IIT B Cyber 2027 may expand to 3–4 more IITs and drop JEE Main. Know the proposed aptitude test, hackathon round, seat count and what it means for students.
Quick Summary
- IIT Kanpur is considering dropping JEE Main as the screening step for its four-year Bachelor of Cybersecurity (B Cyber) programme from the 2027 admission cycle.
- A dedicated aptitude test followed by a hackathon is the proposed replacement.
- Three to four more IITs are expected to start offering B Cyber from 2027, which could roughly triple the total seats.
- In 2026, IIT Kanpur (40 seats) and IIT Madras (50 seats) offered 90 seats between them, but only 52 students were admitted.
- Nothing is officially notified yet. Aspirants should wait for the formal announcement from the institutes.
Also Read: UIIC AO Salary 2026 Revised; Check Pay Scale, In-Hand Salary, Allowances & Perks
What Is Changing in IIT B Cyber Admission From 2027?
Students planning to study cybersecurity at an Indian Institute of Technology may face a very different admission route from 2027.
The Bachelor of Cybersecurity programme — commonly called B Cyber — was launched this year by IIT Kanpur and IIT Madras. It is a four-year undergraduate degree that sits outside the usual IIT admission pipeline. At IIT Kanpur, the programme runs under the Wadhwani School of AI and Intelligent Systems.
Two changes are now on the table for 2027:
- JEE Main may no longer be used for the first-level screening.
- More IITs are likely to join, expanding the number of available seats.
Both changes point in the same direction: admission is moving away from a purely marks-based filter and towards demonstrated skill.
Why JEE Main Could Be Dropped
When B Cyber launched for the 2026-27 session, IIT Kanpur already broke from tradition by not requiring a JEE Advanced score. Instead, candidates were shortlisted using their JEE Main score plus evidence of prior cybersecurity work — things like capture-the-flag (CTF) competition results, open-source contributions, bug bounty reports or independent security projects. Shortlisted candidates then sat an on-campus test that included an in-person hackathon.
IIT Kanpur’s own admission FAQ has already indicated that JEE Main will not be used going forward and that a separate entrance test will be announced.
The logic is straightforward. JEE Main tests Physics, Chemistry and Mathematics. It is an excellent filter for core engineering aptitude — but it says very little about whether a student can reverse-engineer a binary, spot a broken authentication flow in an API, or think like an attacker. For a programme built to produce security professionals, a subject-specific filter makes more sense than a general one.
Practical effect for students: a strong self-taught security background may count for more in this admission process than it does anywhere else in the IIT system.
Also Read: UIIC AO Selection Process and Exam Pattern 2026 (Revised): Prelims, Mains, Descriptive & Interview
The Proposed Aptitude Test: What to Expect
The proposed model has two stages:
Stage 1 — Aptitude test. Expected to assess problem-solving ability and foundational computer science knowledge, including programming and networking basics.
Stage 2 — Hackathon. A practical, monitored assessment held on campus.
The 2026 admission test at IIT Kanpur gives the clearest picture of the kind of content involved. Its published syllabus covered:
| Area | What it covers |
|---|---|
| Cryptography | Encryption basics, hashing, common cryptographic weaknesses |
| Web security | Injection flaws, authentication issues, session handling |
| API security | Endpoint abuse, broken access control, token handling |
| Network security | Protocols, traffic analysis, network-level attacks |
| Reverse engineering | Binary analysis, understanding compiled programs |
| OSINT | Open-source intelligence gathering and analysis |
| Operating systems | Linux and Windows internals |
| Cloud security | Misconfiguration, access management |
| Malware & threat analysis | Identifying and analysing malicious code |
The test was conducted on sanitised desktop systems under supervision by IIT Kanpur experts, and was designed to measure analytical thinking, curiosity and aptitude for cybersecurity rather than memorised theory.
The 2027 syllabus and exam schedule have not been released. Expect details in the coming months.
Seats in 2026: The Numbers Tell a Story
| Institute | Seats offered (2026) | Students admitted |
|---|---|---|
| IIT Kanpur | 40 | 32 |
| IIT Madras | 50 | 20 |
| Total | 90 | 52 |
Nearly 40 percent of seats went unfilled in the first year. That is not unusual for a brand-new programme with an unfamiliar name and an unfamiliar admission route — many aspirants and their families simply did not know it existed, or were unsure how it compared to a conventional B.Tech.
Both institutes are aiming to fill more seats in the next cycle. With three to four additional IITs expected to join, the combined seat count could reach roughly three times the current level.
For a student weighing options, an under-subscribed first-year programme is worth noticing. Competition is currently far lower than for a CSE seat at the same institutes.
What the B Cyber Programme Actually Involves
The course blends cybersecurity, computer science, artificial intelligence and systems.
The IIT Kanpur structure is unusual and worth understanding clearly:
- Years 1–2: Coursework on campus — classroom teaching, lab sessions and hands-on training.
- Years 3–4: Internship, primarily at selected government organisations. Some organisations may pay a stipend during this period.
- On completion: An IIT Kanpur degree and alumnus status.
IIT Kanpur Director Manindra Agrawal has described the programme as being meant especially for young ethical hackers, with the goal of producing cyber warriors for the future.
That two-year placement component is the defining feature. It is closer to an apprenticeship model than a standard engineering degree, and it means a graduate leaves with real operational experience rather than only academic exposure.
Why India Needs This Programme
India’s digital public infrastructure — payments, identity, healthcare records, telecom — has scaled faster than the security workforce protecting it. Ransomware incidents, data breaches at large enterprises and attacks on critical infrastructure have all risen sharply in recent years.
The demand is visible in the job market too. Security roles in India — SOC analyst, penetration tester, security engineer, threat intelligence analyst, cloud security specialist — consistently show high vacancy rates and salary premiums over general software roles, because supply is thin.
A dedicated undergraduate pipeline into government security organisations addresses a specific national gap rather than a general one.
What This Means for Students and Job Seekers
If you are a Class 11 or 12 student interested in security: Start building a demonstrable portfolio now. CTF participation (CTFtime rankings, TryHackMe, HackTheBox), a GitHub profile with security tooling, responsible disclosure reports, and a working knowledge of Linux and networking are all things this admission process is designed to reward. These carry weight in a way they simply do not in JEE-based admissions.
If you are already in a different degree: The B Cyber route is an undergraduate entry point, so it will not apply to you. But the same skill signals — practical, provable, portfolio-based — are exactly what security employers screen for. Certifications like CompTIA Security+, eJPT, OSCP and cloud security credentials serve a similar function in the hiring market.
If you are a parent evaluating this option: The programme awards a full IIT degree with alumnus status. The trade-off is that the final two years are spent in an internship placement rather than on campus, and the career path is more specialised than a general CSE degree. That specialisation is an advantage in a shortage market and a constraint if the student later wants to pivot broadly.
Important caution: none of the 2027 changes are final. Do not build an entire preparation plan around a dropped JEE Main until the institutes confirm it officially. A sensible approach is to keep JEE Main preparation on track while building security skills in parallel — that keeps both doors open.

Frequently Asked Questions
Q. Is JEE Main definitely being dropped for B Cyber 2027?
Not officially confirmed by a formal notification. IIT Kanpur has indicated JEE Main will not be used and that a separate entrance test will be announced, but students should wait for the official admission brochure.
Q. Was JEE Advanced ever required for B Cyber?
No. Even in the first cycle, JEE Advanced was not required. Only JEE Main was used, and only for shortlisting.
Q. Which IITs offer B Cyber right now?
IIT Kanpur and IIT Madras. Three to four more IITs are expected to join from 2027, but the specific institutes have not been named.
Q. How many seats will be available in 2027?
Not announced. If the expansion happens as reported, the total could be around three times the current 90 seats.
Q. Do I get a regular IIT degree?
Yes. Students who complete the programme receive an IIT degree and alumnus status.
Q. Is there a stipend during the internship years?
Some of the government organisations hosting interns may pay a stipend. This is not guaranteed across all placements.
Q. What should I study for the aptitude test?
The 2027 syllabus is not out. Based on the 2026 test, focus on cryptography, web and API security, network security, reverse engineering, OSINT, Linux and Windows internals, and cloud security fundamentals — alongside general programming and problem-solving.