Key Regulatory Facts at a Glance
Stay audit-ready with a clear view of critical dates, legal requirements, and reporting obligations under India's Cyber Security Regulations for Critical Information Infrastructure.
Why CEA 2026 Compliance Cannot Wait
The deadline is fixed. The exposure is regulatory, operational, and legal. The runway to close the gap is shorter than it looks.
The cost of non-compliance is real
Under Regulation 16, the Ministry of Power CISO can recommend proceedings and penalties directly against non-compliant utilities, not just flag the gap.
The operational reality
- Unmapped OT assets and undocumented IT/OT connections
- Shared CISO responsibilities across non-ring-fenced roles
- Legacy Windows XP/7 workstations with no patch path
- Vendor access without BOM disclosure or risk assessment
- Operational data hosted outside India
No grandfathering for legacy systems
- Older control systems are in scope from day one
- No exemption window for equipment nearing end-of-life
- Compensating controls must be documented, not assumed
Compliance is a strategic imperative
- Mandates compensating controls, not just intent
- Requires formal risk acceptance and phased remediation
- Must be backed by evidence, not a statement of policy
Who Must Comply?
The CEA 2026 Regulations apply to Responsible Entities that own, operate, or manage OT infrastructure tied to India's interconnected power system, and to the vendors who support them.
The 8 Critical Control Domains
Every power-sector CISO must address each domain with an operating model, a control design, and a defensible evidence trail. Explore the framework below.
Governance & CISO Ring-Fencing
Make accountability visible, dedicated, and durable.
- Appoint a dedicated CISO and Alternate CISO as regular senior employees
- CISO must be an Indian citizen/resident, hold an engineering degree, with 15+ years of power-sector or IT experience
- Minimum 3-year tenure, ring-fenced exclusively to cybersecurity
- Publish CISO contact details publicly and notify CSIRT-Power
Reference Framework compiled for Internal Briefing Use, Verify Against the Current CEA / CERT-In / CSIRT-Power Guidelines Before Filing Compliance Submissions.
End-to-End Industrial OT Cybersecurity.
Shieldworkz is an end-to-end industrial cybersecurity company specializing in Operational Technology security for critical infrastructure. We don't just advise we architect, implement, and validate.
OT Network Monitoring
Passive OT network threat monitoring integrated with 24x7 ISD.
OThello Assess
Audit-ready gap assessment report in under 24 hours — complete with evidence mapping and prioritized remediation roadmap.
OT Security Architecture
IT/OT segregation design, ESP firewall deployment, unidirectional gateway implementation.
CISO Governance Support
Policy drafting, CCMP development, CERT-In vetting coordination, Board resolution templates.
24×7 ISD Design
SOC architecture, staffing models, certification roadmaps, SIEM/OT monitoring deployment.
Incident Response
Respond to incidents of all types with accuracy while ensuring reporting obligations are met
Audit Preparation & Evidence
Pre-audit readiness reviews, evidence repository structuring, auditor liaison.
Legacy OT Remediation
Compensating control design, phased modernization, offline patching workflows.
Your 8-Month Countdown Starts Now
Here's your roadmap five phases from CISO appointment to full continuous compliance.
Immediate
0–30 Days- Formalize CISO & Alternate CISO appointments
- Publish CISO contact details and notify CSIRT-Power
- Initiate baseline Cyber Asset Register discovery
- Book your Shieldworkz CEA Preparedness Briefing
Foundation
31–90 Days- Draft Board-approved Cyber Security Policy (33 mandated elements)
- Develop CCMP and submit for CERT-In vetting
- Identify all IT/OT connections; isolate unauthorized links
- Submit CII identification to NCIIPC
Operationalization
3–6 Months- Establish or upgrade 24×7 ISD within India
- Issue vendor contract addendums for BOM and signed patches
- Deploy OT perimeter firewalls with DPI and offline update workflows
- Implement data residency controls for cloud and historical data
Audit Readiness
6–12 Months- Execute annual cybersecurity audit with CERT-In empanelled agency
- Remediate Critical/High findings within 1-month SLA
- Conduct Board-approved cyber crisis drills on non-repeating scenarios
- Submit Audit Closure Report within 6 months
Continuous Compliance
12–24 Months- Operationalize bi-annual risk assessments
- Enforce auditor rotation (2-year/3-year limits)
- Maintain First Schedule evidence repository
- Continuous improvement through threat intelligence integration







