The National Institute of Electronics and Information Technology (NIELIT), an autonomous scientific society under the Ministry of Electronics and Information Technology, launched CYBER KUSHTI 2026 on 15 August 2026 - a national cyber security and Artificial Intelligence hackathon that scores the ability to judge security findings rather than the speed of detecting them.
It is run with the Information Sharing and Analysis Center (ISAC Foundation) under the National Security Database, with CERT-In as Knowledge Partner, and is the official parallel technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026).
Every team receives an identical, deliberately imperfect Security Assessment Package containing false, duplicated and genuine findings, with some real vulnerabilities omitted; teams are scored for correctly rejecting false findings as well as for identifying genuine ones.
Registration is free, open to students and independent researchers in teams of three, from 15 August to 10 September 2026, with three rounds - The Akhada (15 September, online), The Dangal (24 September, online) and The Kesari (9 October 2026, in person at the Dr Ambedkar International Centre, New Delhi).
A conventional Capture The Flag contest rewards whoever finds a hidden vulnerability first, so it measures discovery speed and, indirectly, the quality of the scanning tools a team can afford. CYBER KUSHTI inverts this: every team gets the same tool-generated output, already full of findings, some of which are false positives, some duplicates, and with some genuine vulnerabilities missing altogether. Marks come from producing a corrected and prioritised assessment and defending it - including marks for correctly throwing out findings that are not real. Because the raw material is identical for everyone and participants may use any AI tools they like, the format is designed to neutralise the advantage of expensive commercial tooling and to test triage and prioritisation, the skill that becomes scarce once machines generate findings faster than analysts can read them. In the final round an automated analysis of the same material is displayed beside the teams' presentations so the audience can see where machine output and human judgment diverge.
Simple Analogy: It is the difference between a race to spot mistakes in a manuscript and an editor's test where you are handed a marked-up proof and judged on which of the corrections you accept, which you strike out, and what the proofreader missed.
An autonomous scientific society under the Ministry of Electronics and Information Technology, originally set up in 1994 as the DOEACC Society and renamed NIELIT in October 2011. It runs examination, certification and skilling in electronics and ICT through 56 NIELIT centres, over 700 accredited institutes and more than 8,000 facilitation centres, and was granted Deemed to be University status under the distinct category by the Ministry of Education in 2024, with eleven constituent campuses at Aizawl, Agartala, Calicut, Chhatrapati Sambhajinagar, Gorakhpur, Imphal, Itanagar, Ajmer, Kohima, Patna and Srinagar.
The national nodal agency for responding to computer security incidents, established in 2004 under Section 70B of the Information Technology Act, 2000, and functioning under the Ministry of Electronics and Information Technology. It issues advisories, vulnerability notes and directions on incident reporting and log retention, and is the Knowledge Partner for this hackathon.
The national nodal agency for the protection of Critical Information Infrastructure, created under Section 70A of the Information Technology Act, 2000 by a gazette notification in January 2014. It is a unit of the National Technical Research Organisation (NTRO), unlike CERT-In which sits under MeitY - the two have complementary but distinct remits.
The Information Sharing and Analysis Center (ISAC Foundation) is a registered not-for-profit cyber security foundation operating as a Section 8 company in India, working on cyber security, AI and professional ethics. The National Security Database (NSD) is its professional recognition and certification project for information security practitioners; teams advancing beyond Round 1 receive NSD recognition credits and the jury includes National Cyber Security Scholars recognised under the NSD.
The parent statute for cyberspace in India. Section 70B creates CERT-In as the national nodal agency for incident response; Section 70A provides for the national nodal agency for Critical Information Infrastructure protection, under which NCIIPC was notified in January 2014; Section 70 deals with protected systems. Both agencies referenced in this hackathon draw their authority from this Act.
India's data protection statute, which received presidential assent on 11 August 2023 and provides for a Data Protection Board of India to enforce its obligations. It places security safeguards and breach-notification duties on data fiduciaries, making assessment and triage of security findings - the skill this hackathon scores - a compliance function and not only a technical one.
Approved in March 2024 with an outlay of Rs 10,371.92 crore over five years, it is the national programme building AI compute, datasets, skilling and safe-AI capacity under MeitY. A hackathon that allows any AI tool but scores human judgment over machine output sits directly on the safe-and-trusted-AI question the mission has to answer.
CERT-In covers the whole civilian internet ecosystem - government, enterprises and individuals - while NCIIPC has a narrower, deeper remit over designated critical information infrastructure and sits inside the intelligence structure as a unit of NTRO. The Section 70B versus Section 70A distinction is the most commonly tested fact in Indian cyber security governance.
NIELIT's route from the DOEACC Society (1994) to a renamed institute (2011) to a de novo Deemed to be University (2024) is the standard example of a certification body converted into a degree-granting institution, and it is the ministry's main instrument for electronics and ICT skilling.
The round names - Akhada, Dangal, Kesari - and the Gada awarded to the winner follow the naming convention now common in Indian government competitions; the release itself ties the Independence Day launch to the idea of independent judgment about machine-generated output.
GS Paper 3 > Science and Technology / Internal Security > Cyber security, its architecture and agencies
General Awareness > Institutions, Acts and Current Affairs
General Awareness > Current Affairs
Cyber security institutions and the IT Act provisions behind them are asked almost every year in Prelims and in general awareness papers; NIELIT recurs through its recruitment and skilling notifications.
A reported security finding that turns out not to be a real vulnerability; correctly rejecting these earns marks in CYBER KUSHTI 2026.
The conventional cyber security contest format in which teams race to discover hidden vulnerabilities or hidden tokens.
Computer resources whose incapacitation would debilitate national security, economy, public health or safety - protected under Section 70A of the IT Act through NCIIPC.
Under the DPDP Act, 2023, the entity that determines the purpose and means of processing personal data and carries the security and breach-notification obligations.