ITAT Delhi Rules Standard Cybersecurity Software and Support Not Taxable as FTS under India–Ireland DTAA
1. Background and Parties Involved
Fireeye Ireland Limited, an Irish-incorporated company and a tax resident of Ireland, sells cybersecurity solutions globally, including in India. Its India-facing business model primarily involves:
- Sale of standard cybersecurity software products (on-premise and SaaS-type) through restricted user licences or subscriptions; and
- Incidental support services, largely in the nature of updates, upgrades, and routine support to ensure proper functioning of the software.
For Assessment Year (AY) 2020-21, the assessee reported income of Rs. 22,07,61,870 (primarily consulting income offered as taxable) and separately earned Rs. 53,39,55,995 from the sale of standard FireEye software products. The latter amount was not offered to tax in India, on the footing that it did not constitute either royalty or Fees for Technical Services (FTS) under the Income Tax Act 1961 or the India–Ireland Double Taxation Avoidance Agreement (DTAA).
For AY 2021-22, the factual matrix and nature of receipts were materially the same, and the assessment followed the pattern of AY 2020-21.
The ACIT, Circle International Tax-1(3)(1), New Delhi (ld. AO) framed assessments under Section 143(3) read with Section 144C(13) pursuant to directions of the Dispute Resolution Panel-1, New Delhi (DRP). The assessee carried both years to the Income Tax Appellate Tribunal, Delhi Bench (ITAT Delhi).
Since the issues were common, the Tribunal disposed both appeals by a single consolidated order, treating ITA No. 825/Del/2023 (AY 2020-21) as the lead appeal.
2. Core Dispute Before the Tribunal
2.1 Main Controversy
The central issue was whether:
- The consideration from sale and grant of restricted right to use standard cybersecurity software licences/subscriptions and related support services could be taxed in India as Fees for Technical Services:
- under
Section 9(1)(vii)of the Income Tax Act 1961, and - under
Article 12(3)(b)of the India–Ireland DTAA.
- under
The assessee’s consistent position was that these receipts:
- Represented business income from sale of standard software;
- Did not involve any transfer of copyright or intellectual property rights;
- Did not amount to rendering of managerial, technical or consultancy services;
- Were therefore not taxable in India absent a Permanent Establishment, and certainly not as FTS or royalty.
2.2 AO’s Stand
The ld. AO, relying heavily on the advanced technological nature of FireEye’s cybersecurity offerings, held that:
- The solutions were not merely standard software, but highly sophisticated, AI/ML-driven, behaviour-based, customised cybersecurity services;
- The activities involved machine learning, behavioural analysis, threat intelligence, advanced threat analytics, neural training models, neural architectures and artificial intelligence-based security engines;
- Such services were customer-specific, customized, and unique, not standard or uniform across users;
- Accordingly, consideration for these offerings was FTS under:
Explanation 2 to Section 9(1)(vii)of the Act, andArticle 12(3)(b)of the India–Ireland DTAA;
- The Supreme Court ruling in “Engineering Analysis Centre of Excellence Pvt. Ltd. vs CIT [2021] 125 taxmann.com 42 (SC)” was inapplicable on the facts.
On this basis, the AO taxed the amount of Rs. 53,39,55,995 for AY 2020-21 as FTS at 10% under the DTAA. A similar approach was adopted for AY 2021-22.
2.3 DRP Directions
During DRP proceedings, the assessee specifically relied upon Engineering Analysis Centre of Excellence Pvt. Ltd. vs CIT and pointed out that the India–Ireland DTAA itself was examined in that judgment. The DRP observed that:
The AO must specifically analyse the applicability or otherwise of the Supreme Court decision in Engineering Analysis and pass a speaking, reasoned order dealing with the assessee’s contention.
Pursuant to these directions, the AO revisited the matter but reiterated that:
- Given the nature of SaaS and AI/ML-driven services, the transaction was not on par with the software transactions considered in Engineering Analysis;
- Therefore, the AO concluded that the Supreme Court decision did not govern the assessee’s case.
3. Assessee’s Submissions Before ITAT
3.1 Nature of Software Products and Business Model
The assessee highlighted that:
It sells a range of standard FireEye software products in the cybersecurity domain, including:
- Network security tools,
- Network forensics,
- Email security,
- Endpoint security,
- Cloudvisory (cloud visibility and governance),
- Helix security operations (XDR platform),
- Detection on Demand (cloud-based file scanner).
These products are pre-packaged, off-the-shelf software, not developed or customized for any particular customer.
Distribution in India is largely through distributors, such as:
- Inflow Technologies Private Limited;
- iValue Info Solutions Private Limited;
among others.
End customers either download the software or access it through the cloud.
The software is licensed on a restricted, non-exclusive, non-transferable basis merely to use the product; there is:
- No right to copy (beyond installation/use limits),
- No right to sublicense,
- No right to modify or create derivative works,
- No right to reverse engineer, decompile or disassemble,
- No transfer of any copyright in the software or IP in the underlying technology.
To substantiate this, the assessee produced:
- Sample Distributor Agreements, and
- The End User License Agreement (EULA).
Key clauses relied upon included: