site-logo
site-logo
site-logo

CEA (Cyber Security in Power Sector) Regulations, 2026: Practical compliance and implementation guide

CEA (Cyber Security in Power Sector) Regulations, 2026: Practical compliance and implementation guide

CEA (Cyber Security in Power Sector) Regulations, 2026: Practical compliance and implementation guide

blog-details-image
author

Team Shieldworkz

PART I — EXECUTIVE OVERVIEW

What the regulations are

The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 were notified in the Gazette of India on 31 July 2026. Issued under Section 177 of the Electricity Act, 2003 with the concurrence of the Ministry of Electronics and Information Technology (MeitY), these regulations transform India's power-sector cybersecurity framework from the previous advisory/voluntary guidelines (2021) into a binding, statutory compliance mandate with defined evidence obligations and audit trails.

Timelines and effective dates

Notification Date: 31 July 2026

  • General Commencement / Enforcement Date: 1 April 2027 (providing entities an 8-month implementation window).

  • Deferred Sub-Regulations: Six specific provisions—Regulations 5(9) (24x7 Information Security Division), 5(24) (Mandatory ISO/IEC 27001 Certification), 5(33) (Mandatory Cyber Security Training), 5(39) (Trusted-Source Procurement for IT), 6(2) (OT Perimeter Hardware Security), and 6(7) (Trusted-Source Procurement for OT)—are deferred and will come into force on separate dates to be notified by the Authority.

Why they matter to India's power sector

As the power sector becomes increasingly digitized and interconnected (via Smart Grids, SCADA, EMS, DMS, and IoT-based substations), the threat vector to critical energy infrastructure expands exponentially. The 2026 Regulations establish a mandatory baseline for cyber resilience, preventing cascade grid failures caused by cyberattacks, cyber sabotage, or supply-chain compromises.

What organizations need to do

Covered entities must transition from informal cybersecurity to a structured, evidence-backed program. This involves appointing a statutorily qualified Chief Information Security Officer (CISO), enforcing physical and logical IT/OT isolation, maintaining a real-time Cyber Asset Register, operationalizing a 6-hour incident reporting workflow, and undergoing mandatory third-party audits by CERT-In empanelled auditors.

What this means for Indian power companies

In Short: Cybersecurity is no longer an IT recommendation or a voluntary checklist—it is an audited law with personal accountability for C-level executives. You must treat Operational Technology (OT) networks with the same or higher priority than corporate IT, isolate control systems from the internet, strictly vet vendors touching your grid assets, and be ready to prove every control to a CERT-In auditor.

PART II — WHO MUST COMPLY?

The Regulations do not treat all power sector participants identically. Capacity thresholds apply specifically to generation, captive plants, and Energy Storage Systems (ESS), whereas transmission, distribution, grid operators, and exchanges are covered without capacity qualifiers.

Applicability matrix

Entity Category

Applicability

Threshold / Condition

Key Obligations

Exemptions / Exceptions

Relevant Clause

Generating Companies / Stations

Mandatory

Installed Capacity

 50 MW

Full IT/OT cybersecurity governance, CISO, OT segmentation, audits, vendor management.

Generating units below 50 MW.

Reg 3(1)(a) / Reg 4

Captive Generating Plants

Mandatory

Aggregate Capacity

 50 MW

OT network isolation, Cyber Asset Register, incident reporting, audits.

Captive units under 50 MW not grid-connected to critical nodes.

Reg 3(1)(b) / Reg 4

Renewable Energy Entities (RE)

Mandatory

Aggregate Capacity

 50 MW at Point of Interconnection

Secure inverter/SCADA communication, OT perimeter protection, air-gapping.

Small solar/wind plants below 50 MW.

Reg 3(1)(c) / Reg 4

Energy Storage Systems (ESS)

Mandatory

Installed Capacity

 50 MW / MWh

BESS/PSP control system security, local time sync, audit compliance.

Systems below 50 MW.

Reg 3(1)(d) / Reg 4

Transmission Licensees (CTU, STU, TBCB)

Mandatory

No minimum threshold (All licensees)

Substation automation security, SCADA/EMS protection, NCIIPC CII compliance.

None.

Reg 3(1)(e) / Reg 4

Distribution Licensees (State, Private, Deemed)

Mandatory

No minimum threshold (All licensees)

Smart meter / AMI security, DMS/ADMS hardening, OT isolation, customer data localization.

None.

Reg 3(1)(f) / Reg 4

System Operators (NLDC, RLDCs, SLDCs)

Mandatory

No minimum threshold (All Despatch Centres)

Extreme availability controls, air-gapped EMS, 24x7 SOC, 6-hr reporting.

None.

Reg 3(1)(g) / Reg 4

Power Exchanges & OTC Platforms

Mandatory

All registered exchanges

Corporate IT security, trading engine protection, data localization.

Exemptfrom OT-specific (Reg 6) & vendor supply chain (Reg 7) chapters.

Reg 3(1)(h) / Reg 4

Equipment Vendors / System Integrators

Mandatory

Entities supplying IT/OT products/services to power sector

Trusted sources procurement, NDA, personnel vetting, SLA security clauses.

Vendors supplying purely non-critical commodity items.

Reg 7 / Reg 8

 

PART III — COMPLETE CEA CYBERSECURITY COMPLIANCE CHECKLIST

Status Key:

Mandatory: Explicitly required by the text of the 2026 Regulations.

Conditional: Depends on specific triggers (e.g., deferred sub-regulations, interconnections).

Recommended: Good engineering practice aligned with CEA intent.

 

#

Compliance Requirement

What the Organization Must Do

Classification

Evidence Required

Responsible Owner

Timeline / Frequency

Clause Ref.

1

CISO Appointment

Designate a CISO & Alternate CISO (Indian citizen, regular senior employee, degree qualified,

15 yrs experience) ring-fenced to cybersecurity alone.

Mandatory

Board resolution, HR appointment letter, qualification proof, published details.

Board / HR

Before 1 Apr 2027 (3-yr tenure)

Reg 5(1)-(3)

2

Cyber Security Policy

Draft, approve, and implement an overarching policy covering 33 mandated domains (access, incident response, supply chain, asset handling, etc.).

Mandatory

Approved Policy Document, Board Approval Minutes, Annual Review Logs.

CISO

Annual Review

Reg 5(4)

3

24x7 Information Security Division (ISD)

Establish a dedicated, operational 24x7 ISD/SOC for continuous threat monitoring and response.

Conditional(Deferred)

ISD organizational charter, SOC shift logs, SIEM setup documents.

CISO / Head IT

Separate CEA Notification Date

Reg 5(9)

4

Cyber Asset Register

Maintain a dynamic, detailed inventory of all IT and OT assets, connected devices, firmware versions, and ownership.

Mandatory

Master Cyber Asset Register (Excel/DB), Change Logs, Verification Sign-offs.

OT/IT Asset Owners

Reviewed annually or upon asset change

Reg 5(12)

5

ISO/IEC 27001 Certification

Obtain formal ISO/IEC 27001 certification for all Critical Information Infrastructure (CII) and critical IT/OT systems.

Conditional(Deferred)

Valid ISO 27001 Certificate, Statement of Applicability (SoA), External Audit Reports.

CISO / Quality Lead

Separate CEA Notification Date

Reg 5(24)

6

Cybersecurity Training & Awareness

Conduct mandatory cybersecurity training for all employees and specialized training for OT personnel.

Conditional(Deferred)

Training materials, Attendance logs, Post-training assessment scores.

CISO / HR

Separate CEA Notification Date

Reg 5(33)

7

Trusted-Source Procurement (IT)

Procure IT hardware, software, and cloud services only from trusted sources/vendors designated by government bodies.

Conditional(Deferred)

Vendor evaluation sheets, Trusted Source certificates, Purchase Order clauses.

Procurement / CISO

Separate CEA Notification Date

Reg 5(39)

8

OT Internet & IT Isolation

Maintain absolute physical isolation (air-gap) between OT networks and the Internet/IT. Interconnection requires explicit exceptions.

Mandatory

Network Architecture diagrams, Physical inspection logs, Firewall/Data-Diode rules.

Head OT / Network Head

Immediate / Continuous

Reg 6(1)

9

OT Interconnection Exception Governance

If OT-IT/Internet connection is unavoidable, perform documented risk assessment and obtain Board-level explicit approval.

Conditional(On Interconnection)

Risk Assessment report, Board Approval Resolution, Hardening controls documentation.

CISO / COO

Prior to connection enablement

Reg 6(1)

10

OT Perimeter Security Hardware

Deploy dedicated, hardware-based boundary security devices (e.g., unidirectional data diodes) at OT perimeters.

Conditional(Deferred)

Purchase orders, Architecture designs, Device configuration backups.

Head OT

Separate CEA Notification Date

Reg 6(2)

11

Trusted-Source Procurement (OT)

Procure OT equipment (PLCs, RTUs, IEDs, SCADA) exclusively from trusted equipment manufacturers and sources.

Conditional(Deferred)

Vendor declaration forms, Trusted product clearance certificates.

Procurement / OT Head

Separate CEA Notification Date

Reg 6(7)

12

Incident Reporting (6-Hour Clock)

Report all confirmed cyber incidents to CSIRT-Power and CERT-In within 6 hours of detection.

Mandatory

Incident logbook, Time-stamped initial notification email/portal copy.

Incident Response Lead / CISO

Within 6 hours of confirmed detection

Reg 5(18)

13

Sabotage Escalation (24-Hour Clock)

Submit a detailed secondary report within 24 hours if an incident involves concluded cyber sabotage in critical systems.

Conditional(On Sabotage)

Detailed Root Cause Analysis (RCA) report, Forensic summary, Ministry report copy.

CISO / Legal

Within 24 hours of confirmation

Reg 5(19)

14

Data Localization & Encryption

Store and process all sensitive power system data exclusively within India; enforce strong encryption at rest and in transit.

Mandatory

Data architecture maps, Cloud hosting location certificates, Encryption config logs.

CISO / CIO

Continuous

Reg 5(15)

15

Annual Comprehensive Cyber Audit

Undergo an annual cybersecurity audit by CERT-In empanelled auditors (9-15 months spacing between cycles).

Mandatory

CERT-In Auditor Engagement Letter, Final Audit Report, Management Response.

CISO

Annually (rotate auditor after 3 yrs)

Reg 8(1)-(4)

16

Audit Remediation Timelines

Remediate Critical and High-risk audit findings within 1 month; Medium and Low findings within 3 months.

Mandatory

Remediation Tracking Matrix, Re-test reports, Closure certificates signed by CISO.

Asset Owners / CISO

High/Crit: 1 Month; Med/Low: 3 Months

Reg 8(5)

17

Vendor SLAs & Personnel Risk Assessment

Embed CEA cybersecurity clauses in vendor contracts, require NDAs, and enforce personnel background checks for vendor staff with OT access.

Mandatory

Vendor Contracts, Signed NDAs, Background Verification (BGV) confirmation logs.

Procurement / Legal / CISO

Prior to giving vendor access

Reg 7(1)-(3)

18

Time Synchronization (Non-Public IP)

Synchronize all IT and OT system clocks to a reliable, secure time source off the public internet (e.g., local stratum NTP / IRNSS/GPS).

Mandatory

NTP Server topology, Configuration files showing non-public IP time source.

OT Head / Network Head

Continuous

Reg 6(4)

 

PART IV — CEA REGULATION → PRACTICAL CONTROL MAPPING

Translate the regulatory text into technical architectures across OT, Control Centers, and Corporate IT environments.

CEA Requirement

Security Objective

Practical Control

Technology / Process

Compliance Evidence

Reg 6(1) Default OT Isolation

Prevent remote cyberattacks originating from corporate IT or internet from reaching OT.

Complete air-gap or strict unidirectional DMZ boundary between Purdue Levels 2/3 and Level 4.

Hardware Data Diodes, Industrial Dual-homed DMZ Firewalls, Jump Hosts.

Network Topology Diagrams, Firewall Rule Base Audits, Switch Port Configurations.

Reg 5(12) Cyber Asset Register

Maintain 100% visibility over all hardware/software assets in IT and OT.

Passive OT network listening and automated asset discovery (no active scanning in live OT).

Passive OT Network Detection & Response (NDR) tools, Asset Management DB.

Asset Inventory Export, MAC/IP Binding tables, Annual physical verification sign-off.

Reg 6(4) Secure Time Sync

Prevent log tampering and ensure precise forensic timeline correlation.

Establish internal, air-gapped NTP servers receiving sync via NavIC/GPS/IRNSS receivers.

Local Stratum-1 NavIC/GPS NTP Master Clock

NTP Configuration files, Time Drift Alert Logs, Local NTP server Status Screenshots.

Reg 5(18) 6-Hour Incident Reporting

Rapid notification to national authorities to contain sector-wide threats.

Pre-configured incident intake workflows, automated SOAR playbooks, rehearsed reporting templates.

Incident Management Portal, Dedicated escalation call trees, CERT-In reporting forms.

Time-stamped notification receipts from CSIRT-Power & CERT-In portal.

Reg 5(15) Data Localization & Encryption

Protect critical energy data from unauthorized extra-territorial access.

Restrict all cloud hosting to Indian data centers; enforce AES-256 for data at rest, TLS 1.3 in transit.

On-premise DBs, Indian Hyperscaler clouds (MeitY empanelled), KMS.

Cloud tenant region confirmation reports, SSL/TLS Cipher suite audit reports.

Reg 7(2) Vendor Personnel Vetting

Mitigate insider threats and supply chain compromises via contractors.

Enforce mandatory background checks, identity checks, and signed non-disclosure agreements.

Vendor Onboarding Portal, Police Verification certificates, PAM jump servers.

BGV Clearance logs, PAM Session Video Recordings, Executed NDAs.


Implementation across OT assets

  • SCADA / EMS / DMS: Air-gapped control networks; centralized syslog export to passive monitoring; restricted engineering commands.

  • PLCs / RTUs / IEDs: Disable unused physical and logical ports (HTTP, Telnet); lock configuration switches; maintain baseline firmware hashes.

  • Engineering Workstations: Dedicated, hardened laptops with no internet connectivity; USB port locking software; multi-factor authentication (MFA) for access control.

  • Substation Automation & Field Networks: Implement IEC 62443 zone/conduit models; segregate IEC 61850 GOOSE/MMS traffic using VLANs.

PART V — CEA COMPLIANCE ROADMAP (0–12 MONTHS)

Given the 1 April 2027 commencement date, this 12-month implementation sequence bridges the working period between official notification and mandatory enforcement.


 

| Phase 0: Immediate Readiness (Months 1–2) | Formally designate CISO & Alternate CISO. Notify Board & publish contact details. Form Steering Committee. | CISO Board Resolution, Public Contact Notice, Charter. | Board / Legal / HR | Reg 5(1)-(3) | Board Resolution, HR File, Email Notification. |

| Phase 1: Policy & Gap Assessment (Months 2–3) | Review current state against 33 policy domains. Draft/update Cyber Security Policy. Conduct gap assessment. | Approved Cyber Security Policy, Gap Assessment Report. | CISO / Steering Comm | Reg 5(4) | Signed Policy Document, Gap Analysis Matrix. |

| Phase 2: Asset Discovery & Register (Months 3–4) | Deploy passive OT discovery. Build comprehensive Cyber Asset Register for all IT & OT. | Master Cyber Asset Register, OT Asset Map. | CISO / OT Head / IT Head | Reg 5(12) | Inventory DB Export, Verification Sign-off. |

| Phase 3: IT/OT Architecture (Months 5–6) | Isolate OT from IT/Internet. Apply DMZs/Data Diodes. Setup non-public local NTP clocks. | Architecture Blueprints, Exception Board Filings, NTP Setup. | Head OT / Network Lead | Reg 6(1), 6(4) | Network Diagrams, Firewall Configs, NTP Logs. |

| Phase 4: Incident Response & Logging (Months 7–8) | Build 6-hour incident reporting workflow to CERT-In / CSIRT-Power. Implement local log aggregators. | Incident Response Plan, Escalation Flowcharts. | Incident Lead / CISO | Reg 5(18)-(19) | Time-stamped Test Logs, IR Simulation Reports. |

| Phase 5: Supply Chain Controls (Months 9–10) | Update vendor contracts with security clauses. Implement vendor BGV & remote access controls. | Vendor SLA Templates, NDA Repository, PAM Logs. | Procurement / Legal / CISO | Reg 7(1)-(3) | Executed Contracts, BGV Certificates. |

| Phase 6: VAPT & Audits (Months 10–11) | Engage CERT-In empanelled auditor. Perform IT/OT VAPT and Comprehensive Cyber Audit. | Pre-audit VAPT Report, Official Cyber Audit Report. | CISO / CERT-In Auditor | Reg 8(1)-(4) | Auditor Report, Remediation Plan. |

| Phase 7: Remediation & Continuous (Months 11–12) | Close Critical/High findings within 1 month. Establish ongoing operational maintenance. | Audit Closure Certificate, Board Compliance Submission. | CISO / Executive Mgmt | Reg 8(5) | Sign-off Letter to CEA / Ministry. |

PART VI — "WHAT SHOULD THE CISO DO FIRST?"

30 / 60 / 90-Day Executive Action Plan

First 30 Days: Mandatory Baseline & Governance

  1. Formalize CISO & Alternate CISO Appointment: Ensure employment contracts, Indian citizenship criteria, and 3-year minimum tenure align with statutory provisions.

  2. Establish Cyber Security Steering Committee: Include Heads of OT, IT, Transmission/Generation Operations, Legal, and HR.

  3. Notify Executive Leadership & Board: Brief the Board on the 1 April 2027 enforcement timeline and personal liability structures.

  4. Draft Mandated Cyber Security Policy: Align existing corporate security policies with the 33 mandatory domains specified in Regulation 5(4).

Days 31–60: Inventory, Architecture & Isolation

  1. Initiate Passive OT Asset Discovery: Deploy non-intrusive network listening tools across control centers, plants, and substations to populate the Cyber Asset Register.

  2. Audit OT-IT Interconnections: Identify all physical and logical connections between OT networks and corporate IT/Internet. Sever unauthorized links immediately.

  3. Formulate Exception Filings: Prepare formal risk assessments and Board resolution filings for any operational interconnections that cannot be air-gapped.

  4. Audit Time Sources: Verify that all SCADA, DCS, PLCs, and historians are receiving time synchronization from local, non-public IP sources (NavIC/GPS master clocks).

Days 61–90: Incident Readiness & Supply Chain Integration

  1. Operationalize the 6-Hour Reporting Workflow: Establish an internal detection-to-reporting mechanism capable of notifying CERT-In and CSIRT-Power within 6 hours of incident confirmation.

  2. Update Vendor Onboarding Protocols: Draft mandatory security addendums, NDAs, and personnel background verification (BGV) requirements for all OT/IT suppliers.

  3. Designate Empanelled Audit Partner: Initiate engagement processes for a CERT-In empanelled auditing firm to schedule the mandatory comprehensive audit.

Top 10 High-Priority Actions That Cannot Wait

  1. Ring-Fence the CISO Role: Terminate dual-hatting (e.g., CIO acting as CISO). The CISO must focus exclusively on cybersecurity.

  2. Sever Direct OT Internet Connections: Immediately disconnect cellular modems, dual-homed engineering laptops, and direct remote-access tools attached to live OT networks.

  3. Freeze Undocumented OT Changes: Enforce strict change control; no unauthorized firmware updates or device swaps in control rooms.

  4. Establish the Master Cyber Asset Register: Begin discovery immediately; building an accurate OT inventory takes months.

  5. Rehearse the 6-Hour Reporting Clock: Run a mock exercise to ensure technical detection escalates to CISO notification within 2 hours, leaving 4 hours for regulatory filings.

  6. Enforce Local Data Residency: Verify that no power plant operational data or grid telemetry is hosted on foreign cloud servers.

  7. Secure Engineering Workstations: Lockdown USB ports and restrict local administrator rights on all laptops used to configure PLCs/RTUs.

  8. Enforce Vendor Personnel Vetting: Require background check documentation for every third-party engineer entering substations or control rooms.

  9. Implement Non-Public Time Sync: Audit NTP sources across all operational nodes to ensure independence from public internet servers.

  10. Budget for CERT-In Third-Party Audits: Allocate capital and operational expenditure for annual independent audits and immediate remediation buffers.

PART VII — EVIDENCE & AUDIT READINESS

An auditor empanelled by CERT-In will evaluate documentary proof of compliance. The evidence matrix below outlines what must be maintained.

Regulatory Audit Evidence Checklist

Evidence Category

Required Document / Artifact

Corresponding Regulatory Ref.

Retention / Review Requirement

Governance & Roles

CISO Appointment Letter, HR Qualification Verification, Indian Residency Proof.

Reg 5(1)-(3)

Retain for CISO tenure + 3 years.

Governance & Roles

Board Minutes approving CISO appointment and Cyber Security Policy.

Reg 5(4)

Permanent record.

Policy Framework

Formal Cyber Security Policy document covering 33 mandated domains.

Reg 5(4)

Annual review evidence.

Asset Management

Master Cyber Asset Register (hardware, software, firmware, location, owner).

Reg 5(12)

Real-time / Annual sign-off.

Architecture & Isolation

Network Architecture Diagrams (signed by Head OT), Data Diode/Firewall Configuration Files.

Reg 6(1)

Maintain current state + historical change logs.

Architecture & Isolation

Documented Risk Assessment and Board Approval for any OT-IT Interconnection.

Reg 6(1)

Valid for duration of connection.

Time Sync

Local NTP Architecture Diagram and Stratum-1 Clock Sync Logs.

Reg 6(4)

12 months rolling logs.

Incident Management

Incident Response Plan, CERT-In / CSIRT-Power initial report copies (time-stamped).

Reg 5(18)-(19)

Retain for 5 years.

Data Protection

Data Localization Attestation, Database/Disk Encryption Verification Certificates.

Reg 5(15)

Annual verification.

Supply Chain

Contracts with CEA cybersecurity clauses, Signed Vendor NDAs, Staff BGV Clearance Logs.

Reg 7(1)-(3)

Duration of contract + 3 years.

Audit & Remediation

Final CERT-In Empanelled Audit Report, Closure Tracking Matrix signed by CISO.

Reg 8(1)-(5)

Retain for 5 years.

PART VIII — IT/OT-SPECIFIC COMPLIANCE

Operational Technology (OT) drives physical power delivery. Applying standard IT security practices directly to OT can cause inadvertent operational outages. Compliance in OT requires engineered safeguards tailored to high-availability environments.

 

 

Key OT compliance operating principles

  • Safety and Availability First: OT security controls must never compromise physical safety or process availability. Active vulnerability scanning on live control networks (Level 0–2) is strictly prohibited. Asset discovery and threat monitoring must rely entirely on passive network tap / SPAN port traffic inspection.

  • Patching Limitations & Mitigating Controls: Industrial controllers (PLCs, RTUs) often cannot be patched without long planned outage windows or vendor re-certification. Where immediate patching is unfeasible, entities must document a formal compensating control plan (e.g., network micro-segmentation, protocol filtering, strict jump-host access).

  • Legacy Systems Handling: Legacy systems running end-of-life operating systems must be isolated behind dedicated industrial firewalls or terminal servers, enforcing strict protocol whitelisting (e.g., allowing only IEC 60870-5-104 or Modbus TCP from designated IP addresses).

  • Vendor Remote Maintenance: Direct inbound vendor remote access (e.g., TeamViewer, AnyDesk) is explicitly prohibited. Remote vendor sessions must go through a secure OT DMZ Jump Host using Multi-Factor Authentication (MFA), session recording, and real-time approval/monitoring by a plant engineer.

  • USB & Maintenance Laptops: Portable devices represent a primary infection vector for air-gapped systems. All vendor or engineering laptops must undergo malware scanning at a dedicated kiosk before connecting to OT networks. USB ports on engineering stations must be physically locked or controlled via endpoint management agents.

PART IX — GAP ASSESSMENT FRAMEWORK

Organizations can use this maturity model to evaluate compliance readiness against the 2026 Regulations.

Scoring Scale

  • 0 — Not Implemented: No process or controls exist.

  • 1 — Initial / Ad-hoc: Unofficial, inconsistent activities.

  • 2 — Partially Implemented: Documented but incomplete execution across assets.

  • 3 — Fully Implemented: Fully operational and aligned with CEA requirements.

  • 4 — Measured / Audit-Ready: Measured, continuously monitored, and backed by complete evidence trails.

Operational assessment matrix

Compliance Domain

CEA Requirement Baseline

Current State (0-4)

Identified Gap

Business & Regulatory Risk

Target Priority

Remediation Action

Owner

Governance

Statutorily qualified CISO appointed for a 3-year term.


CIO currently doubles as CISO.

Regulatory non-compliance, conflict of interest.

P0

Appoint dedicated CISO, pass Board resolution.

Board / HR

OT Isolation

Physical air-gap between OT and IT/Internet.


OT historian linked directly to corporate network.

Critical vulnerability to external malware/ransomware.

P0

Install dual-homed DMZ firewall and data diode.

Head OT

Asset Register

Complete Cyber Asset Register for IT & OT.


Partial Excel sheet for IT only; OT missing.

Inability to define audit scope or detect rogue devices.

P1

Deploy passive OT asset discovery tool.

CISO / OT Lead

Time Sync

Non-public time source for all system logs.


SCADA syncing via public NTP servers.

Regulatory failure; log timestamp invalidation during forensics.

P1

Install NavIC/GPS stratum-1 time server locally.

OT Head

Incident Response

Reporting to CERT-In / CSIRT-Power within 6 hours.


Informal process taking >24 hours to report.

Statutory violation, regulatory penalties.

P0

Implement SOAR playbook and 2-hour internal escalation.

CISO / IR Lead

Supply Chain

Vendor background checks and cybersecurity contracts.


Contracts lack specific CEA clauses.

Third-party supply chain compromise.

P2

Amend procurement templates and NDA rules.

Procurement

Third-Party Audit

Annual audit by CERT-In empanelled auditor.


Audits done irregularly by non-empanelled firm.

Rejection of compliance report by CEA/Ministry.

P0

Issue RFP for CERT-In empanelled auditing firm.

CISO

 

PART X — MANAGEMENT & BOARD DASHBOARD

 

 

 

PART XI — COMMON MISINTERPRETATIONS

#

Common Misconception

What the Regulations Actually Say

Correct Interpretation

Operational / Practical Implication

1

"The 2026 Regulations are just updated recommendations, like the 2021 guidelines."

The 2026 Regulations were notified under Section 177 of the Electricity Act, 2003 as binding statutory regulations.

Compliance is legally mandatory with statutory enforcement, not voluntary guidance.

Non-compliance can be escalated to the Ministry of Power and regulatory authorities.

2

"All sub-regulations must be implemented by 1 April 2027."

Six specific sub-regulations (5(9), 5(24), 5(33), 5(39), 6(2), 6(7)) are explicitly deferred to separate notification dates.

Baseline compliance begins 1 April 2027, but deferred items carry independent future deadlines.

Do not delay baseline readiness while waiting for deferred provision dates.

3

"Every power entity under 50 MW is completely exempt from the regulations."

The 50 MW threshold applies only to generating plants, captive units, and ESS. Transmission, distribution, and load despatch centers have no capacity threshold.

All transmission/distribution utilities and SLDCs must fully comply regardless of megawatt capacity.

Small DISCOMs or private transmission lines cannot claim capacity exemption.

4

"Any CERT-In empanelled auditor can audit us forever."

Regulation 8 mandates auditor rotation after three consecutive engagements.

Empanelled auditors must be rotated every 3 years.

Procurement teams must track auditor tenure to prevent invalid audit submissions.

5

"We can run active vulnerability scans on our live SCADA networks to build our asset register."

Regulation 6 mandates non-disruptive, safe operational technology practices. Active scanning on live OT can crash legacy PLCs.

Asset identification in live OT must use passive traffic monitoring and non-intrusive discovery.

Standard IT active vulnerability scanners (e.g., Nessus active sweeps) must not be run on live OT subnets.

 

PART XII — MASTER CEA COMPLIANCE TO-DO LIST

This master checklist can be copied directly into spreadsheet tools (Excel / Google Sheets) for program tracking.

Priority

Action Item

Regulatory Basis

Responsible Owner

Target Due Date

Primary Evidence Artifact

Status

P0

Appoint statutorily eligible CISO & Alternate CISO (3-yr tenure, Indian citizen).

Reg 5(1)-(3)

Board / HR

30 Days

Board Resolution & Appointment Letter.

Open

P0

Physically isolate OT networks from IT and Internet.

Reg 6(1)

Head OT / IT

60 Days

Network Diagrams & Firewall Rule Audit.

Open

P0

Establish 6-hour incident reporting workflow to CERT-In & CSIRT-Power.

Reg 5(18)

CISO / IR Lead

60 Days

Incident Escalation Plan & Test Log.

Open

P0

Engage CERT-In empanelled auditor for annual comprehensive audit.

Reg 8(1)-(4)

CISO / Proc.

180 Days

Auditor Contract & Empanelment Proof.

Open

P1

Build complete Cyber Asset Register for all IT and OT assets.

Reg 5(12)

CISO / Asset Owners

90 Days

Master Cyber Asset Database.

Open

P1

Update Cyber Security Policy to cover all 33 mandated domains.

Reg 5(4)

CISO

90 Days

Approved Policy Document & Board Minutes.

Open

P1

Install local NavIC/GPS NTP server for non-public OT time synchronization.

Reg 6(4)

Head OT

120 Days

NTP Server Config & Stratum Sync Logs.

Open

P1

Mandate data localization (India residency) and encryption for all sensitive data.

Reg 5(15)

CIO / CISO

120 Days

Cloud Residency Attestation & Cipher Logs.

Open

P2

Embed CEA security clauses, NDAs, and personnel BGV requirements into vendor contracts.

Reg 7(1)-(3)

Procurement / Legal

150 Days

Signed Vendor Contracts & NDAs.

Open

P2

Establish remediation workflow: High/Critical in 1 month, Med/Low in 3 months.

Reg 8(5)

CISO / IT / OT

180 Days

Audit Remediation Tracker.

Open

P3

Plan readiness for deferred provisions (24x7 SOC, ISO 27001, Trusted Procurement).

Reg 5(9), 5(24), 5(39), 6(2), 6(7)

CISO

Continuous

Budget Allocation & Strategy Paper.

Open


Book a free briefing on CEA Cyber Security in Power Sector
Regulation 2026

Recommended reading

Download the CEA Cyber Security in Power Sector Regulation 2026 compliance checklist

More about this new regulation

 

Disclaimer: This document is intended solely as a practical cybersecurity compliance guide and does not constitute legal advice. Organizations should refer to the officially notified CEA Regulations in the Gazette of India and applicable directions or clarifications from competent authorities for authoritative interpretations.

 

احصل على تحديثات أسبوعية

الموارد والأخبار

تعرف على كيفية معالجة حلولنا الرائدة في مجال أمن تكنولوجيا التشغيل (OT) للتحديات الأمنية الحيوية

قد تود أيضًا

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.