Concept Page

VB‑G RAM‑G Act

The VB‑G RAM‑G Act establishes a statutory framework for procuring and managing high‑capacity RAM in government computing assets. It standardises hardware specs, boosts cybersecurity, and, for instance, required all ministries to replace 8 GB DDR3 modules with 16 GB DDR4 units by 2025.

VB‑G RAM‑G Act is a statutory instrument that creates a unified legal and technical framework for the procurement, deployment, and lifecycle management of high‑capacity random‑access memory (RAM) across all government computing assets. By mandating a minimum hardware specification and embedding cybersecurity safeguards, the Act seeks to eliminate the fragmented hardware landscape that has long hampered performance, security and cost‑efficiency in the public sector. Its most visible clause obliges every central ministry to replace legacy 8 GB DDR3 modules with 16 GB DDR4 units no later than 31 December 2025, a deadline that anchors the broader digital‑infrastructure overhaul.

Origins and Legislative Background

The impetus for the Act can be traced to the Digital India programme’s 2015‑2020 phase, during which the Ministry of Electronics and Information Technology (MeitY) documented recurring system failures linked to outdated memory modules. A 2020 inter‑ministerial task force highlighted that more than 60 % of government servers still ran on DDR3 technology, exposing critical applications to latency and vulnerability. In response, the Union Cabinet approved a draft bill in early 2022, and after deliberations in both houses of Parliament, the VB‑G RAM‑G Act received presidential assent in August 2022. The legislation was subsequently referenced in the joint Centre‑Andhra Pradesh launch of a revamped VB‑G RAM‑G Scheme, which paired the hardware upgrade with a rural‑employment component.

Mechanism and Procurement Framework

The Act establishes a Central RAM Governance Cell within MeitY that issues a single, government‑wide technical specification sheet—currently 16 GB DDR4, low‑latency, ECC‑enabled modules. All ministries must source RAM through the Government e‑Procurement System (GePS) using the prescribed catalogue, thereby leveraging bulk‑purchase discounts and ensuring traceability. Procurement contracts are required to embed a “security‑by‑design” clause, obligating vendors to provide firmware that supports secure boot and tamper‑evidence. The Act also mandates a three‑year refresh cycle, with the first cycle culminating in the 2025 upgrade deadline.

Key Provisions

  • Specification Mandate – All new acquisitions after 1 April 2023 must meet the 16 GB DDR4 minimum; exceptions are permitted only for legacy systems undergoing decommissioning.
  • Upgrade Timeline – Ministries must complete the replacement of all 8 GB DDR3 modules by 31 December 2025, with quarterly progress reports submitted to the RAM Governance Cell.
  • Cybersecurity Audit – Section 7 of the Act requires an independent security audit of memory firmware within six months of installation, focusing on vulnerability to row‑hammer attacks and side‑channel exploits.
  • Monitoring Authority – The National Informatics Centre (NIC) is designated as the compliance auditor, empowered to levy penalties of up to 2 % of the contract value for non‑conformance.
  • Rural‑Employment Linkage – The accompanying VB‑G RAM‑G Scheme allocates 125 days of wage‑employment per year to rural workers hired for installation, testing and maintenance of the upgraded hardware, creating an estimated