
CEA Compliance Requirements for Power Utilities: What Changes


Team Shieldworkz
For years, cybersecurity in India's power sector ran on guidance. Good utilities followed it closely. Others treated it as a long-term aspiration. That era has ended. The Central Electricity Authority (CEA) has notified the Cyber Security in Power Sector Regulations, 2026, published in the Gazette of India on July 31, 2026, with mandatory provisions coming into force on April 1, 2027.
If you run a generating station, a transmission network, a distribution company, an energy storage project or a control centre, this is not a paperwork exercise. These regulations touch how you organize your security team, how you separate control systems from business networks, how fast you report an incident, who may connect to your plant and where your operational data lives.
This guide breaks down what is changing, why it matters operationally, and how to build a realistic plan in the months that remain. It is written for CISOs, OT security leaders, plant managers, engineers and compliance heads who need clarity rather than commentary.
Why OT Security Leaders Should Read This Now
The window between notification and enforcement is short when measured against how long real OT change takes. Network redesign, vendor contract updates and shift-level training do not happen in a quarter. Leaders who start early will treat compliance as a by-product of better security. Those who start late will treat it as an emergency.
Compliance becomes enforceable. The regulations convert voluntary guidance into a statutory obligation with audit consequences.
Visibility is now a legal prerequisite. Six-hour reporting is only possible if you can actually see what is happening inside plant networks.
Your vendors are part of your audit. Supplier practices, software transparency and patch support now sit inside your compliance boundary.
Governance moves to the top. Security leadership, a round-the-clock security function and board-level accountability are written into the framework.
What Has Changed: From Guidelines to Statutory Regulation
The CEA framed these regulations under the Electricity Act, 2003, with concurrence from the Ministry of Electronics and Information Technology. That legal footing matters. Earlier guidance encouraged good practice. These regulations define obligations, assign accountability and set expectations that auditors can test.

Figure 2: Notification, effective date and provisions awaiting separate implementation dates.
Who Is Covered
The regulations apply to entities that manage operational technology connected to the interconnected power system, along with the information technology systems linked to it. Generating companies, captive generating plants and energy storage systems are covered at 50 MW and above. Power exchanges and over-the-counter platforms are covered under specified provisions. Smaller entities are encouraged to adopt baseline controls even where the formal threshold does not reach them, which is wise, because attackers do not respect capacity thresholds.
Entity Type | Coverage | What It Means in Practice |
Generating companies and captive plants | Installations of 50 MW and above | Plant control systems, historians and engineering workstations come into scope |
Energy storage systems | Projects of 50 MW and above | Battery management and inverter controls need the same discipline as thermal assets |
Transmission and distribution entities | OT and linked IT systems tied to the interconnected system | Substation automation and control-centre networks require isolation and monitoring |
Power exchanges and trading platforms | Specified provisions | Data protection, reporting and governance obligations apply |
Smaller entities | Baseline controls encouraged | Early adopters reduce risk and prepare for wider expectations |
A Central Coordinating Body
The regulations establish the Computer Security Incident Response Team for the power sector, known as CSIRT-Power, as the nodal agency. Its remit includes incident analysis, alerts and advisories, assessments, audits, exercises, capacity building and supply chain security. For utilities, this means a single point to report to and learn from, and a single authority that will see patterns across the sector.
The Core Compliance Areas Explained
The regulations are broad, but they cluster around a handful of themes. The table below gives a quick view before we go deeper into each.
Compliance Area | What Is Expected | Operational Impact |
Security governance | Senior CISO and alternate CISO, minimum three-year tenure, round-the-clock Information Security Division, written policy and crisis plan | New roles, budgets and reporting lines |
Cyber asset management | Maintained register of all cyber assets | Full discovery of PLCs, RTUs, relays, servers and network devices |
Network separation | OT generally isolated from IT and the internet; perimeter security devices for OT networks | Segmentation redesign and remote access changes |
Incident reporting | Six hours to CSIRT-Power and CERT-In; 24 hours for sabotage involving critical systems | Live monitoring and rehearsed playbooks |
Audits and testing | Annual audit of critical systems, 9 to 15 months between audits, auditor rotation, pre-commissioning testing | Continuous evidence collection |
Vendors and supply chain | Software bill of materials, regular patches, trusted-source procurement | Contract and procurement changes |
Data protection | Critical operational data, backups and cloud hosting kept within India; secured data links | Architecture and hosting review |
People and training | Mandatory cyber security training; trained security staff | Role-based training programs |
1. Security Governance: A Named Owner With Real Authority
Each covered entity must appoint a senior, regular employee as Chief Information Security Officer for a minimum three-year tenure, backed by an alternate. A dedicated Information Security Division operating around the clock and located in India is also expected. The CEA will separately notify implementation dates for some of these provisions, so watch for those announcements.
The practical question is not who holds the title. It is whether that person can stop a risky change, secure budget for remediation and speak to the board in plain language. Utilities that place the CISO deep inside IT, with no line of sight to plant engineering, will struggle. Effective models create a joint working group where operations, engineering, IT and security share decisions.
2. Cyber Asset Management: You Cannot Protect What You Have Not Found
A maintained asset register sounds basic. In an operating plant it rarely is. Many utilities still depend on spreadsheets that were accurate during commissioning and drifted afterward. Serial links, forgotten engineering laptops, vendor-installed gateways and undocumented wireless access points are common finds during first-time discovery.
A compliant register goes beyond a device list. It records firmware versions, network locations, owners, criticality to power delivery and known vulnerabilities. Passive discovery methods, which listen to traffic instead of probing devices, are the safest way to build it in a live environment.
3. Risk Assessment and Vulnerability Remediation
Patching in a power plant is not the same as patching an office laptop. A relay or controller cannot simply be restarted during peak demand. The regulations expect structured risk assessment, which gives you room to justify decisions: patch now, apply a compensating control, or accept risk with documented approval.
Rank vulnerabilities by consequence to generation, transmission or distribution, not by score alone.
Link every deferred patch to a compensating control such as isolation, tighter access or enhanced monitoring.
Record the decision, the approver and the review date. Auditors look for the reasoning, not just the outcome.
4. OT and IT Separation: The Change Engineers Will Feel Most
The regulations state that OT systems must generally be physically isolated from IT systems and the internet. For many utilities, years of convenience-driven connectivity will need to be unwound: shared servers, direct vendor remote sessions, historian replication paths that cross into corporate networks, and mobile or cloud dashboards pulling live plant data.

Figure 3: A three-zone model with a monitored boundary between business systems and control systems.
Isolation does not mean you lose operational data. It means every path between zones is deliberate, narrow, monitored and documented. One-way data transfer and a controlled boundary zone let you move information out of plant networks without opening a door back in. Confirm the precise wording of each isolation clause with your legal and compliance team, then design to the strictest reasonable reading.
5. Monitoring and Incident Response

Figure 4: Reporting clocks that apply once an incident is detected.
Reporting to both CSIRT-Power and CERT-In within six hours is demanding. Think about what has to happen before you can file: someone must detect abnormal behavior, an analyst must decide whether it is a security event or a process fault, an engineer must confirm what is affected, and a senior owner must approve the report. Without prepared playbooks, that chain can consume the six hours before anyone starts writing.
Strong programs prepare three things in advance: a reporting template that captures the facts regulators will ask for, a decision tree that separates process faults from security events, and a contact roster that works at 2 a.m. They also run tabletop exercises with operations staff, because the best technical response fails if the control room hears about it late.
6. Access Management
Shared accounts on control stations, permanent vendor credentials and unmanaged remote access are among the most frequent findings in industrial environments. Expect auditors to ask who can reach what, from where and under which approval. The expected baseline includes individual named accounts, multi-factor authentication for critical systems, time-limited vendor access with session recording, and a defined process to remove access when a contractor leaves.
7. Vendors and Supply Chain
The regulations place real obligations on suppliers: a software bill of materials, regular security patch updates, and compliance with local data storage rules. Procurement of OT equipment must also come from trusted sources under government requirements. For utilities, this reshapes contracts, tender documents and maintenance agreements.
Add security clauses to every new purchase order and renewal: patch timelines, vulnerability disclosure, and breach notification duties.
Request a software bill of materials for control systems and keep it with the asset record.
Assess each vendor's remote support path and retire any that bypass your controlled boundary.
Define an exit process so access, credentials and data are removed when a contract ends.
8. Data Protection and Localization
Sensitive operational and historical grid data, including backups and information on cloud platforms, must be stored and protected within India. Real-time operational data must travel over dedicated, secure channels. Utilities with cloud-based analytics, remote monitoring contracts or foreign-hosted support tools should map where data flows today. Surprises tend to hide in monitoring subscriptions and equipment support portals.
9. Audits and Evidence
A comprehensive audit of critical systems is expected at least once each financial year, with intervals between nine and fifteen months. The same audit agency cannot work with you for more than two consecutive years, and new critical systems need testing before commissioning. Annual audits reward teams that collect evidence all year. They punish teams that rebuild it in the final month.
Real-World Lessons: Why These Requirements Exist
Every major requirement in the regulations traces back to an event somewhere in the world, including in India. The incidents below are widely documented, and each maps to a specific compliance expectation.
Incident | What Happened | Core Weakness | Related Requirement |
Ukraine, December 2015 | Attackers took control of operator workstations at three distribution companies and opened breakers, leaving roughly 225,000 customers without power for hours | Remote access and weak separation between networks | Network isolation, access management |
Ukraine, December 2016 | Specialized malware targeted a transmission substation near Kyiv and interrupted supply for about an hour | Attackers understood grid protocols | Monitoring, perimeter devices, response drills |
Ukraine, April 2022 | A further attempt on a power provider used purpose-built tools and was reported as disrupted before major outage | Defenders detected and contained in time | Incident reporting, prepared response |
Kudankulam, India, 2019 | The operator publicly acknowledged malware on an administrative network at a nuclear power plant, separate from control systems | Infection reached the business network | Isolation of OT from IT, reporting |
Mumbai grid disruption, 2020 | A major outage fed debate on possible cyber involvement; public conclusions varied between agencies | Limited forensic evidence available publicly | Logging, evidence retention, audit trails |
Two themes run through these cases. First, attackers repeatedly entered through business networks or remote access paths and then moved toward control systems. Separation, access control and monitoring address exactly this pattern. Second, the Mumbai episode showed that without strong logs and evidence, even officials struggle to say with confidence what happened. The new audit and reporting duties push utilities to keep that evidence.
The Ukrainian events also taught a more uncomfortable lesson. In 2015, operators watched their screens being controlled by someone else. The technical failure was serious, but the operational surprise was worse. Teams had never rehearsed responding to a hostile hand on the console. That is why exercises with operators belong in a compliance plan, not on a wish list.
Challenges Utilities Will Face
Understanding the rules is the easy part. Implementing them across real plants with decades of installed equipment is where programs slow down.
Challenge | Business Impact | Practical Response |
Legacy equipment with no security features | Cannot be patched or fitted with modern controls; replacement is slow and costly | Wrap with compensating controls: isolation, monitoring and strict access |
Remote and unmanned sites | Weak physical and network oversight; hard to inspect | Standardize secure remote connectivity and central logging |
Unclear ownership between IT and engineering | Gaps in accountability and delayed decisions | Joint governance forum with named owners per system |
Skills shortage in OT security | Slow remediation, over-reliance on outside help | Role-based training and a blended internal and external model |
Vendor dependence | Hard to enforce patch timelines or access limits | Revise contracts and centralize vendor access |
Evidence gathering at audit time | Last-minute effort, unclear proof, audit findings | Collect evidence continuously from day one |
Distributed energy and storage growth | More connected devices, more third-party platforms | Include them in the asset register and data-flow review |
The Hidden Risk: Treating Compliance as a Project
Organizations that approach regulation as a one-time project often finish with a thick binder and a fragile environment. A better view is that the regulations describe a security operating rhythm: discover, assess, protect, monitor, respond, prove, repeat. The binder should be a by-product of that rhythm.
Practical Recommendations: A 12-Month Readiness Roadmap
You do not need to fix everything at once. You need to fix the right things in the right order, without risking plant stability. The following approach has worked for industrial teams facing regulatory deadlines.
Phase | Timeline | Key Activities | Output |
Discover | Months 1 to 2 | Passive asset discovery, network mapping, data-flow review, gap assessment against each requirement | Asset register and gap report |
Prioritise | Months 3 to 4 | Risk ranking, segmentation design, vendor access review, budget approval | Funded remediation plan |
Remediate | Months 5 to 9 | Isolation and boundary build, access controls, monitoring and logging, playbook creation | Operating controls |
Prove | Months 10 to 12 | Internal audit dry run, incident tabletop with operators, evidence pack assembly | Audit-ready documentation |
Start With a Gap Assessment That Engineers Respect
Map each regulatory expectation to your current controls and mark the result as met, partly met or not met. Include plant engineers in the review. Their knowledge of how systems actually behave will keep your plan realistic and earn their support when changes affect operations.
Fix Boundaries Before Buying Tools
Many programs rush to buy monitoring platforms before settling network structure. A clean boundary makes monitoring simpler, cheaper and more accurate. Redesign first, then instrument.
Make Remote Access Boring
Funnel all vendor and employee remote access through one controlled gateway with multi-factor authentication, session recording and automatic expiry. When access is predictable, anomalies stand out.
Rehearse the Six Hours
Run a tabletop exercise built around a plausible scenario, such as ransomware on the corporate network that threatens to spread toward plant systems. Time every step from first alert to submitted report. The results will show where the real delays hide.
Build an Evidence Pack as You Go
• Approved policy, crisis plan and governance records
• Current asset register with change history
• Network diagrams showing zones and approved paths
• Risk assessments and documented patch decisions
• Access reviews, vendor access logs and exit records
• Training attendance and exercise reports
• Audit findings with closure proof
Common Mistakes to Avoid
• Treating the regulations as an IT initiative while plant teams hear about it late.
• Buying monitoring tools before the network is segmented.
• Running aggressive scanning in live control networks without engineering approval.
• Relying on vendor assurances without contract language or evidence.
• Waiting for every implementation date to be notified before starting the work.
• Preparing for the audit instead of preparing for the incident the audit is meant to prevent.
What Each Leader Should Prioritize
Compliance succeeds when every role understands its part. The table below translates the regulations into first priorities for the people who will carry them out.
Role | First Priority | Success Looks Like |
CISO | Define governance, reporting lines and a funded roadmap tied to each regulatory area | Board-approved plan with named owners and quarterly progress reviews |
Plant manager | Protect availability while agreeing outage windows for remediation work | Security changes scheduled alongside planned maintenance |
ICS engineer | Validate the asset register, review data flows and test changes safely | Accurate inventory and approved network paths |
SOC lead | Extend monitoring into plant networks and tune alerts for operational context | Alerts that separate security events from process faults quickly |
Compliance head | Map clauses to evidence and manage the audit calendar | Evidence collected continuously, not in the final month |
Procurement head | Embed security terms and trusted-source checks in every OT purchase | Contracts that enforce patching, transparency and access rules |
The Business Case: What Is at Stake
Regulatory compliance is the visible reason to act. The larger reason is the cost of failure in an electricity business. A disruption to generation or supply carries direct revenue loss, penalties under grid and licence conditions, equipment damage, safety exposure and long-term reputational harm. For distribution companies, public trust is also at stake, because customers feel every outage immediately.
Consider the pattern that has repeated across industries. A business network is compromised. Responders cannot quickly confirm whether control systems are affected. Operators, wanting to be safe, take parts of the plant offline manually. The attacker never reached the control layer, yet production still stopped for days because nobody could prove otherwise. Segmentation, asset visibility and monitoring directly reduce this kind of expensive uncertainty.
There is also a financing and partnership angle. Lenders, insurers, joint venture partners and large industrial customers increasingly ask how critical infrastructure operators manage cyber risk. A clear compliance position, backed by evidence, makes those conversations simpler.
Questions Boards and Executives Should Be Asking
• Do we have a complete and current register of every cyber asset in our plants and substations?
• Can we show, today, which networks connect to the internet and to our business systems?
• If an incident happened tonight, who would decide to report it, and how long would that take?
• Which vendors can reach our control systems, and when did we last review that access?
• Where is our operational data stored, including backups and support tools?
• When did we last rehearse a cyber incident with plant operators in the room?
If leadership cannot answer these questions with confidence, that is not a failure. It is a useful starting point, and a far better one than learning the answers during an audit or an incident.
How Shieldworkz Supports Organizations
Shieldworkz focuses on operational technology and industrial control environments, which means our work begins with how your plant runs, not with how an office network behaves. Our specialists combine engineering understanding with security practice so that protection does not come at the cost of availability.
• Asset visibility. Passive discovery and a complete, maintained cyber asset register across control centres, substations and generation sites.
• Compliance gap assessment. A structured assessment of your current controls against each regulatory expectation, with prioritized, practical findings.
• Segmentation and architecture. Design and support for OT and IT separation, controlled boundaries and secure remote access that respects operating realities.
• Monitoring and detection. Continuous visibility into industrial networks, with alerts that engineers and analysts can act on quickly.
• Incident readiness. Playbooks, reporting templates and tabletop exercises designed to meet the six-hour and 24-hour expectations.
• Vendor and supply chain risk. Contract guidance, risk assessments and access models that bring suppliers inside your security program.
• Audit preparation. Evidence organization, internal audit dry runs and remediation tracking that reduce audit-season pressure.
• Awareness and skills. Role-based training for control room operators, engineers, security staff and leadership.
We work alongside your teams, with respect for outage windows, safety rules and change control procedures.
Frequently Asked Questions
1.When do the CEA Cyber Security Regulations 2026 take effect?
The mandatory provisions come into force on April 1, 2027. The CEA will notify separate dates for certain provisions, including those on the Information Security Division, mandatory training, trusted-source procurement and perimeter devices for OT networks.
2.Do the regulations apply to renewable and storage projects?
Yes, where the entity meets the capacity threshold. Generating companies, captive plants and energy storage systems of 50 MW and above are covered, and smaller entities are encouraged to follow baseline controls.
3.How quickly must an incident be reported?
Cyber security incidents must generally be reported within six hours to CSIRT-Power and CERT-In. Cyber sabotage incidents involving critical systems must be reported within 24 hours.
4.Does OT isolation mean we cannot share any plant data with the business?
No. It means data movement must be controlled, minimal and monitored. Secure one-way transfer methods and a monitored boundary zone allow reporting and analytics without exposing control systems.
5.How often are audits required?
A comprehensive audit of critical systems is expected at least once each financial year, with nine to fifteen months between audits. The same audit agency cannot conduct more than two consecutive audits.
Conclusion
The CEA Cyber Security Regulations 2026 mark a turning point for India's electricity sector. They treat cyber security as part of reliable power delivery, which is exactly where it belongs. The shift from guidance to law raises expectations on governance, network separation, reporting speed, vendor accountability and evidence.
The utilities that benefit most will be those that act early and deliberately. Know your assets. Draw clean boundaries. Control who connects. Watch what happens inside your plants. Rehearse the six hours. Keep evidence as a habit. Do these things well and compliance follows, along with a more resilient grid.
April 2027 is closer than it looks when measured in outage windows and procurement cycles. The best time to begin was when the regulations were notified. The next best time is this quarter.
Book a Free Consultation with Our Experts
Not sure where your plants stand against the new regulations? Speak with Shieldworkz OT security specialists for a no-obligation conversation. We will listen to your environment, help you identify the highest-risk gaps and outline a practical path to readiness that protects plant operations.
احصل على تحديثات أسبوعية
الموارد والأخبار
تعرف على كيفية معالجة حلولنا الرائدة في مجال أمن تكنولوجيا التشغيل (OT) للتحديات الأمنية الحيوية
قد تود أيضًا

How AI Is Changing IEC 62443 Assessments

Team Shieldworkz

Deep investigative threat intelligence report: Alleged SafePay cyberattack on T-Systems

Team Shieldworkz

OT Media Scan Solution: What to Evaluate Before Securing Removable Media

Team Shieldworkz

G99 cybersecurity evidence pack for UK generators and BESS: What DNOs need to see in the PGMD

Team Shieldworkz

Inside the alleged onsemi Cyberattack: How Far Did Qilin Really Get?

Team Shieldworkz

Best IEC 62443 Risk Assessment Platform for Industrial OT Security

Team Shieldworkz

