- One printing slip in limb (A)(i) ("denying or cause the denial") is flagged, not corrected.
Read next
- Section 66E of the Information Technology Act, 2000: punishment for violation of privacy
- Sections 70 and 70A of the Information Technology Act, 2000: protected system and national nodal agency
- Section 67 of the Information Technology Act, 2000: publishing or transmitting obscene material
- IT Act 2000 and Cybercrimes in India: key provisions, offences and amendments
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
