site-logo
site-logo
site-logo

Key requirements mandated by the CEA Cyber Security in Power Sector Regulations 2026

Key requirements mandated by the CEA Cyber Security in Power Sector Regulations 2026

Key requirements mandated by the CEA Cyber Security in Power Sector Regulations 2026

blog-details-image
author

Prayukth K V

Continuing our in-depth coverage of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, in today’s post we look at some of the key requirements mandated by this regulation.

The requirements below are summarised from the final CEA Cyber Security in Power Sector Regulations, 2026. Headings and explanatory text have been condensed for readability; readers should refer to the notified Regulations for the authoritative wording.

The final Regulations state:

General effective date: 1 April 2027

However, Regulations 5(9), 5(24), 5(33), 5(39), 6(2), and 6(7) will become effective on dates separately specified by CEA with prior Central Government approval.

Scope and extent of applicability:

(1) These Regulations shall apply to:


(a) all the entities which own, operate, or manage Operational Technology infrastructure associated with the interconnected power system and their Information Technology infrastructure that is physically or logically connected to such Operational Technology infrastructure, for their existing as well as upcoming infrastructure:

 Provided that in respect of generating companies, captive generating plants, and organisations having Energy Storage System, these regulations shall be applicable only where such entities have an installed capacity of 50 MW or more:

Provided further that the entities having an installed capacity of less than 50 MW are encouraged to implement the minimum baseline cyber security controls outlined in the “15 Elemental Cyber Defense Controls for Micro, Small and Medium Enterprises” issued by Indian Computer Emergency Response Team;

(b) power exchanges and over the counter platforms, except regulations 6, 11, and 12.
(2) The vendor shall comply with the regulations 11 and 12 of these regulations as applicable.

Specific areas and action items

CISO and Alternate CISO related requirements:

  • Senior-management-level regular employees

  • CISO reports to the head of the entity

  • Minimum 3-year CISO appointment

  • CISO role restricted to cybersecurity functions

  • CISO/Alternate CISO contact details available publicly

  • CISO must undergo at least 5 working days of cybersecurity training per financial year

  • CISO must be an Indian citizen and resident

  • Additional qualifications/experience are specified in Regulation 7.

Regulation 5(9) requires a dedicated ISD headed by the CISO and operating 24×7, with:

  • adequate staffing

  • valid domain-specific cybersecurity certification for ISD personnel

  • minimum 5 working days of power-sector cybersecurity training per financial year

  • minimum 3-year deployment period

However, this is one of the provisions whose commencement date will be separately notified.


Area

Action item

Awareness and sensitization

Conduct cyber security awareness program and cyber security exercises including mock-drills and tabletop exercises, at least once in every six months;

Data storage and residency

Ensure that sensitive information and sensitive data including such data and information hosted on cloud

as well as such historical data and information, is stored in an encrypted, secured, and protected environment

and resides within India only;

Vendor agreements

Include all cyber security requirements as well as applicable cyber security rules, regulations issued by the Central Government and Non - Disclosure Agreement in Service Level Agreement with the vendors, as specified under Cyber Security Policy,

Back-ups

Ensure online and offline backups of all critical systems in a separate, safe and secure environment as specified in cyber security policy;

Threat and risk audits

Facilitate a comprehensive cyber security audit encompassing all critical systems, as specified under regulation 13, at least once in every financial year but with a minimum and maximum gap of nine months and fifteen months, respectively, between two consecutive cyber security audits.

Ensure that the cyber security audit including vulnerability assessment and penetration testing is carried out prior to the commissioning of any new critical system including replacement of such system and manage

vulnerabilities and risks for critical system as per the mechanism defined in Cyber Security Policy. Three consecutive audits cannot be conducted by the same audit organisation/personnel.

Asset register

Maintain asset register-

(a) for all cyber assets along with the requisite details including ownership, hardware, firmware, software, and patch as per the procedure defined in Cyber Security Policy;

(b) recording the details of all critical systems along with the requisite details including its configuration, hardware, software, network architecture depicting data flows and communication

protocols used therein:

Provided that such register shall be reviewed and updated at least once in every financial year or upon commissioning of any new cyber asset or critical system including replacements thereof, whichever is earlier;

Cyber Risk Assessment and Mitigation Plan

Maintain Cyber Risk Assessment and Mitigation Plan for all assets detailed in cyber asset register, as per the procedure defined in Cyber Security Policy:

Provided that Cyber Risk Assessment and Mitigation Plan shall be updated at least once in every six months and reviewed at least once in every financial year and such Cyber Risk Assessment and Mitigation Plan shall be implemented to manage the vulnerabilities, threats and risks associated thereof;

Commissioning of new equipment

Furnish relevant information including system details and functionality, of all new critical systems commissioned including those replaced, as per asset register associated with critical systems to the Computer Security Incident Response Team - Power within thirty days of such commissioning or replacement;

CII identification

Provide the relevant information to National Critical Information Infrastructure Protection Centre for identification of Critical Information Infrastructure. Further, within sixty days of an asset being identified as a

Critical Information Infrastructure by National Critical Information Infrastructure Protection Centre, entity shall approach the Appropriate Government for notifying such asset as a Protected System;

CII accessibility from external networks

Ensure that Critical Information Infrastructure and Protected System are not discoverable on public platforms unless approved by the head or board of the entity, as applicable, on the basis of business requirements, criticality, and risk assessment of such system

FAT and Site Acceptance Test

Ensure that the procurement process mandates inclusion of Factory Acceptance Test and Site

Acceptance Test including testing of cyber security requirements

Vendor personnel training

Ensure that all personnel including personnel engaged by vendors in day-to-day operation and maintenance of all critical systems, have mandatorily undergone designated cyber security courses pertaining

to power sector;

Physical separation from networks connected with critical systems

Ensure that the systems, networks, and applications associated with physical security of critical systems are physically separated from the network of such critical systems:

Provided that in case of such physical separation is not feasible, with approval of head of the entity, subject systems, networks, and applications shall be logically separated from the networks of such critical systems;

Incident response and recovery

Maintain Incident Response and Recovery Plan, as specified in Cyber Security Policy, to recover from cyber incidents and resume normal operations at the earliest: Provided that such plan shall be reviewed and updated at least once in every six months

Monitoring

Have surveillance and continuous monitoring of Information Technology systems and Operational Technology systems, as applicable, for identification of threats as well as vulnerabilities and provide incident response and remediation support thereof

Logs of security devices

Ensure that logs of all security devices deployed at Electronic Security Perimeter are enabled to record exchange of data and information flowing through such devices;

Policy review

Ensure regular, at least once in every year, review and updating of rules and policies of perimeter security devices;

Procurement

Ensure that the Information Technology equipment and services are procured from trusted sources, in accordance with orders, directions or guidelines issued by the Central Government from time to time

Vulnerability and incident disclosure

Have structured vulnerability disclosure and management programs with vendors and Computer Security Incident Response Team. Maintain a register to record all cyber security incidents along with relevant details, as per the format prescribed by Computer Security Incident Response Team - Power

Additional requirements for OT operators

Physical isolation

Ensure physical isolation of Operational Technology system from internet as well as Information Technology system. Provided that in case such isolation from Information Technology system is not possible due to business requirements, such Information Technology and Operational Technology interconnection may be permitted, as per the procedure defined in Cyber Security Policy, with suitable hardened logical separation between Operational Technology system and Information Technology system, on the basis of risk assessment of such interconnection and approval of head or board of the entity, as applicable.

Provided further that such inter-connection is continuously monitored for detection of malicious activities and corrective measures thereof:

Provided also that such approval and logs associated with such inter-connection shall be retained for a period as specified in data retention policy;

Perimeter security

Ensure deployment of suitable perimeter level cyber security devices including firewall at point of interconnection of Operational Technology system with communication system of power system such that the deployed security system meets the requirements of, amongst other requirements, the detection and filtering of Operational Technology related protocols as well as traffic; content, user and application based filtering; deep packet inspection, intrusion detection; geo-fencing; user controlled updates; detection based on

signature and behavioural anomalies and filtering thereof:

Provided that the updates including signatures for devices forming part of such security system shall be carried out in offline mode, as specified in Cyber Security Policy;

Information exchange

Ensure that control and operation of power system elements and exchange of information thereof including real time data shall be over a dedicated communication channel isolated from the internet through perimeter level cyber security devices and shall be confined to national boundaries only:

Provided that for entities having business requirements or cross border power system elements, the exchange of information and real time data, as identified under Cyber Security Policy, may be permitted beyond the national boundaries only through dedicated separate communication system and unidirectional gateway, isolated from internet and along with cyber security devices, to transmit and receive subject to the condition that such information and data are monitored continuously to detect any anomaly or unauthorised

attempt:

Provided further that in case of exchange of real time information and data associated with end consumers, the same may be permitted through secured connection, isolated from public access, subject to the condition that exchange of sensitive information and data thereof over such connection shall be encrypted to ensure its confidentiality, integrity, and privacy;

Remote operation

Ensure that if remote operation is necessary for business requirements, the same shall be, within India, with the prior approval of head or board of the entity, as applicable, as per the procedure specified in the Cyber Security Policy

Compliance with orders

Ensure that all Operational Technology equipment, components, and parts thereof deployed for control and operation of power system shall comply with orders issued by the Central Government;

Segmentation

Ensure that the Operational Technology environment is segmented into different trust levels on the basis of criticality, security requirements, and risk assessment;

Communication security

Ensure that the communication system particularly channel, catering the Operational Technology data and information between the two entities is protected by owner of such system against cyber security threats.


Action items, deadlines and evidence required

Requirement Area

CEA Requirement

Frequency / Deadline

Practical Evidence

CISO Governance

CISO + Alternate CISO, reporting, tenure, qualifications

Ongoing

Appointment letter, JD, org chart

Cyber Asset Register

Maintain complete cyber asset/critical system register

Annual + on new asset

Asset register

Cyber Risk Assessment

Maintain CRAMP

Update ≥6 months

Risk register

Cybersecurity Audit

Comprehensive audit

Annual; 9–15 month interval

Audit report

New Critical Systems

Audit + VA/PT before commissioning

Before commissioning

VAPT/audit evidence

Incident Reporting

Report to CSIRT-Power + CERT-In

≤6 hours

Incident records

OT Isolation

Physical separation / approved hardened logical separation

Continuous

Architecture + approvals

OT Monitoring

Continuous IT/OT surveillance

Continuous

NDR/SIEM records

CII

Submit information to NCIIPC

As applicable

CII correspondence

ISO/Technical Certification

Certification covering critical systems

As separately notified

Certificate

This list only covers some of the key requirements. We will cover more requirements in subsequent posts.

You can book a free briefing session on this regulation conducted by a CEA expert here.

We have more downloadable resources on the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026.

The CEA Cyber Security in Power Sector Regulation 2026

CEA 2026 Compliance Checklist

CEA Cybersecurity Regulations 2026: What Indian Power Companies Need to Do


Regulatory note: This article is an explanatory summary of selected requirements from the notified Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026. It is not a substitute for the Gazette notification or applicable directions, policies and procedures issued by CEA, CSIRT-Power, CERT-In, NCIIPC or other competent authorities.

You can download the official notification from here.

احصل على تحديثات أسبوعية

الموارد والأخبار

تعرف على كيفية معالجة حلولنا الرائدة في مجال أمن تكنولوجيا التشغيل (OT) للتحديات الأمنية الحيوية

قد تود أيضًا

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.