Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026:

The Central Electricity Authority (CEA) has notified the comprehensive Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 under the Electricity Act, 2003, coming into force from April 1, 2027.
- A statutory regulatory framework formulated by the CEA under Section 177 read with Section 73(c) of the Electricity Act, 2003 (with formal concurrence from the Ministry of Electronics and Information Technology – MeitY).
- It establishes binding cyber defense standards for entities owning, managing, or operating Operational Technology (OT) and interconnected Information Technology (IT) systems across India’s power sector.
- Aim is to build institutional cyber resilience across the Indian power sector, protect Critical Information Infrastructure (CII) and Industrial Control Systems (ICS) from external sabotage, prevent supply chain vulnerabilities, and ensure secure, uninterrupted electricity generation, transmission, and distribution.
Key Features of the Regulations:
- Broad Sectoral Scope & Generation Thresholds: Applies to all transmission utilities, distribution licensees, load dispatch centers, power exchanges, and OTC platforms.
- For generating companies, captive plants, and Energy Storage Systems (ESS), it applies to installations with a capacity of 50 MW and above.
- Institutional Governance (CISO & 24/7 Security Division): Mandates the appointment of a regular senior-level Chief Information Security Officer (CISO) and an Alternate CISO for a minimum 3-year tenure, supported by a dedicated, 24/7 operational Information Security Division within India.
- Physical & Logical IT-OT Network Isolation: Requires strict physical segregation of Operational Technology (OT) and Critical Information Infrastructure (CII) from the public Internet and general IT networks.
- Strict Incident Reporting Timelines: Mandates reporting of all cybersecurity incidents to CSIRT-Power and CERT-In within 6 hours, while incidents classified as cyber sabotage in critical systems must be reported within 24 hours.
- Rigorous Audit Cycles & Vulnerability Closure: Pre-commissioning audits (VAPT) are mandatory for new critical systems. Annual audits must have a 9-to-15 month gap.
- Identified critical/high-risk vulnerabilities must be resolved within 1 month, and medium/low-risk issues within 3 months.
- Data Localization & Domestic Security Perimeter: Sensitive operational and historical grid data—including information hosted on cloud platforms—must be encrypted, protected, and stored exclusively within India.
- Supply Chain Security & Prosumer Distributed Resources: Hardware and software must be procured from trusted sources, complete with a Software/Hardware Bill of Materials (BoM). Vendors of prosumer Distributed Generation Resources must ensure end-to-end encrypted communications and local data hosting.


