site-logo
site-logo
site-logo

CEA Cybersecurity Regulations 2026: What Indian power companies need to do

CEA Cybersecurity Regulations 2026: What Indian power companies need to do

CEA Cybersecurity Regulations 2026: What Indian power companies need to do

blog-details-image
author

Team Shieldworkz

The Gazette of India published the statutory notification of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026. Issued under the authority of the Electricity Act, 2003, this mandatory regulatory framework establishes legally enforceable cybersecurity obligations across India’s generation, transmission, distribution, and grid dispatch infrastructure.

The regulation shifts the Indian power sector from ad-hoc advisory compliance to an enforceable, auditable, and operationally rigorous cybersecurity framework. Key imperatives include:

  • Mandatory 24x7 Information Security Divisions (ISD)

  • Strict IT/OT physical and logical isolation

  • Enforceable 6-hour incident reporting timelines

  • Comprehensive supply chain vendor accountability (including Bill of Materials)

  • Stringent data residency mandates (storing sensitive operational data strictly within India)

This article provides an authoritative analysis, operational translation, compliance checklist, evidence framework, and implementation roadmap designed specifically for power-sector CISOs, OT security leaders, plant heads, and executive leadership.

What the CEA Cybersecurity Regulations 2026 actually do

The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 establish mandatory baseline standards to ensure the safe and secure operation and maintenance of electrical plants and lines across the national grid.


Statutory Basis and Inter-Agency Roles

  • Regulatory Basis: Enacted by the Central Electricity Authority (CEA) in exercise of powers under Section 177(1) read with Section 73(c) of the Electricity Act, 2003 (36 of 2003), following statutory public consultation and concurrence from the Ministry of Electronics and Information Technology (MeitY).

  • Central Electricity Authority (CEA): The statutory authority promulgating the regulations and holding powers to issue sub-sectoral orders and relax provisions under specific hardship conditions (Regulation 17).

  • CISO Ministry of Power: Holds statutory oversight, including powers to call for audit reports, order independent third-party re-audits or compliance verifications at the entity’s cost, and recommend legal proceedings under Section 142 of the Electricity Act, 2003, or the IT Act, 2000 (Regulations 14, 15, 16).

  • CSIRT-Power (Computer Security Incident Response Team - Power): Established by the Ministry of Power as an extended arm of CERT-In. CSIRT-Power functions as the sector's central coordinating and nodal agency for reporting, incident response, threat analysis, advisories, supply chain security, CCMP advising, and establishing Central and Regional Cybersecurity Coordination Forums (Regulation 4).

  • Sub-Sectoral CSIRTs: Specialized bodies designated by the CEA to assist CSIRT-Power across Generation, Transmission, Distribution, and Grid Operations (Regulation 4(4)).

  • NCIIPC & CERT-In: Coordinated bodies for Critical Information Infrastructure (CII) identification (Section 70 of IT Act 2000), Protected System notifications, threat intelligence, and vetting of Cyber Crisis Management Plans (CCMPs) (Regulations 3(1)(k), 4(2), 5(11), 5(29)).

Materially significant regulatory paradigm shifts

  • Lawfully Binding Mandate: Replaces voluntary guidelines with enforceable legal obligations tied to regulatory penalties under Section 142 of the Electricity Act, 2003.

  • Explicit IT/OT Boundary Disambiguation: Delineates unique security requirements for IT and OT environments, enforcing physical/logical isolation and zero direct internet exposure for control networks.

  • Regulatory Accountability for Supply Chains: Imposes direct compliance duties on OEMs, System Integrators, and Cloud Providers, including mandatory Bill of Materials (BOM) disclosures and trusted-source procurement.

  • Data Sovereignty Mandate: Mandates that all sensitive operational data, cloud-hosted systems, and historical logs reside exclusively within the geographic boundaries of India.

Who is covered?

The applicability scope is detailed under Regulation 2:


Comprehensive applicability matrix

Entity Category

Specific Scope & Threshold Conditions

Applicable Regulations

Key Regulatory Directives

Thermal, Hydro, Nuclear Generation

Entities with total installed capacity

.

Regulations 1 through 17

Full compliance across plant DCS, SCADA, PLCs, and connected IT.

Renewable Energy Generation

Solar/Wind utility-scale plants with aggregate capacity

.

Regulations 1 through 17

Secure PPC, SCADA, inverter communication, and telemetry to SLDC.

Energy Storage Systems (ESS)

Standalone or hybrid ESS facilities with capacity

.

Regulations 1 through 17

BMS/BESS controller isolation, cyber asset registration, physical security.

Captive Generating Plants

Industrial captive power plants with installed capacity

.

Regulations 1 through 17

Complete isolation of plant OT from industrial process IT and external networks.

Small Power Generators / Captive

Plants with total installed capacity

.

Exempt from statutory mandate

Encouraged to adopt CERT-In "15 Elemental Cyber Defense Controls for MSMEs".

Transmission Licensees

Inter-State (ISTS) and Intra-State (InSTS) transmission licensees.

Regulations 1 through 17

Substation Automation Systems (SAS), protection relays, SAS-to-SLDC gateways.

Distribution Licensees (Discoms)

All public and private electricity distribution utilities (no capacity floor).

Regulations 1 through 17

SCADA/DMS, GIS, AMI/Smart Metering head-end systems, sub-station automation.

Grid Load Despatch Centres

National (NLDC), Regional (RLDCs), and State Load Despatch Centres (SLDCs).

Regulations 1 through 17

EMS/SCADA isolation, CISO appointment reporting to parent head (Reg 5(4)).

Power Exchanges & OTC Platforms

Approved electricity trading exchanges and OTC contract platforms.

Regs 1–5, 7–10, 13–17 (Exempt from Reg 6, 11, 12)

Trading system IT security, 24x7 ISD, CISO ring-fencing, public app audits.

Vendors, OEMs & Integrators

OEMs, System Integrators, contractors, and Cloud Service Providers.

Regulation 11 (Direct) & Reg 5(20)

Provision of BOM, digitally signed patches, EOL disclosures, SLAs, NDAs.

Distributed Generation / Prosumers

Distributed Generation Resources (DGR

, rooftop solar, ESS).

Regulation 12 (Vendor Obligation)

Vendors must ensure encryption, local data residency, and mutual authentication.

When Does Compliance Begin?

The notification sets specific timelines regarding publication versus legal enforceability:


 

Crucial Distinction: The notification date (31 July 2026) is the official publication date. The enforcement date is 1 April 2027. Power companies must utilize the intervening window to achieve audit readiness.

What has changed for Indian power companies?

The regulation establishes explicit requirements that alter standard operating procedures across governance, IT, OT, and supply-chain operations.

Shift in Operational Requirements

Requirement Area

Prior Operating Standard (Pre-2026)

Mandatory Requirement Under CEA Regulations 2026

Impact Level

CISO Governance

CISO often held dual responsibilities (e.g., CIO/IT Head) with variable terms.

Dedicated CISO ring-fenced exclusively to cybersecurity for a minimum 3-year term, reporting directly to Head of Entity.

High

Security Operations

IT SOC operating on 8x5 or outsourced basis; limited or no OT coverage.

Dedicated 24x7 Information Security Division (ISD) within India with certified staff (Reg 5(9)).

Critical

IT/OT Architecture

Dual-homed workstations or routed firewalls connecting IT and OT networks.

Strict physical isolation of OT from Internet and IT networks. Logical connections require explicit Board approval and unidirectional gateways.

Critical

Remote Access & Ops

Broad VPN access granted to OEM vendors for routine support.

Allowed only for emergencies/troubleshooting. OT Remote Operation requires prior Board approval and dedicated non-Internet channels within India.

Critical

Data Residency

Operational logs, cloud applications, or telemetry stored on international cloud servers.

Sensitive data, cloud data, historical records, and backups must reside strictly within India in encrypted form.

High

Time Synchronisation

Systems synced to public NTP servers or non-validated internal clocks.

Clocks synchronized to a vetted reference time source (terrestrial or India-specific satellite, e.g., NavIC/IRNSS) independent of the Internet for OT.

Medium

Supply Chain & BOM

Procurement based on commercial specs; limited visibility into software components.

Mandatory Bill of Materials (BOM), mandatory FAT/SAT cybersecurity testing, and Trusted Source procurement.

High

Incident Reporting

Reporting within 24–48 hours or handled internally without mandatory escalation.

Mandatory initial incident reporting within 6 hours to CSIRT-Power and CERT-In. Cyber sabotage reported within 24 hours.

Critical

 

Major compliance obligations

Cyber Security Policy and CCMP

Entities must maintain a Board-approved Cyber Security Policy aligned with their Business Continuity Plan (BCP), reviewed annually (Regulation 5(10), 8). Entities must also establish a Cyber Crisis Management Plan (CCMP) vetted by CERT-In and approved annually by the Board (Regulation 5(11)).

Asset Management and Cyber Asset Register

Entities must maintain a Cyber Asset Register covering all hardware, software, firmware, patch versions, ownership, configurations, data flows, and network architecture (Regulation 5(25)). The register must be updated annually or upon any new commissioning/replacement.


 Cyber Risk Assessment and Vulnerability Management

Risk assessments must be updated every 6 months and formally reviewed annually (Regulation 5(26)). Pre-commissioning cybersecurity audits, including Vulnerability Assessment and Penetration Testing (VAPT), are mandatory for all new or replaced critical systems (Regulation 5(2    7)).

OT/ICS Implications

The regulation establishes specific requirements for real-world Industrial Control Systems (ICS), SCADA, DCS, PLCs, RTUs, IEDs, and Substation Automation Systems (SAS).


 

  

Control Implementations for OT Assets

  • DCS / SCADA / EMS / DMS: Main and backup control centers must maintain complete physical or logical isolation from IT networks (Regulation 6(1)). Data transfer to IT must utilize unidirectional gateways (data diodes) or dedicated separate communication channels (Regulation 8(28)).

  • PLCs, RTUs, and IEDs: Controllers must reside within defined Electronic Security Perimeters (ESP) (Regulation 3(1)(v), 5(13)). Direct exposure to routed external networks or maintenance modems is strictly prohibited.

  • Engineering Workstations & Laptops: Transient cyber assets used for programming and calibration must be inventoried, vulnerability-scanned, hardened, and restricted from concurrent Internet exposure.

  • OT Patching: Software/firmware updates for OT assets must be digitally signed by the OEM, validated in a simulated/test environment, and applied via offline modes (Regulation 6(2), 8(25)).

IT/OT Segregation & Network Security

Regulation 6(1) mandates the physical isolation of OT systems from the Internet and IT networks.

Interconnection Compliance Pipeline

If business operations require an IT/OT interconnection:

  1. Risk Assessment: Conduct a formal risk assessment detailing threat vectors introduced by the interconnection (Regulation 6(1)).

  2. Approval: Obtain explicit prior approval from the Head of the Entity or the Board of Directors (Regulation 6(1)).

  3. Architecture: Implement hardened logical separation (e.g., dual firewalls, demilitarized zones, unidirectional gateways) (Regulations 6(1), 8(28)).

  4. OT Firewalls: Deploy OT-aware firewalls capable of Deep Packet Inspection (DPI) for industrial protocols (e.g., IEC 60870-5-104, IEC 61850, DNP3, Modbus) (Regulation 6(2)).

  5. Offline Updates: Firewall signatures and security updates must be applied offline to avoid persistent cloud update connections into the OT environment (Regulation 6(2)).

  6. Logging & Audit: Maintain all interconnection logs and approval documentation for audit inspection (Regulations 6(1), 8(33)).

CISO & Governance Requirements

Mandatory Qualifications & Governance Rules (Regulation 5 & 7)

 

 

  • SLDC Oversight Provision: If an entity such as a State Load Despatch Centre (SLDC) operates as part of a parent or holding company, a dedicated CISO must be appointed specifically for that entity, reporting directly to the Head of the parent/holding company (Regulation 5(4)).

Asset Visibility and Critical-System Identification

Regulation 5(16) and 8(5) mandate a structured process for identifying and classifying systems into Critical Systems and Non-Critical Systems:

  1. Impact Analysis: Systems whose unavailability or degradation would adversely affect power business operations or grid reliability are designated as Critical Systems (Regulation 3(1)(h),(i),(j)).

  2. Critical Information Infrastructure (CII): Critical systems identified as CII under Section 70 of the IT Act, 2000, must be submitted to NCIIPC (Regulation 5(29)).

  3. Protected System Notification: Within 60 days of NCIIPC identifying an asset as CII, the entity must approach the Appropriate Government to officially notify the asset as a Protected System (Regulation 5(29)).

  4. Public Search Exclusion: CII and Protected Systems must not be discoverable on public platforms or search engines unless specifically authorized by the Board based on operational necessity and risk assessment (Regulation 5(30)).

Monitoring, Detection & Incident Response

Mandatory 24x7 Information Security Division (ISD)

Regulation 5(9) requires every covered entity to establish an in-house, 24x7 Information Security Division located within India. Staff must hold domain-specific cybersecurity certifications and undergo at least 5 man-days of specialized power-sector training annually, with a minimum deployment tenure of 3 years.

Mandatory Incident Reporting Timelines (Regulation 7(3)(a))

 

 

  Post-Incident Follow-Up:

    * Root Cause Analysis (RCA) and Action Taken Report (ATR) shared with

      CSIRT-Power and CERT-In (Reg 7(3)(g)).

    * Incident logs retained for 180 days prior and 180 days post-incident

      (Minimum total retention: 365 days) (Reg 8(33)).

Vendor & Supply-Chain Security

Regulations 5(20), 11, and 12 impose mandatory obligations on third-party suppliers, OEMs, EPC contractors, and service providers.

Vendor Compliance Checklist

Statutory Requirement

Legal Ref.

Operational Obligation

Bill of Materials (BOM)

Reg 11(5)

Vendors must supply a structured inventory of all software libraries, components, modules, and firmware.

Digitally Signed Patches

Reg 11(2)

Vendors must provide digitally signed or validated security updates throughout the contract term or asset useful life.

Recovery Plans

Reg 11(1)

Vendors must deliver documented and tested restoration procedures for all supplied systems.

End-of-Life Disclosures

Reg 11(4)

Vendors must formally notify entities of End-of-Life (EOL) or End-of-Support (EOS) dates for hardware/software.

System Hardening

Reg 11(6)

Hardware and software must be delivered pre-hardened with unnecessary ports, services, and default accounts disabled.

Personnel Vetting

Reg 5(20)

Vendor staff accessing critical systems must undergo formal personnel risk assessments and background checks.

Prosumer / DGR Security

Reg 12

Inverter and monitoring vendors for rooftop solar/ESS must enforce encryption, mutual authentication, and domestic data hosting.

 

Legacy and obsolete OT

Operating unsupported legacy assets (e.g., Windows XP/7 engineering workstations, legacy RTUs, unpatchable PLCs) presents significant compliance challenges.

Regulatory approach to obsolete assets (Regulation 3(1)(z), 8(22))

An Obsolete Asset is defined as an asset declared end-of-life by its OEM, lacking official support, and posing potential operational or security risks.


 

Audit, certification and evidence

Mandatory Audit Cycle (Regulation 5(22), 13, 14)

  • Frequency: Comprehensive cybersecurity audits covering all Critical Systems must be conducted once per financial year.

  • Audit Interval: The gap between consecutive annual audits must be at least 9 months and no more than 15 months.

  • Auditor Rotation:

    • Cyber Security Audits: No agency or individual auditor may conduct more than 2 consecutive annual audits for the same entity (Regulation 5(22)).

    • ISO/IEC 27001 / Technical Certification: No agency may conduct more than 3 consecutive certification audits (Regulation 5(24)).

  • Remediation Timelines:

    • Critical & High Risk Findings: Must be fully remediated within 1 month of report submission (with compensating controls implemented immediately) (Regulation 13(3)).

    • Medium & Low Risk Findings: Must be remediated within 3 months (Regulation 13(3)).

    • Closure Report: The CISO must ensure the final Audit Closure Report is submitted within 6 months of audit initiation (Regulation 14(1)).

CEA 2026 Compliance Checklist

This master operational checklist allows security teams to track compliance across all mandatory regulatory requirements.

#

Domain

Requirement

Regulatory Ref.

Operational Action Required

Primary Evidence Expected

Owner

Priority

1

Governance

Senior Management CISO

Reg 5(1),(5),(6)

Appoint regular senior employee as CISO for min 3-year term exclusively for cybersecurity.

Board Resolution, Appointment Letter, CISO Profile

MD / CEO

P1

2

Governance

Alternate CISO

Reg 5(1),(2)

Formally designate Alternate CISO to prevent concurrent vacancies.

Office Order, Designation Records

Board

P1

3

Governance

CISO Qualifications

Reg 7(1)

Verify Indian citizenship/residency, engineering degree, and 15+ years experience.

Degree copies, Passport/Aadhaar proof, CV

HR Head

P1

4

Governance

CISO Contact Publication

Reg 5(7)

Publish CISO/Alt-CISO contact details publicly and notify CSIRT-Power.

Public Website link, CSIRT-Power Email Copy

CISO

P2

5

Governance

Cyber Security Policy

Reg 5(10), 8

Draft BCP-aligned policy; obtain annual Board approval.

Approved Policy document, Board Minutes

CISO

P1

6

Governance

Cyber Crisis Mgmt Plan

Reg 5(11), 9

Draft CCMP; obtain CERT-In vetting and annual Board approval.

CERT-In Vetting Letter, Board Approval

CISO

P1

7

Operations

24x7 Security Division

Reg 5(9)

Establish round-the-clock ISD in India with certified personnel.

Shift Roster, Staff Certificates, SOC Architecture

CISO

P1

8

Asset Mgmt

Cyber Asset Register

Reg 5(25), 8(4)

Maintain complete asset register (hardware, OS, firmware, patch, location).

Asset Register (Excel/Database), Audit Logs

IT/OT Lead

P1

9

Asset Mgmt

Critical System List

Reg 5(16), 8(5)

Define criteria and register all Critical IT/OT Systems.

Critical System Register, BCP Impact Analysis

CISO

P1

10

Asset Mgmt

CII & Protected System

Reg 5(29)

Submit CII details to NCIIPC; approach Govt within 60 days for Protected System notification.

NCIIPC Filing Records, Govt Notification

CISO

P1

11

Network

IT/OT Isolation

Reg 6(1)

Enforce physical isolation of OT from Internet/IT; execute Board approvals for logical links.

Architecture Diagram, Firewall Rules, Board Approval

OT Head

P1

12

Network

OT Perimeter Firewalls

Reg 6(2)

Deploy OT firewalls at grid boundaries; apply signature updates offline.

Firewall Config, DPI Logs, Maintenance Logs

OT Lead

P1

13

Network

Dedicated OT Comms

Reg 6(3)

Confine power control and real-time data flow to dedicated channels within India.

Network Routing Diagrams, Telecom Agreements

Telecom Lead

P1

14

Network

Time Synchronisation

Reg 5(32), 8(27)

Sync IT/OT clocks to independent reference source (terrestrial/Indian satellite).

NTP Config, Clock Sync Logs, Risk Assessment

IT/OT Lead

P2

15

Operations

Remote Access Controls

Reg 5(17), 8(15)

Restrict remote access to emergencies; enforce MFA, geo-fencing, CISO approval, and logging.

Remote Access Approval Forms, MFA Logs, VPN Audit

CISO

P1

16

Operations

OT Remote Operation

Reg 6(4), 8(16)

Obtain Board approval for OT remote operation; route via non-Internet domestic channels.

Board Approval, Dedicated Circuit Contracts

Plant Head

P1

17

Operations

24x7 OT Surveillance

Reg 5(36)

Implement continuous monitoring and threat detection across IT/OT environments.

SIEM/NTA Sensor Deployment Logs, Alerts

CISO

P1

18

Operations

6-Hour Incident Reporting

Reg 7(3)(a)

Mandate incident notification to CSIRT-Power and CERT-In within 6 hours.

Incident Register, Incident Reporting SOP

CISO

P1

19

Data Protection

Domestic Data Residency

Reg 5(19)

Store all sensitive/cloud/historical data in encrypted form strictly within India.

Cloud SLA, Data Hosting Architecture, Storage Config

CIO/CISO

P1

20

Supply Chain

Vendor SLA & NDA

Reg 5(20)

Include cybersecurity rules, NDAs, and breach liability clauses in all vendor SLAs.

Executed Vendor Contracts, Signed NDAs

Legal/Proc

P2

21

Supply Chain

Bill of Materials (BOM)

Reg 11(5)

Mandate sub-component software BOM disclosures from hardware/software OEMs.

OEM BOM Submissions, Asset Files

Procurement

P2

22

Supply Chain

FAT/SAT Cyber Testing

Reg 5(31)

Integrate mandatory cybersecurity validation testing into FAT and SAT protocols.

FAT/SAT Test Sign-off Sheets, Test Reports

Project Lead

P2

23

Audit

Annual Cyber Audit

Reg 5(22), 13

Execute annual cybersecurity audit; observe 9–15 month gap and auditor rotation limits.

Audit Reports, Engagement Contracts

CISO

P1

24

Audit

VAPT for New Systems

Reg 5(27)

Perform pre-commissioning VAPT for all new or replaced critical systems.

Pre-commissioning VAPT Reports, Remediation Sign-off

CISO

P1

25

Audit

Annual Self-Audit

Reg 15

Conduct annual FY self-audit; remediate non-compliances prior to next cycle.

Self-Audit Assessment Sheet, Board Report

CISO

P2

Evidence-Readiness Checklist

To satisfy statutory inspections and external compliance audits by the Ministry of Power CISO, entities must maintain a structured repository containing the following documents:

Mandatory evidence map

[ GOVERNANCE & POLICY ]

  * Approved Cyber Security Policy & Board Resolution (Reg 5(10))

  * Vetted Cyber Crisis Management Plan (CCMP) & CERT-In Letter (Reg 5(11))

  * Data Retention Policy & Backup Policy Documents (Reg 8(18),(33))

  * First Schedule Document Archive (Reg 7(3)(i))

 

[ PERSONNEL & APPOINTMENTS ]

  * CISO & Alternate CISO Formal Designation Orders (Reg 5(1))

  * CISO Qualification, Residency, & Citizenship Records (Reg 7(1))

  * Annual Training Records (Min 5 man-days/year for CISO & ISD staff) (Reg 5(8),(9))

 

[ ARCHITECTURE & ASSETS ]

  * Cyber Asset Register & Critical Systems Register (Reg 5(25))

  * Approved Network Architecture Diagrams depicting IT/OT Boundaries (Reg 5(25))

  * Board Approvals for IT/OT Logical Connections & Remote Operations (Reg 6(1),(4))

  * NCIIPC CII Submissions & Govt Protected System Notifications (Reg 5(29))

 

[ OPERATIONAL LOGS & AUDITS ]

  * Annual Cyber Security Audit Reports & Closure Reports (Last 3 years) (Reg 8(33))

  * ISO/IEC 27001 / Technical Criteria Certificates (Last 4 years) (Reg 8(33))

  * Pre-commissioning VAPT Reports for New Critical Assets (Reg 5(27))

  * System Logs & Incident Logs (180 days routine; 365 days post-incident) (Reg 8(33))

  * FAT / SAT Cybersecurity Verification Sign-off Sheets (Full Asset Lifetime) (Reg 8(33))

 

Implementation Roadmap


  

Detailed Milestone Tasks

Immediate 0–30 Day Actions

  1. Formalize CISO & Alternate CISO Appointments: Verify qualifications (15+ years experience, engineering degree, Indian citizenship/residency) and issue formal designation orders ring-fencing the role exclusively to cybersecurity (Regulations 5(1), 5(6), 7(1)).

  2. Publish CISO Contact Details: Post CISO/Alt-CISO contact information on the public website and submit details to CSIRT-Power (Regulation 5(7)).

  3. Establish Baseline Cyber Asset Register: Initiate asset discovery across plant IT and OT environments to create an initial inventory of connected devices (Regulation 5(25)).

31–90 Day Plan

  1. Policy & CCMP Alignment: Review and align the Cyber Security Policy and CCMP with CERT-In and CSIRT-Power guidelines; submit for Board approval (Regulations 5(10), 5(11), 8, 9).

  2. IT/OT Boundary Review: Identify all direct connections between corporate IT and plant OT; isolate unauthorized connections or draft formal risk assessment justifications for Board approval (Regulation 6(1)).

  3. NCIIPC Notification: Compile critical asset lists and submit CII identification documentation to NCIIPC (Regulation 5(29)).

3–6 Month Plan

  1. Operationalize 24x7 ISD: Establish or upgrade the round-the-clock Information Security Division within India, ensuring certified staffing and training rosters (Regulation 5(9)).

  2. Vendor Addendums & BOM Enforcement: Issue formal contract addendums to key OEMs and vendors requiring compliance with Regulation 11 (BOM, digitally signed patches, recovery plans).

  3. Logging & ESP Hardening: Enable logging on all Electronic Security Perimeter firewalls and configure log ingestion into a central SIEM platform (Regulations 5(13), 5(37)).

6–12 Month Plan

  1. Bi-Annual Cyber Exercises: Conduct structured mock drills and tabletop crisis simulations (Regulation 5(18), 10(2)).

  2. Annual Cybersecurity Audit: Engage a CERT-In empanelled auditing agency to execute a comprehensive annual cybersecurity audit across all Critical Systems (Regulation 5(22), 13).

  3. Time Synchronisation Deployment: Deploy independent terrestrial or Indian satellite-based (NavIC) reference time clocks for OT environments (Regulation 5(32), 8(27)).

Pre-1 April 2027 Readiness Plan

  1. Audit Remediation & Closure: Complete remediation of all identified audit findings and submit the Audit Closure Report (Regulation 13(3), 14(1)).

  2. Formal Self-Audit: Execute an annual self-audit under Regulation 15 and present compliance findings to the Board.

  3. Final Evidence Repository Verification: Verify that all First Schedule documents, logs, and evidence files are archived and accessible for potential Ministry of Power inspection.

12–24 Month Compliance Roadmap


 

Framework Mapping Note: While power companies can leverage established global cybersecurity frameworks (e.g., IEC 62443 for ISA/OT security, ISO/IEC 27001 for ISMS, NIST SP 800-82, and MITRE ATT&CK for ICS) to structure technical controls, compliance verification is strictly determined by the provisions of the CEA 2026 Regulations.

CEA Cybersecurity Maturity Model

Entities can evaluate their compliance posture against this 5-level maturity framework:

CEA compliance spectrum

LEVEL 1: REACTIVE     -> Informal security; unmapped OT assets; shared IT/OT links.

  LEVEL 2: COMPLIANT    -> Baseline CEA compliance; CISO appointed; 6-hr reporting.

  LEVEL 3: MANAGED      -> Operational 24x7 ISD; physical IT/OT separation; SIEM logs.

  LEVEL 4: RESILIENT    -> OT DPI threat detection; BOM tracked; automated drills.

  LEVEL 5: ADVANCED     -> Real-time threat intelligence; zero-trust OT access.

Maturity Profile Breakdown

Dimension

Level 1: Reactive

Level 2: Basic Compliance

Level 3: Managed

Level 4: Resilient

Level 5: Advanced Cyber Resilience

Governance

Dual-hatted CISO; policy unapproved or outdated.

Dedicated CISO appointed; Board approves policy & CCMP annually.

CISO ring-fenced; 3-year term enforced; regular Board reporting.

CISO-led ISD; proactive risk mitigation across all business units.

Fully integrated cybersecurity governance embedded in capital procurement.

Asset Visibility

Partial manual spreadsheet of IT assets only.

Cyber Asset Register maintained; Critical Systems identified.

Register automatically updated on commissioning; BOM collected.

Comprehensive asset visibility including nested sub-components and firmware.

Automated real-time asset discovery and vulnerability correlation.

IT/OT Architecture

Dual-homed systems; unmonitored IT/OT links.

IT/OT logical separation implemented with Board approval.

Strict physical OT isolation; unidirectional gateways deployed.

ESP firewalls with OT DPI protocol filtering deployed at all trust boundaries.

Zero-trust OT segmentation with continuous micro-segmentation checks.

Monitoring & Response

Ad-hoc log collection; incident response reactive.

6-hour incident reporting process defined; SOC monitoring IT.

24x7 domestic ISD operational; SIEM collecting ESP firewall logs.

Passive OT network threat monitoring integrated with 24x7 ISD.

Automated incident containment with real-time CSIRT-Power threat sharing.

Audit & Assurance

Audits conducted irregularly without rotation.

Annual cybersecurity audit executed; gap between 9–15 months.

Audit findings remediated within 1-month / 3-month SLAs.

Auditor rotation strictly enforced (2-yr / 3-yr limits).

Continuous automated compliance verification and audit evidence synthesis.

Top 25 Actions for Power CISOs


Questions every Power CISO should ask

To evaluate operational readiness, CISOs should present these 20 practical questions to their engineering, IT, OT, and leadership teams:

  1. Asset Visibility: Can we generate a complete Cyber Asset Register showing hardware, OS, firmware version, and active patch level for every controller across our facilities?

  2. IT/OT Separation: Are any PLCs, RTUs, DCS controllers, or engineering workstations directly reachable from the corporate IT network or the Internet?

  3. Board-Approved Connections: Do we maintain formal Board approval resolutions and documented risk assessments for every logical connection between IT and OT?

  4. Remote Access Auditing: Can we produce MFA authentication logs, CISO approvals, and session recordings for every remote access session established into our OT network over the past 12 months?

  5. OT Remote Operations: Are any power generation or grid switching operations conducted remotely over public internet channels?

  6. Incident Escalation Speed: Does our SOC workflow guarantee that an OT incident will be escalated and formally reported to CSIRT-Power and CERT-In within 6 hours of discovery?

  7. Cloud Data Residency: Are any operational telemetry logs, SCADA historian backups, or sensitive enterprise data hosted on cloud infrastructure located outside India?

  8. Substation Time Sync: How are protection relays and SAS gateways synchronized, and can our time source operate independently if Internet connection is lost?

  9. Supply Chain BOM: Do our current procurement contracts require OEMs to provide a granular software Bill of Materials (BOM) for new digital control systems?

  10. Pre-Commissioning VAPT: Is pre-commissioning VAPT mandatory in our project sign-off workflow before taking new substations or generation units online?

  11. Auditor Rotation Tracking: Have we utilized the same cybersecurity auditing firm or individual auditor for more than two consecutive annual audits?

  12. Audit SLA Enforcement: Are our technical teams capable of remediating Critical and High-risk audit findings within 30 days of report receipt?

  13. Vetted CCMP: Has our Cyber Crisis Management Plan been formally reviewed and vetted by CERT-In within the past 12 months?

  14. 24x7 Domestic ISD: Is our 24x7 Information Security Division physically located within India, and do all staff members meet the mandatory 5 man-day power cybersecurity training rule?

  15. Legacy Asset Phase-Out: Do we maintain a documented phase-out plan and active compensating controls for unsupported legacy operating systems and end-of-life controllers?

  16. Public Discoverability: Are any of our Protected Systems, SCADA web portals, or internal control interfaces indexed or discoverable on public platforms?

  17. Vendor Personnel Risk: Do we execute formal personnel risk assessments and require signed undertakings before allowing third-party vendor engineers physical or cyber access to critical systems?

  18. Offline Patch Validation: Are software updates and security patches for our OT environments tested in a simulated environment and applied strictly offline?

  19. Backup Restoration Testing: Have we physically tested the restoration of critical OT systems from offline backups within the past 12 months to verify recovery time objectives?

  20. First Schedule Compliance: Do we maintain an archive containing all 12 mandatory document types specified in the First Schedule of the CEA 2026 regulations?

The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 establish mandatory cybersecurity standards for India's power grid. By replacing voluntary recommendations with statutory obligations, the regulation establishes legal accountability for grid security.

Compliance requires addressing key operational imperatives:

  • Disconnecting OT networks from public networks and securing necessary IT connections

  • Establishing 24x7 security monitoring located domestically

  • Formalizing vendor supply chain disclosures and BOM tracking

  • Enforcing strict 6-hour incident escalation workflows

  • Maintaining complete, auditable evidence repositories

Power-sector organizations must utilize the transition window leading up to 1 April 2027 to conduct gap analyses, execute technical remediation, and align their operations with these statutory requirements.

Book a free briefing on compliance with the new CEA cybersecurity guidelines here.

Download a comprehensive checklist for CEA compliance here.

احصل على تحديثات أسبوعية

الموارد والأخبار

تعرف على كيفية معالجة حلولنا الرائدة في مجال أمن تكنولوجيا التشغيل (OT) للتحديات الأمنية الحيوية

قد تود أيضًا

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.