site-logo
site-logo
site-logo
HERO BG

Upcoming Webinar

CEA Cybersecurity Regulations 2026:
The Power Sector Compliance Roadmap

By registering, you will also receive the exclusive Shieldworkz CEA 2026 Compliance Checklist
A 25-point actionable framework for power-sector CISOs.

The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 are now law.

Enforceable from April 1, 2027, these regulations transform cybersecurity from a voluntary best practice into a statutory mandate with penalties under the Electricity Act, 2003. If you lead operations, security, or compliance at a generation company, transmission utility, DISCOM, load despatch centre, or renewable energy operator, this is not optional. The clock is ticking.

Join Shieldworkz for an exclusive executive briefing.

The Urgency: Why You Cannot Wait

The Gazette notification is dated 31 July 2026. The enforcement deadline is 1 April 2027. That leaves less than 8 months to build an audit-ready compliance posture.

Under these regulations, power-sector entities must now deliver:

Webinar Details 

Date and Time : August 19, 2026, 4:00 PM IST 

Location : Virtual Session 

Speakers: Prayukth K V, Sharath Acharya

The Mandate, and what it means for your organization

Seven binding obligations under the cybersecurity regulations for the power sector, translated from regulatory language into what your entity actually has to build, staff, and prove.

08
CONTROL DOMAINS TO OPERATIONALIZE
6 Hrs
INCIDENT REPORTING WINDOW
₹1 Cr
MAX PENALTY PER INCIDENT
GovernanceTechnical ControlTime-Bound
01
Governance
Governance & CISO Ring-Fencing

Appoint a dedicated CISO and Alternate CISO as regular senior employees, Indian citizen/resident, engineering degree, 15+ years of power-sector or IT experience. Minimum 3-year tenure, ring-fenced exclusively to cybersecurity, with contact details published publicly and notified to CSIRT-Power.

02
Governance
24×7 Information Security Division

Stand up an in-house, India-based ISD, not an outsourced helpdesk — staffed by certified personnel providing round-the-clock monitoring, integrated with your OT network detection and incident response workflow.

03
Technical Control
IT/OT Segregation & Network Architecture

Control systems must be physically separated from corporate IT and the internet. Any logical connection requires Board-level approval, ESP firewalls, and unidirectional gateway deployment, data flows one way, out, never in.

04
Technical Control
Cyber Asset & Critical System Registers

Maintain a complete, continuously updated Cyber Asset Register covering every PLC, RTU, HMI, and SCADA component — mapped to criticality tier, so nothing unmapped or undocumented slips through an audit.

05
Time-Bound
Cybersecurity Audits & VAPT

A comprehensive audit with a CERT-In empanelled agency is due on a 9–15 month cycle. Any Critical or High finding must be remediated within a 1-month SLA, backed by documented evidence rather than a statement of intent.

06
Technical Control
Vendor & Supply-Chain Security

OEMs must provide a Bill of Materials, ship digitally signed patches, and pass a formal vendor risk assessment — with contract addendums covering BOM disclosure and NDAs before they ever touch your infrastructure.

07
Time-Bound
Incident Reporting & Retention

Report incidents to CSIRT-Power and CERT-In within 6 hours of discovery. If it qualifies as cyber sabotage, the window tightens to 24 hours for critical systems — with evidence retained for the full audit cycle.

08
Governance
Legacy, Data Residency & Remote Operations

No grandfathering for legacy systems — older control equipment is in scope from day one. All sensitive operational data, cloud systems, and historical logs must reside strictly within India, encrypted, with compensating controls documented, not assumed.

SHIELDWORKZ · CEA 2026 COMPLIANCE FRAMEWORKREFERENCE ONLY — VERIFY AGAINST CURRENT CEA / CERT-IN / CSIRT-POWER GUIDELINES

What You Will Learn in This Webinar

This is not a reading of the regulation. This is an operational translation for power-sector leaders.

The Compliance Gap Analysis: Identify where your current OT security posture falls short of CEA 2026 mandates.

IT/OT Architecture Reality Check: How to achieve physical isolation without breaking operational visibility.

The 6-Hour Clock: Building an incident response workflow that satisfies CSIRT-Power and CERT-In reporting timelines.

Vendor & Supply Chain Playbook: Enforcing BOM disclosures, FAT/SAT cybersecurity testing, and contract addendums.

Evidence-Ready Audit Trail: The 12-document First Schedule archive every CISO must maintain for Ministry of Power inspections.

Legacy OT Survival Guide: How to handle end-of-life SCADA, DCS, and PLC assets that cannot be patched.

The 0–30–90–180 Day Roadmap: A practical implementation plan to achieve baseline compliance before the April 2027 deadline.

Who Should Attend

Chief Information Security Officers (CISOs) & Alternate CISOs

Heads of OT / ICS Security

Plant Heads & Station Managers (Thermal, Hydro, Nuclear, Renewables)

Chief Technology Officers & Head of Engineering

Compliance, Risk, and Legal Heads at Gencos, Transcos, DISCOMs, and SLDCs

Procurement & Vendor Management Leaders

Who Should Attend

Shieldworkz is an end-to-end industrial OT cybersecurity company. We do not sell generic IT security tools repurposed for factories and grids. We design, implement, and manage cybersecurity specifically for operational technology environments - SCADA, DCS, PLCs, substation automation, and smart grid infrastructure.

We understand the difference between a corporate firewall and an OT firewall that speaks IEC 61850. We understand why a power plant cannot simply "patch and reboot." And we understand what Indian regulators - and Indian grid operators - actually need to demonstrate compliance.

Secure Your Spot Now

By submitting, I consent to receive communications from Shieldworkz, its subsidiaries, partners, and affiliates.

Meet the Panel Experts

Seats are limited and priority access is reserved for power-sector operators.