Transmission tower and wire.
India | News | Policy & Programmes

CEA notifies Cyber Security Regulations for India’s power sector

Transmission tower and wire.

The Central Electricity Authority (CEA) has notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, introducing a unified cyber security framework for entities across India’s power sector. The regulations will come into force on April 1, 2027, although selected provisions will be implemented later on dates to be notified separately.

The regulations prescribe cyber security requirements covering governance, operational technology (OT), information technology (IT), incident reporting, audits, procurement and supply chain security.

Coverage

The regulations apply to all entities that own, operate or manage OT infrastructure connected to the interconnected power system, along with IT infrastructure that is physically or logically connected to such OT systems.

They cover generating companies, captive generating plants and energy storage systems with an installed capacity of 50 MW or above. Power exchanges, over-the-counter trading platforms and vendors supplying equipment and services to the power sector are also covered under specified provisions. Entities below 50 MW are encouraged to implement baseline cyber security controls issued by the Indian Computer Emergency Response Team (CERT-In).

Governance

Each covered entity must appoint a Chief Information Security Officer (CISO) and an alternate CISO at the senior management level. Both must be Indian citizens and residents, possess an engineering degree or equivalent qualification, and have at least 15 years of experience in the power or IT sectors.

Entities must also establish a dedicated Information Security Division in India that operates round the clock.

The regulations require every entity to maintain a Cyber Security Policy, a Cyber Crisis Management Plan and an inventory of all cyber assets.

Operational safeguards

The regulations require critical systems to remain physically isolated from the internet and IT networks. Any exceptions must be supported by a risk assessment and approved by the entity’s head or board.

Remote access to cyber assets will be permitted only under controlled conditions with appropriate approvals and continuous monitoring. Remote operation of OT systems will be allowed only from within India through dedicated communication channels isolated from the internet.

Communication links carrying OT data between entities must also be secured against cyber threats.

Incident reporting

The Computer Security Incident Response Team-Power (CSIRT-Power), established by the Ministry of Power, will serve as the sector’s nodal agency for cyber security incidents.

Entities must report cyber security incidents to both CSIRT-Power and CERT-In within six hours. Incidents involving cyber sabotage of critical systems must be reported within 24 hours.

The Cyber Crisis Management Plan must be vetted by CERT-In, reviewed annually and tested through at least one mock drill every year.

Audit and procurement

The regulations mandate a comprehensive cyber security audit of critical systems at least once every financial year, with a gap of not less than nine months and not more than 15 months between audits.

Critical and high-risk vulnerabilities identified during audits must be addressed within one month, while medium- and low-risk vulnerabilities must be rectified within three months. Entities must also conduct annual self-audits, and the Ministry of Power’s Chief Information Security Officer may appoint a third-party auditor to verify compliance.

The regulations also require IT and OT equipment and services to be procured only from trusted sources in accordance with Central Government directions. Vendors will be required to provide security patches, recovery procedures, bills of materials, end-of-support details and vulnerability disclosure mechanisms.

Data protection

Sensitive information, including data hosted on cloud platforms, must be encrypted and stored exclusively within India. Entities must also adopt a data retention policy, with retention periods ranging from 180 days for logs to the full lifecycle of Factory Acceptance Test and Site Acceptance Test records.

Implementation

While the regulations take effect from April 1, 2027, the CEA will separately notify the implementation dates for provisions relating to Information Security Divisions, ISO/IEC 27001 or Technical Criteria Certificate compliance, mandatory cyber security training, procurement from trusted sources, deployment of perimeter cyber security devices for OT networks, and procurement of OT equipment from trusted sources.

The featured photograph is for representation only.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *