The Central Electricity Authority (CEA) has issued the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, establishing a comprehensive framework to strengthen cyber security across India’s power sector. The regulations were published in the Gazette of India on July 31, 2026, and the mandatory provisions will come into full effect from April 1, 2027.
The regulations apply to entities that own, operate, or manage Operational Technology (OT) and interconnected Information Technology (IT) systems in the power sector. Generating companies, captive power plants, and Energy Storage Systems (ESS) with a capacity of 50 MW or more are directly covered. Smaller entities below 50 MW are encouraged to implement basic cyber security controls recommended by CERT-In for micro, small and medium enterprises. Power exchanges, over-the-counter platforms, and technology vendors are also subject to relevant requirements.
Under the new framework, the Computer Security Incident Response Team – Power (CSIRT-Power) will serve as the central agency for coordinating cyber security incidents in the electricity sector. It will monitor threats, issue alerts, develop standard operating procedures, and coordinate with CERT-In and the National Critical Information Infrastructure Protection Centre (NCIIPC).
Covered organizations will have to appoint a senior regular employee as Chief Information Security Officer (CISO) for a minimum tenure of three years, along with an alternate CISO. They must also establish a 24-hour Information Security Division staffed with trained cyber security professionals.
The regulations require organizations to maintain a Cyber Security Policy, Cyber Crisis Management Plan, and updated Asset Register. These policies must be reviewed annually. Annual cyber security audits will also be mandatory, while the same audit agency cannot conduct audits for more than two consecutive years. Entities must additionally obtain ISO/IEC 27001 certification or meet equivalent technical requirements.
A major focus of the regulations is protecting OT systems that control critical power infrastructure. OT networks must be physically separated from the internet and conventional IT networks. Real-time operational data must be transferred through dedicated and secure communication channels, with critical data restricted to systems located within India.
Remote access to critical assets will be permitted only for emergency troubleshooting and must use multi-factor authentication, continuous monitoring, and detailed logging. Sensitive information and backups must also be encrypted and stored within India.
The framework places additional responsibilities on vendors supplying hardware, software, and cloud services. Vendors must provide tested recovery plans, digitally signed software patches, and a comprehensive Bill of Materials. Procurement must also comply with government requirements for trusted sources.
For distributed generation prosumers using cloud platforms, real-time operational data must be hosted within India and transferred through secure, encrypted communication channels.
The regulations also introduce strict incident reporting requirements. Cyber incidents must be reported to CSIRT-Power within six hours. Through mandatory audits, stronger institutional responsibilities, network segregation, data localization, and vendor accountability, the CEA aims to create a more resilient cyber security environment and protect India’s increasingly digital and interconnected electricity infrastructure.
Discover more from SolarQuarter
Subscribe to get the latest posts sent to your email.




