


Team Shieldworkz
PART I — EXECUTIVE OVERVIEW
What the regulations are
The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 were notified in the Gazette of India on 31 July 2026. Issued under Section 177 of the Electricity Act, 2003 with the concurrence of the Ministry of Electronics and Information Technology (MeitY), these regulations transform India's power-sector cybersecurity framework from the previous advisory/voluntary guidelines (2021) into a binding, statutory compliance mandate with defined evidence obligations and audit trails.
Timelines and effective dates
Notification Date: 31 July 2026
General Commencement / Enforcement Date: 1 April 2027 (providing entities an 8-month implementation window).
Deferred Sub-Regulations: Six specific provisions—Regulations 5(9) (24x7 Information Security Division), 5(24) (Mandatory ISO/IEC 27001 Certification), 5(33) (Mandatory Cyber Security Training), 5(39) (Trusted-Source Procurement for IT), 6(2) (OT Perimeter Hardware Security), and 6(7) (Trusted-Source Procurement for OT)—are deferred and will come into force on separate dates to be notified by the Authority.
Why they matter to India's power sector
As the power sector becomes increasingly digitized and interconnected (via Smart Grids, SCADA, EMS, DMS, and IoT-based substations), the threat vector to critical energy infrastructure expands exponentially. The 2026 Regulations establish a mandatory baseline for cyber resilience, preventing cascade grid failures caused by cyberattacks, cyber sabotage, or supply-chain compromises.
What organizations need to do
Covered entities must transition from informal cybersecurity to a structured, evidence-backed program. This involves appointing a statutorily qualified Chief Information Security Officer (CISO), enforcing physical and logical IT/OT isolation, maintaining a real-time Cyber Asset Register, operationalizing a 6-hour incident reporting workflow, and undergoing mandatory third-party audits by CERT-In empanelled auditors.
What this means for Indian power companies
In Short: Cybersecurity is no longer an IT recommendation or a voluntary checklist—it is an audited law with personal accountability for C-level executives. You must treat Operational Technology (OT) networks with the same or higher priority than corporate IT, isolate control systems from the internet, strictly vet vendors touching your grid assets, and be ready to prove every control to a CERT-In auditor.
PART II — WHO MUST COMPLY?
The Regulations do not treat all power sector participants identically. Capacity thresholds apply specifically to generation, captive plants, and Energy Storage Systems (ESS), whereas transmission, distribution, grid operators, and exchanges are covered without capacity qualifiers.
Applicability matrix
Entity Category | Applicability | Threshold / Condition | Key Obligations | Exemptions / Exceptions | Relevant Clause |
Generating Companies / Stations | Mandatory | Installed Capacity 50 MW | Full IT/OT cybersecurity governance, CISO, OT segmentation, audits, vendor management. | Generating units below 50 MW. | Reg 3(1)(a) / Reg 4 |
Captive Generating Plants | Mandatory | Aggregate Capacity 50 MW | OT network isolation, Cyber Asset Register, incident reporting, audits. | Captive units under 50 MW not grid-connected to critical nodes. | Reg 3(1)(b) / Reg 4 |
Renewable Energy Entities (RE) | Mandatory | Aggregate Capacity 50 MW at Point of Interconnection | Secure inverter/SCADA communication, OT perimeter protection, air-gapping. | Small solar/wind plants below 50 MW. | Reg 3(1)(c) / Reg 4 |
Energy Storage Systems (ESS) | Mandatory | Installed Capacity 50 MW / MWh | BESS/PSP control system security, local time sync, audit compliance. | Systems below 50 MW. | Reg 3(1)(d) / Reg 4 |
Transmission Licensees (CTU, STU, TBCB) | Mandatory | No minimum threshold (All licensees) | Substation automation security, SCADA/EMS protection, NCIIPC CII compliance. | None. | Reg 3(1)(e) / Reg 4 |
Distribution Licensees (State, Private, Deemed) | Mandatory | No minimum threshold (All licensees) | Smart meter / AMI security, DMS/ADMS hardening, OT isolation, customer data localization. | None. | Reg 3(1)(f) / Reg 4 |
System Operators (NLDC, RLDCs, SLDCs) | Mandatory | No minimum threshold (All Despatch Centres) | Extreme availability controls, air-gapped EMS, 24x7 SOC, 6-hr reporting. | None. | Reg 3(1)(g) / Reg 4 |
Power Exchanges & OTC Platforms | Mandatory | All registered exchanges | Corporate IT security, trading engine protection, data localization. | Exemptfrom OT-specific (Reg 6) & vendor supply chain (Reg 7) chapters. | Reg 3(1)(h) / Reg 4 |
Equipment Vendors / System Integrators | Mandatory | Entities supplying IT/OT products/services to power sector | Trusted sources procurement, NDA, personnel vetting, SLA security clauses. | Vendors supplying purely non-critical commodity items. | Reg 7 / Reg 8 |
PART III — COMPLETE CEA CYBERSECURITY COMPLIANCE CHECKLIST
Status Key:
Mandatory: Explicitly required by the text of the 2026 Regulations.
Conditional: Depends on specific triggers (e.g., deferred sub-regulations, interconnections).
Recommended: Good engineering practice aligned with CEA intent.

# | Compliance Requirement | What the Organization Must Do | Classification | Evidence Required | Responsible Owner | Timeline / Frequency | Clause Ref. |
1 | CISO Appointment | Designate a CISO & Alternate CISO (Indian citizen, regular senior employee, degree qualified, 15 yrs experience) ring-fenced to cybersecurity alone. | Mandatory | Board resolution, HR appointment letter, qualification proof, published details. | Board / HR | Before 1 Apr 2027 (3-yr tenure) | Reg 5(1)-(3) |
2 | Cyber Security Policy | Draft, approve, and implement an overarching policy covering 33 mandated domains (access, incident response, supply chain, asset handling, etc.). | Mandatory | Approved Policy Document, Board Approval Minutes, Annual Review Logs. | CISO | Annual Review | Reg 5(4) |
3 | 24x7 Information Security Division (ISD) | Establish a dedicated, operational 24x7 ISD/SOC for continuous threat monitoring and response. | Conditional(Deferred) | ISD organizational charter, SOC shift logs, SIEM setup documents. | CISO / Head IT | Separate CEA Notification Date | Reg 5(9) |
4 | Cyber Asset Register | Maintain a dynamic, detailed inventory of all IT and OT assets, connected devices, firmware versions, and ownership. | Mandatory | Master Cyber Asset Register (Excel/DB), Change Logs, Verification Sign-offs. | OT/IT Asset Owners | Reviewed annually or upon asset change | Reg 5(12) |
5 | ISO/IEC 27001 Certification | Obtain formal ISO/IEC 27001 certification for all Critical Information Infrastructure (CII) and critical IT/OT systems. | Conditional(Deferred) | Valid ISO 27001 Certificate, Statement of Applicability (SoA), External Audit Reports. | CISO / Quality Lead | Separate CEA Notification Date | Reg 5(24) |
6 | Cybersecurity Training & Awareness | Conduct mandatory cybersecurity training for all employees and specialized training for OT personnel. | Conditional(Deferred) | Training materials, Attendance logs, Post-training assessment scores. | CISO / HR | Separate CEA Notification Date | Reg 5(33) |
7 | Trusted-Source Procurement (IT) | Procure IT hardware, software, and cloud services only from trusted sources/vendors designated by government bodies. | Conditional(Deferred) | Vendor evaluation sheets, Trusted Source certificates, Purchase Order clauses. | Procurement / CISO | Separate CEA Notification Date | Reg 5(39) |
8 | OT Internet & IT Isolation | Maintain absolute physical isolation (air-gap) between OT networks and the Internet/IT. Interconnection requires explicit exceptions. | Mandatory | Network Architecture diagrams, Physical inspection logs, Firewall/Data-Diode rules. | Head OT / Network Head | Immediate / Continuous | Reg 6(1) |
9 | OT Interconnection Exception Governance | If OT-IT/Internet connection is unavoidable, perform documented risk assessment and obtain Board-level explicit approval. | Conditional(On Interconnection) | Risk Assessment report, Board Approval Resolution, Hardening controls documentation. | CISO / COO | Prior to connection enablement | Reg 6(1) |
10 | OT Perimeter Security Hardware | Deploy dedicated, hardware-based boundary security devices (e.g., unidirectional data diodes) at OT perimeters. | Conditional(Deferred) | Purchase orders, Architecture designs, Device configuration backups. | Head OT | Separate CEA Notification Date | Reg 6(2) |
11 | Trusted-Source Procurement (OT) | Procure OT equipment (PLCs, RTUs, IEDs, SCADA) exclusively from trusted equipment manufacturers and sources. | Conditional(Deferred) | Vendor declaration forms, Trusted product clearance certificates. | Procurement / OT Head | Separate CEA Notification Date | Reg 6(7) |
12 | Incident Reporting (6-Hour Clock) | Report all confirmed cyber incidents to CSIRT-Power and CERT-In within 6 hours of detection. | Mandatory | Incident logbook, Time-stamped initial notification email/portal copy. | Incident Response Lead / CISO | Within 6 hours of confirmed detection | Reg 5(18) |
13 | Sabotage Escalation (24-Hour Clock) | Submit a detailed secondary report within 24 hours if an incident involves concluded cyber sabotage in critical systems. | Conditional(On Sabotage) | Detailed Root Cause Analysis (RCA) report, Forensic summary, Ministry report copy. | CISO / Legal | Within 24 hours of confirmation | Reg 5(19) |
14 | Data Localization & Encryption | Store and process all sensitive power system data exclusively within India; enforce strong encryption at rest and in transit. | Mandatory | Data architecture maps, Cloud hosting location certificates, Encryption config logs. | CISO / CIO | Continuous | Reg 5(15) |
15 | Annual Comprehensive Cyber Audit | Undergo an annual cybersecurity audit by CERT-In empanelled auditors (9-15 months spacing between cycles). | Mandatory | CERT-In Auditor Engagement Letter, Final Audit Report, Management Response. | CISO | Annually (rotate auditor after 3 yrs) | Reg 8(1)-(4) |
16 | Audit Remediation Timelines | Remediate Critical and High-risk audit findings within 1 month; Medium and Low findings within 3 months. | Mandatory | Remediation Tracking Matrix, Re-test reports, Closure certificates signed by CISO. | Asset Owners / CISO | High/Crit: 1 Month; Med/Low: 3 Months | Reg 8(5) |
17 | Vendor SLAs & Personnel Risk Assessment | Embed CEA cybersecurity clauses in vendor contracts, require NDAs, and enforce personnel background checks for vendor staff with OT access. | Mandatory | Vendor Contracts, Signed NDAs, Background Verification (BGV) confirmation logs. | Procurement / Legal / CISO | Prior to giving vendor access | Reg 7(1)-(3) |
18 | Time Synchronization (Non-Public IP) | Synchronize all IT and OT system clocks to a reliable, secure time source off the public internet (e.g., local stratum NTP / IRNSS/GPS). | Mandatory | NTP Server topology, Configuration files showing non-public IP time source. | OT Head / Network Head | Continuous | Reg 6(4) |
PART IV — CEA REGULATION → PRACTICAL CONTROL MAPPING
Translate the regulatory text into technical architectures across OT, Control Centers, and Corporate IT environments.
CEA Requirement | Security Objective | Practical Control | Technology / Process | Compliance Evidence |
Reg 6(1) Default OT Isolation | Prevent remote cyberattacks originating from corporate IT or internet from reaching OT. | Complete air-gap or strict unidirectional DMZ boundary between Purdue Levels 2/3 and Level 4. | Hardware Data Diodes, Industrial Dual-homed DMZ Firewalls, Jump Hosts. | Network Topology Diagrams, Firewall Rule Base Audits, Switch Port Configurations. |
Reg 5(12) Cyber Asset Register | Maintain 100% visibility over all hardware/software assets in IT and OT. | Passive OT network listening and automated asset discovery (no active scanning in live OT). | Passive OT Network Detection & Response (NDR) tools, Asset Management DB. | Asset Inventory Export, MAC/IP Binding tables, Annual physical verification sign-off. |
Reg 6(4) Secure Time Sync | Prevent log tampering and ensure precise forensic timeline correlation. | Establish internal, air-gapped NTP servers receiving sync via NavIC/GPS/IRNSS receivers. | Local Stratum-1 NavIC/GPS NTP Master Clock | NTP Configuration files, Time Drift Alert Logs, Local NTP server Status Screenshots. |
Reg 5(18) 6-Hour Incident Reporting | Rapid notification to national authorities to contain sector-wide threats. | Pre-configured incident intake workflows, automated SOAR playbooks, rehearsed reporting templates. | Incident Management Portal, Dedicated escalation call trees, CERT-In reporting forms. | Time-stamped notification receipts from CSIRT-Power & CERT-In portal. |
Reg 5(15) Data Localization & Encryption | Protect critical energy data from unauthorized extra-territorial access. | Restrict all cloud hosting to Indian data centers; enforce AES-256 for data at rest, TLS 1.3 in transit. | On-premise DBs, Indian Hyperscaler clouds (MeitY empanelled), KMS. | Cloud tenant region confirmation reports, SSL/TLS Cipher suite audit reports. |
Reg 7(2) Vendor Personnel Vetting | Mitigate insider threats and supply chain compromises via contractors. | Enforce mandatory background checks, identity checks, and signed non-disclosure agreements. | Vendor Onboarding Portal, Police Verification certificates, PAM jump servers. | BGV Clearance logs, PAM Session Video Recordings, Executed NDAs. |
Implementation across OT assets
SCADA / EMS / DMS: Air-gapped control networks; centralized syslog export to passive monitoring; restricted engineering commands.
PLCs / RTUs / IEDs: Disable unused physical and logical ports (HTTP, Telnet); lock configuration switches; maintain baseline firmware hashes.
Engineering Workstations: Dedicated, hardened laptops with no internet connectivity; USB port locking software; multi-factor authentication (MFA) for access control.
Substation Automation & Field Networks: Implement IEC 62443 zone/conduit models; segregate IEC 61850 GOOSE/MMS traffic using VLANs.
PART V — CEA COMPLIANCE ROADMAP (0–12 MONTHS)
Given the 1 April 2027 commencement date, this 12-month implementation sequence bridges the working period between official notification and mandatory enforcement.

| Phase 0: Immediate Readiness (Months 1–2) | Formally designate CISO & Alternate CISO. Notify Board & publish contact details. Form Steering Committee. | CISO Board Resolution, Public Contact Notice, Charter. | Board / Legal / HR | Reg 5(1)-(3) | Board Resolution, HR File, Email Notification. |
| Phase 1: Policy & Gap Assessment (Months 2–3) | Review current state against 33 policy domains. Draft/update Cyber Security Policy. Conduct gap assessment. | Approved Cyber Security Policy, Gap Assessment Report. | CISO / Steering Comm | Reg 5(4) | Signed Policy Document, Gap Analysis Matrix. |
| Phase 2: Asset Discovery & Register (Months 3–4) | Deploy passive OT discovery. Build comprehensive Cyber Asset Register for all IT & OT. | Master Cyber Asset Register, OT Asset Map. | CISO / OT Head / IT Head | Reg 5(12) | Inventory DB Export, Verification Sign-off. |
| Phase 3: IT/OT Architecture (Months 5–6) | Isolate OT from IT/Internet. Apply DMZs/Data Diodes. Setup non-public local NTP clocks. | Architecture Blueprints, Exception Board Filings, NTP Setup. | Head OT / Network Lead | Reg 6(1), 6(4) | Network Diagrams, Firewall Configs, NTP Logs. |
| Phase 4: Incident Response & Logging (Months 7–8) | Build 6-hour incident reporting workflow to CERT-In / CSIRT-Power. Implement local log aggregators. | Incident Response Plan, Escalation Flowcharts. | Incident Lead / CISO | Reg 5(18)-(19) | Time-stamped Test Logs, IR Simulation Reports. |
| Phase 5: Supply Chain Controls (Months 9–10) | Update vendor contracts with security clauses. Implement vendor BGV & remote access controls. | Vendor SLA Templates, NDA Repository, PAM Logs. | Procurement / Legal / CISO | Reg 7(1)-(3) | Executed Contracts, BGV Certificates. |
| Phase 6: VAPT & Audits (Months 10–11) | Engage CERT-In empanelled auditor. Perform IT/OT VAPT and Comprehensive Cyber Audit. | Pre-audit VAPT Report, Official Cyber Audit Report. | CISO / CERT-In Auditor | Reg 8(1)-(4) | Auditor Report, Remediation Plan. |
| Phase 7: Remediation & Continuous (Months 11–12) | Close Critical/High findings within 1 month. Establish ongoing operational maintenance. | Audit Closure Certificate, Board Compliance Submission. | CISO / Executive Mgmt | Reg 8(5) | Sign-off Letter to CEA / Ministry. |
PART VI — "WHAT SHOULD THE CISO DO FIRST?"
30 / 60 / 90-Day Executive Action Plan
First 30 Days: Mandatory Baseline & Governance
Formalize CISO & Alternate CISO Appointment: Ensure employment contracts, Indian citizenship criteria, and 3-year minimum tenure align with statutory provisions.
Establish Cyber Security Steering Committee: Include Heads of OT, IT, Transmission/Generation Operations, Legal, and HR.
Notify Executive Leadership & Board: Brief the Board on the 1 April 2027 enforcement timeline and personal liability structures.
Draft Mandated Cyber Security Policy: Align existing corporate security policies with the 33 mandatory domains specified in Regulation 5(4).
Days 31–60: Inventory, Architecture & Isolation
Initiate Passive OT Asset Discovery: Deploy non-intrusive network listening tools across control centers, plants, and substations to populate the Cyber Asset Register.
Audit OT-IT Interconnections: Identify all physical and logical connections between OT networks and corporate IT/Internet. Sever unauthorized links immediately.
Formulate Exception Filings: Prepare formal risk assessments and Board resolution filings for any operational interconnections that cannot be air-gapped.
Audit Time Sources: Verify that all SCADA, DCS, PLCs, and historians are receiving time synchronization from local, non-public IP sources (NavIC/GPS master clocks).
Days 61–90: Incident Readiness & Supply Chain Integration
Operationalize the 6-Hour Reporting Workflow: Establish an internal detection-to-reporting mechanism capable of notifying CERT-In and CSIRT-Power within 6 hours of incident confirmation.
Update Vendor Onboarding Protocols: Draft mandatory security addendums, NDAs, and personnel background verification (BGV) requirements for all OT/IT suppliers.
Designate Empanelled Audit Partner: Initiate engagement processes for a CERT-In empanelled auditing firm to schedule the mandatory comprehensive audit.
Top 10 High-Priority Actions That Cannot Wait
Ring-Fence the CISO Role: Terminate dual-hatting (e.g., CIO acting as CISO). The CISO must focus exclusively on cybersecurity.
Sever Direct OT Internet Connections: Immediately disconnect cellular modems, dual-homed engineering laptops, and direct remote-access tools attached to live OT networks.
Freeze Undocumented OT Changes: Enforce strict change control; no unauthorized firmware updates or device swaps in control rooms.
Establish the Master Cyber Asset Register: Begin discovery immediately; building an accurate OT inventory takes months.
Rehearse the 6-Hour Reporting Clock: Run a mock exercise to ensure technical detection escalates to CISO notification within 2 hours, leaving 4 hours for regulatory filings.
Enforce Local Data Residency: Verify that no power plant operational data or grid telemetry is hosted on foreign cloud servers.
Secure Engineering Workstations: Lockdown USB ports and restrict local administrator rights on all laptops used to configure PLCs/RTUs.
Enforce Vendor Personnel Vetting: Require background check documentation for every third-party engineer entering substations or control rooms.
Implement Non-Public Time Sync: Audit NTP sources across all operational nodes to ensure independence from public internet servers.
Budget for CERT-In Third-Party Audits: Allocate capital and operational expenditure for annual independent audits and immediate remediation buffers.
PART VII — EVIDENCE & AUDIT READINESS
An auditor empanelled by CERT-In will evaluate documentary proof of compliance. The evidence matrix below outlines what must be maintained.
Regulatory Audit Evidence Checklist
Evidence Category | Required Document / Artifact | Corresponding Regulatory Ref. | Retention / Review Requirement |
Governance & Roles | CISO Appointment Letter, HR Qualification Verification, Indian Residency Proof. | Reg 5(1)-(3) | Retain for CISO tenure + 3 years. |
Governance & Roles | Board Minutes approving CISO appointment and Cyber Security Policy. | Reg 5(4) | Permanent record. |
Policy Framework | Formal Cyber Security Policy document covering 33 mandated domains. | Reg 5(4) | Annual review evidence. |
Asset Management | Master Cyber Asset Register (hardware, software, firmware, location, owner). | Reg 5(12) | Real-time / Annual sign-off. |
Architecture & Isolation | Network Architecture Diagrams (signed by Head OT), Data Diode/Firewall Configuration Files. | Reg 6(1) | Maintain current state + historical change logs. |
Architecture & Isolation | Documented Risk Assessment and Board Approval for any OT-IT Interconnection. | Reg 6(1) | Valid for duration of connection. |
Time Sync | Local NTP Architecture Diagram and Stratum-1 Clock Sync Logs. | Reg 6(4) | 12 months rolling logs. |
Incident Management | Incident Response Plan, CERT-In / CSIRT-Power initial report copies (time-stamped). | Reg 5(18)-(19) | Retain for 5 years. |
Data Protection | Data Localization Attestation, Database/Disk Encryption Verification Certificates. | Reg 5(15) | Annual verification. |
Supply Chain | Contracts with CEA cybersecurity clauses, Signed Vendor NDAs, Staff BGV Clearance Logs. | Reg 7(1)-(3) | Duration of contract + 3 years. |
Audit & Remediation | Final CERT-In Empanelled Audit Report, Closure Tracking Matrix signed by CISO. | Reg 8(1)-(5) | Retain for 5 years. |
PART VIII — IT/OT-SPECIFIC COMPLIANCE
Operational Technology (OT) drives physical power delivery. Applying standard IT security practices directly to OT can cause inadvertent operational outages. Compliance in OT requires engineered safeguards tailored to high-availability environments.

Key OT compliance operating principles
Safety and Availability First: OT security controls must never compromise physical safety or process availability. Active vulnerability scanning on live control networks (Level 0–2) is strictly prohibited. Asset discovery and threat monitoring must rely entirely on passive network tap / SPAN port traffic inspection.
Patching Limitations & Mitigating Controls: Industrial controllers (PLCs, RTUs) often cannot be patched without long planned outage windows or vendor re-certification. Where immediate patching is unfeasible, entities must document a formal compensating control plan (e.g., network micro-segmentation, protocol filtering, strict jump-host access).
Legacy Systems Handling: Legacy systems running end-of-life operating systems must be isolated behind dedicated industrial firewalls or terminal servers, enforcing strict protocol whitelisting (e.g., allowing only IEC 60870-5-104 or Modbus TCP from designated IP addresses).
Vendor Remote Maintenance: Direct inbound vendor remote access (e.g., TeamViewer, AnyDesk) is explicitly prohibited. Remote vendor sessions must go through a secure OT DMZ Jump Host using Multi-Factor Authentication (MFA), session recording, and real-time approval/monitoring by a plant engineer.
USB & Maintenance Laptops: Portable devices represent a primary infection vector for air-gapped systems. All vendor or engineering laptops must undergo malware scanning at a dedicated kiosk before connecting to OT networks. USB ports on engineering stations must be physically locked or controlled via endpoint management agents.
PART IX — GAP ASSESSMENT FRAMEWORK
Organizations can use this maturity model to evaluate compliance readiness against the 2026 Regulations.
Scoring Scale
0 — Not Implemented: No process or controls exist.
1 — Initial / Ad-hoc: Unofficial, inconsistent activities.
2 — Partially Implemented: Documented but incomplete execution across assets.
3 — Fully Implemented: Fully operational and aligned with CEA requirements.
4 — Measured / Audit-Ready: Measured, continuously monitored, and backed by complete evidence trails.
Operational assessment matrix
Compliance Domain | CEA Requirement Baseline | Current State (0-4) | Identified Gap | Business & Regulatory Risk | Target Priority | Remediation Action | Owner |
Governance | Statutorily qualified CISO appointed for a 3-year term. | CIO currently doubles as CISO. | Regulatory non-compliance, conflict of interest. | P0 | Appoint dedicated CISO, pass Board resolution. | Board / HR | |
OT Isolation | Physical air-gap between OT and IT/Internet. | OT historian linked directly to corporate network. | Critical vulnerability to external malware/ransomware. | P0 | Install dual-homed DMZ firewall and data diode. | Head OT | |
Asset Register | Complete Cyber Asset Register for IT & OT. | Partial Excel sheet for IT only; OT missing. | Inability to define audit scope or detect rogue devices. | P1 | Deploy passive OT asset discovery tool. | CISO / OT Lead | |
Time Sync | Non-public time source for all system logs. | SCADA syncing via public NTP servers. | Regulatory failure; log timestamp invalidation during forensics. | P1 | Install NavIC/GPS stratum-1 time server locally. | OT Head | |
Incident Response | Reporting to CERT-In / CSIRT-Power within 6 hours. | Informal process taking >24 hours to report. | Statutory violation, regulatory penalties. | P0 | Implement SOAR playbook and 2-hour internal escalation. | CISO / IR Lead | |
Supply Chain | Vendor background checks and cybersecurity contracts. | Contracts lack specific CEA clauses. | Third-party supply chain compromise. | P2 | Amend procurement templates and NDA rules. | Procurement | |
Third-Party Audit | Annual audit by CERT-In empanelled auditor. | Audits done irregularly by non-empanelled firm. | Rejection of compliance report by CEA/Ministry. | P0 | Issue RFP for CERT-In empanelled auditing firm. | CISO |
PART X — MANAGEMENT & BOARD DASHBOARD

PART XI — COMMON MISINTERPRETATIONS
# | Common Misconception | What the Regulations Actually Say | Correct Interpretation | Operational / Practical Implication |
1 | "The 2026 Regulations are just updated recommendations, like the 2021 guidelines." | The 2026 Regulations were notified under Section 177 of the Electricity Act, 2003 as binding statutory regulations. | Compliance is legally mandatory with statutory enforcement, not voluntary guidance. | Non-compliance can be escalated to the Ministry of Power and regulatory authorities. |
2 | "All sub-regulations must be implemented by 1 April 2027." | Six specific sub-regulations (5(9), 5(24), 5(33), 5(39), 6(2), 6(7)) are explicitly deferred to separate notification dates. | Baseline compliance begins 1 April 2027, but deferred items carry independent future deadlines. | Do not delay baseline readiness while waiting for deferred provision dates. |
3 | "Every power entity under 50 MW is completely exempt from the regulations." | The 50 MW threshold applies only to generating plants, captive units, and ESS. Transmission, distribution, and load despatch centers have no capacity threshold. | All transmission/distribution utilities and SLDCs must fully comply regardless of megawatt capacity. | Small DISCOMs or private transmission lines cannot claim capacity exemption. |
4 | "Any CERT-In empanelled auditor can audit us forever." | Regulation 8 mandates auditor rotation after three consecutive engagements. | Empanelled auditors must be rotated every 3 years. | Procurement teams must track auditor tenure to prevent invalid audit submissions. |
5 | "We can run active vulnerability scans on our live SCADA networks to build our asset register." | Regulation 6 mandates non-disruptive, safe operational technology practices. Active scanning on live OT can crash legacy PLCs. | Asset identification in live OT must use passive traffic monitoring and non-intrusive discovery. | Standard IT active vulnerability scanners (e.g., Nessus active sweeps) must not be run on live OT subnets. |
PART XII — MASTER CEA COMPLIANCE TO-DO LIST
This master checklist can be copied directly into spreadsheet tools (Excel / Google Sheets) for program tracking.
Priority | Action Item | Regulatory Basis | Responsible Owner | Target Due Date | Primary Evidence Artifact | Status |
P0 | Appoint statutorily eligible CISO & Alternate CISO (3-yr tenure, Indian citizen). | Reg 5(1)-(3) | Board / HR | 30 Days | Board Resolution & Appointment Letter. | Open |
P0 | Physically isolate OT networks from IT and Internet. | Reg 6(1) | Head OT / IT | 60 Days | Network Diagrams & Firewall Rule Audit. | Open |
P0 | Establish 6-hour incident reporting workflow to CERT-In & CSIRT-Power. | Reg 5(18) | CISO / IR Lead | 60 Days | Incident Escalation Plan & Test Log. | Open |
P0 | Engage CERT-In empanelled auditor for annual comprehensive audit. | Reg 8(1)-(4) | CISO / Proc. | 180 Days | Auditor Contract & Empanelment Proof. | Open |
P1 | Build complete Cyber Asset Register for all IT and OT assets. | Reg 5(12) | CISO / Asset Owners | 90 Days | Master Cyber Asset Database. | Open |
P1 | Update Cyber Security Policy to cover all 33 mandated domains. | Reg 5(4) | CISO | 90 Days | Approved Policy Document & Board Minutes. | Open |
P1 | Install local NavIC/GPS NTP server for non-public OT time synchronization. | Reg 6(4) | Head OT | 120 Days | NTP Server Config & Stratum Sync Logs. | Open |
P1 | Mandate data localization (India residency) and encryption for all sensitive data. | Reg 5(15) | CIO / CISO | 120 Days | Cloud Residency Attestation & Cipher Logs. | Open |
P2 | Embed CEA security clauses, NDAs, and personnel BGV requirements into vendor contracts. | Reg 7(1)-(3) | Procurement / Legal | 150 Days | Signed Vendor Contracts & NDAs. | Open |
P2 | Establish remediation workflow: High/Critical in 1 month, Med/Low in 3 months. | Reg 8(5) | CISO / IT / OT | 180 Days | Audit Remediation Tracker. | Open |
P3 | Plan readiness for deferred provisions (24x7 SOC, ISO 27001, Trusted Procurement). | Reg 5(9), 5(24), 5(39), 6(2), 6(7) | CISO | Continuous | Budget Allocation & Strategy Paper. | Open |
Book a free briefing on CEA Cyber Security in Power Sector
Regulation 2026
Recommended reading
Download the CEA Cyber Security in Power Sector Regulation 2026 compliance checklist
More about this new regulation
Disclaimer: This document is intended solely as a practical cybersecurity compliance guide and does not constitute legal advice. Organizations should refer to the officially notified CEA Regulations in the Gazette of India and applicable directions or clarifications from competent authorities for authoritative interpretations.
Recibe semanalmente
Recursos y Noticias
Vea cómo nuestras soluciones de seguridad de OT líderes en la industria abordan los desafíos de seguridad críticos
También te puede interesar

How Zero Trust and Network Segmentation Strengthen NDR in Industrial Environments

Team Shieldworkz

ISA/IEC 62443 and NIST Controls for Securing Cyber-Physical Systems

Team Shieldworkz

North Carolina Ports cyberattack: What happened, what we know and what we still don't

Team Shieldworkz

Malware Prevention Strategies Using Media Scan in OT

Team Shieldworkz

CEA Cybersecurity Regulations 2026: What Indian power companies need to do

Team Shieldworkz

Controles avanzados de detección de amenazas que aumentan la eficacia de NDR

Equipo Shieldworkz

