
Upcoming Webinar
CEA Cybersecurity Regulations 2026:
The Power Sector Compliance Roadmap
By registering, you will also receive the exclusive Shieldworkz CEA 2026 Compliance Checklist
A 25-point actionable framework for power-sector CISOs.
The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 are now law.
Enforceable from April 1, 2027, these regulations transform cybersecurity from a voluntary best practice into a statutory mandate with penalties under the Electricity Act, 2003. If you lead operations, security, or compliance at a generation company, transmission utility, DISCOM, load despatch centre, or renewable energy operator, this is not optional. The clock is ticking.
Join Shieldworkz for an exclusive executive briefing.
The Urgency: Why You Cannot Wait
The Gazette notification is dated 31 July 2026. The enforcement deadline is 1 April 2027. That leaves less than 8 months to build an audit-ready compliance posture.
Under these regulations, power-sector entities must now deliver:
Webinar Details
Date and Time : August 19, 2026, 4:00 PM IST
Location : Virtual Session
Speakers: Prayukth K V, Sharath Acharya
The Mandate, and what it means for your organization
Seven binding obligations under the cybersecurity regulations for the power sector, translated from regulatory language into what your entity actually has to build, staff, and prove.
Appoint a dedicated CISO and Alternate CISO as regular senior employees, Indian citizen/resident, engineering degree, 15+ years of power-sector or IT experience. Minimum 3-year tenure, ring-fenced exclusively to cybersecurity, with contact details published publicly and notified to CSIRT-Power.
Stand up an in-house, India-based ISD, not an outsourced helpdesk — staffed by certified personnel providing round-the-clock monitoring, integrated with your OT network detection and incident response workflow.
Control systems must be physically separated from corporate IT and the internet. Any logical connection requires Board-level approval, ESP firewalls, and unidirectional gateway deployment, data flows one way, out, never in.
Maintain a complete, continuously updated Cyber Asset Register covering every PLC, RTU, HMI, and SCADA component — mapped to criticality tier, so nothing unmapped or undocumented slips through an audit.
A comprehensive audit with a CERT-In empanelled agency is due on a 9–15 month cycle. Any Critical or High finding must be remediated within a 1-month SLA, backed by documented evidence rather than a statement of intent.
OEMs must provide a Bill of Materials, ship digitally signed patches, and pass a formal vendor risk assessment — with contract addendums covering BOM disclosure and NDAs before they ever touch your infrastructure.
Report incidents to CSIRT-Power and CERT-In within 6 hours of discovery. If it qualifies as cyber sabotage, the window tightens to 24 hours for critical systems — with evidence retained for the full audit cycle.
No grandfathering for legacy systems — older control equipment is in scope from day one. All sensitive operational data, cloud systems, and historical logs must reside strictly within India, encrypted, with compensating controls documented, not assumed.
What You Will Learn in This Webinar
This is not a reading of the regulation. This is an operational translation for power-sector leaders.
The Compliance Gap Analysis: Identify where your current OT security posture falls short of CEA 2026 mandates.
IT/OT Architecture Reality Check: How to achieve physical isolation without breaking operational visibility.
The 6-Hour Clock: Building an incident response workflow that satisfies CSIRT-Power and CERT-In reporting timelines.
Vendor & Supply Chain Playbook: Enforcing BOM disclosures, FAT/SAT cybersecurity testing, and contract addendums.
Evidence-Ready Audit Trail: The 12-document First Schedule archive every CISO must maintain for Ministry of Power inspections.
Legacy OT Survival Guide: How to handle end-of-life SCADA, DCS, and PLC assets that cannot be patched.
The 0–30–90–180 Day Roadmap: A practical implementation plan to achieve baseline compliance before the April 2027 deadline.
Who Should Attend
Chief Information Security Officers (CISOs) & Alternate CISOs
Heads of OT / ICS Security
Plant Heads & Station Managers (Thermal, Hydro, Nuclear, Renewables)
Chief Technology Officers & Head of Engineering
Compliance, Risk, and Legal Heads at Gencos, Transcos, DISCOMs, and SLDCs
Procurement & Vendor Management Leaders
Who Should Attend
Shieldworkz is an end-to-end industrial OT cybersecurity company. We do not sell generic IT security tools repurposed for factories and grids. We design, implement, and manage cybersecurity specifically for operational technology environments - SCADA, DCS, PLCs, substation automation, and smart grid infrastructure.
We understand the difference between a corporate firewall and an OT firewall that speaks IEC 61850. We understand why a power plant cannot simply "patch and reboot." And we understand what Indian regulators - and Indian grid operators - actually need to demonstrate compliance.
Secure Your Spot Now
Meet the Panel Experts



