
Regulatory Playbook
The CEA Cyber Security in Power Sector
Regulation 2026
No signup required!
The CEA Cyber Security Regulations 2026: What Every Power Sector Entity Needs to Know
On 31 July 2026, the Central Electricity Authority notified the CEA (Cyber Security in Power Sector) Regulations, 2026 in the Gazette of India. Issued under the Electricity Act, 2003, with MeitY concurrence, the regulations convert India's power-sector cybersecurity framework from the voluntary 2021 guidelines into a binding, audited, evidence-based compliance mandate. Enforcement begins 1 April 2027, with six dependency-heavy provisions deferred to separate CEA orders.
This isn't an incremental update to existing guidance. It's a structural shift from "here's what we recommend" to "here's what you must document, implement, and prove during an annual third-party audit." Generators at or above 50 MW, every transmission and distribution licensee, every load despatch centre, and power exchanges are directly regulated, and for the first time, vendors supplying this sector are directly bound by their own chapter of obligations.
Who Is Actually Covered
The regulations apply to any entity that owns, operates, or manages Operational Technology infrastructure tied to the interconnected power system, along with connected IT infrastructure. In practice, that means:
Generating companies, captive generating plants, and Energy Storage System organizations at or above the 50 MW installed-capacity threshold.
Transmission licensees, CTU, state transcos, and private TBCB licensees, with no capacity threshold.
Distribution licensees, state, private, and deemed licensees, again with no threshold.
National, Regional, and State Load Despatch Centres.
Power exchanges and over-the-counter platforms, though these are exempt from the OT-specific and vendor chapters.
The Core Requirements at a Glance
Regulation 5 alone runs to forty-two clauses covering governance, architecture, data handling, and vendor management. The practical shape of the obligation looks like this:
A designated CISO and alternate CISO , regular senior-management employees, Indian citizens and residents, holding an engineering degree, with at least fifteen years of power sector or IT experience, a minimum three-year tenure, and a role ring-fenced to cyber security alone.
A Cyber Security Policy covering thirty-three mandated elements, spanning governance, criticality classification, incident response, access management, supply-chain risk, data handling, and change management, approved and reviewed annually by the head or board.
A Cyber Crisis Management Plan prepared in consultation with CSIRT-Power, vetted by CERT-In, and tested annually through drills on non-repeating scenarios.
OT physically isolated from the internet and from IT by default; where interconnection is unavoidable, it must be risk-assessed, hardened, board-approved, and continuously monitored.
Comprehensive asset and critical-system registers, reviewed annually or on any commissioning or replacement, whichever comes first.
Six-hour incident reporting to CSIRT-Power and CERT-In for standard events, tightening to twenty-four hours for concluded cyber sabotage in critical systems.
Hard data localization, sensitive information, including cloud-hosted and historical data, must be encrypted, secured, and stored exclusively within India.
Vendor SLAs embedding all applicable cybersecurity requirements and an NDA that survives contract expiry, with mandatory personnel risk assessments for vendor staff touching critical systems.
The Audit Regime
A cyber security audit under these regulations means one conducted by a CERT-In empanelled auditor, or another auditor the Ministry of Power designates. This empanelment requirement attaches to every statutory audit, the annual comprehensive audit, pre-commissioning audits including vulnerability assessment and penetration testing, and web-application clearance audits.
Comprehensive annual audits of all critical systems, spaced 9-15 months apart, with mandatory auditor rotation after three consecutive engagements.
Auditor's report due within six weeks of audit commencement; critical and high-risk findings remediated within one month, medium and low findings within three months.
A closure report due within six months of audit commencement, with major findings reported to the head or board.
A separate annual self-audit against all applicable regulations, with non-compliances remediated before the next financial year's self-audit , subject to third-party verification at the entity's cost if the Ministry of Power demands it.
How Shieldworkz Supports Your CEA 2026 Readiness
Turning forty-two clauses of Regulation 5, nine clauses of Regulation 6, and thirty-three policy elements into an executable, audit-ready program is the real work behind this regulation. Shieldworkz OT security team supports power sector entities, generators, transmission and distribution licensees, and load despatch centres , through the full readiness cycle:
Clause-by-clause gap assessments mapping your current posture against every applicable CEA 2026 requirement.
Cyber Security Policy and Cyber Crisis Management Plan development, including preparation for CERT-In vetting.
Passive asset discovery to build compliant cyber asset and critical-system registers without touching live OT.
OT/IT architecture review and segmentation design to meet the Regulation 6 isolation requirements.
Continuous monitoring deployment that builds the operating history your first audit will expect to see.
Whether you're starting from a blank compliance program or closing specific gaps ahead of the 1 April 2027 deadline, we help translate the regulation into a prioritized roadmap your board can act on.
Get the Full Breakdown , No Signup Required
Want the complete clause-by-clause view, including how the six deferred provisions map to your specific asset class and what to start preparing for now? Download the full CEA 2026 regulatory breakdown directly, no form, no email, no signup required.
Download the Full Regulations
Prefer to talk it through with someone who works with power sector OT environments every day? We're happy to walk through your specific scope, timeline, and gaps directly.
Schedule a Demo With Shieldworkz OT Security Experts
Find out where your CEA 2026 compliance program has gaps , including the deferred provisions most teams aren't budgeting for yet , before an auditor, CERT-In, or CSIRT-Power finds them for you.
Get CEA 2026 Ready. Identify Gaps, Strengthen OT Security, and Build an Audit-Ready Path. Book a 30-Minute Consultation Today.
