On 31 July 2026 the Central Electricity Authority notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 in the Gazette of India, Extraordinary. The document published on that date is not a consultation paper, an advisory, or a further revision of the guidance the sector has worked with since 2021, but subordinate legislation made under the Electricity Act, 2003, and every entity within its scope is bound by it.
The regulations come into force on 1 April 2027, with six of the more demanding provisions deferred to dates that the Authority will notify through separate orders. In the period between now and the commencement date, the organisations that own and operate India's generation, transmission, distribution, dispatch and market infrastructure are expected to establish a body of governance, documentation, architecture and assurance that most of them do not presently hold in the form the regulations describe.
This guide explains what the regulations require, which organisations must comply, what has to be established rather than simply documented, how the audit and self-audit cycles operate, what is now expected of vendors, and how a compliance programme might reasonably be sequenced against the commencement date.

Why These Regulations Exist
It is useful to begin with the conditions the regulations were written to address, because the structure of the document follows from them fairly directly.
India's electricity system has changed considerably faster than the assumptions built into much of the equipment that runs it. Generation, transmission, distribution and load dispatch are now connected by continuous real-time data exchange that did not exist when a great deal of the installed control equipment was originally specified, and distribution utilities have brought metering, outage management, billing and consumer platforms into the same network estate that supports operations. Grid-connected rooftop solar and energy storage systems have placed internet-facing, vendor-managed devices behind a very large number of consumer connections. Each of these developments delivered genuine operational and commercial value, and each of them also created a path into the power system that had not previously existed.
The Authority responded to these conditions in stages rather than in a single instrument. The CEA (Cyber Security in Power Sector) Guidelines, 2021 were the first comprehensive statement of what preparedness in the sector should look like, and they were subsequently amended. The Ministry of Power established the Computer Security Incident Response Team - Power as the sector's incident coordination body, and cyber security audits conducted by CERT-In empanelled auditors became established practice across a substantial part of the industry over the same period.
That framework achieved what guidance is capable of achieving, in that it gave utilities a common reference, raised the level of awareness considerably, and created the institutions through which a sectoral response could be organised. What it could not do was compel, since a guideline may be read, accepted in principle, and then deferred against a capital programme without any consequence attaching to that decision, and the variation in preparedness across the sector reflected precisely that position. The 2026 Regulations address this by converting the substance of the guidance into a statutory instrument and attaching to it named accountability, defined timelines, mandatory independent audit and a route to enforcement.
The Legal Character of the Regulations
Because these are regulations made under the Electricity Act rather than guidance issued alongside it, non-compliance now carries a consequence, and that distinction governs how the remainder of the document should be read.
Where an entity does not comply, the regulations provide that the Chief Information Security Officer of the Ministry of Power may, after seeking written clarification and examining it, recommend to the Central Government that proceedings be initiated under the Information Technology Act, 2000, or file a petition before the Appropriate Commission for proceedings under the Electricity Act. The regulations do not themselves prescribe penalties, and the financial consequence that arises under the Electricity Act is modest when measured against the balance sheet of a large utility, so the exposure should not be assessed in monetary terms alone. A proceeding of this kind is a matter of record before a Commission that also determines tariff, licence and performance matters, and it is initiated by an official of the Ministry of Power, which is a materially different position from the one that obtained under guidance.
A further mechanism changes the way assurance is likely to be treated. The Chief Information Security Officer of the Ministry of Power may call for the audit closure report or the compliance report of any entity, seek written clarification, and then, with the prior approval of the Authority and prior notice to the entity, appoint a third-party auditor to verify what that entity has claimed, with the cost of the verification borne by the entity itself. Where the findings of that third-party audit differ from the observations recorded in the entity's own closure report, the Ministry's officer may take further action, so a compliance position that an entity reports to the regulator is capable of being independently tested at the Ministry's initiative and at the entity's expense.
Sitting alongside the regulations is the Computer Security Incident Response Team - Power, which the document establishes as the coordinating agency for reporting and responding to cyber security incidents in the sector and as the nodal agency for their analysis, prediction and prevention. Its directions and guidelines are to be complied with by entities and vendors alike, and it is responsible for developing standard operating procedures, sub-sector specific benchmarks and security controls, for issuing alerts, advisories and threat intelligence in coordination with CERT-In and the National Critical Information Infrastructure Protection Centre, and for advising entities in the preparation of their crisis management plans. The Authority may in addition designate sub-sectoral response teams for generation, transmission, distribution and grid operation.
The practical consequence for planning is that the notification should be treated as a foundation rather than as the complete statement of what will be required, since a considerable body of binding technical detail will follow it in the form of directions, benchmarks and separate orders, and acting upon those issuances is itself a named responsibility of the entity's own Chief Information Security Officer.
Scope and Applicability
Scope is determined by function rather than by licence category, in that the regulations apply to every entity that owns, operates or manages operational technology infrastructure associated with the interconnected power system, together with the information technology infrastructure that is connected to it, whether that connection is physical or logical. The regulations apply to the existing as well as the upcoming infrastructure of those entities, so an obligation cannot be avoided on the basis that a system was commissioned before the regulations were made.
The entities named in the regulations, and the qualifications that apply to them, are as follows.
- Generating companies, captive generating plants and organisations having energy storage systems, where installed capacity is 50 MW or more. Entities below that threshold are encouraged, though not required, to implement the minimum baseline controls that CERT-In has published for micro, small and medium enterprises.
- Transmission licensees and distribution licensees, to which no capacity threshold applies.
- The National Load Dispatch Centre, the Regional Load Dispatch Centres and the State Load Dispatch Centres, to which no capacity threshold applies.
- Power exchanges and over the counter platforms, which carry the general cyber security requirements but fall outside the chapters dealing specifically with operational technology systems and with vendors.
The provision most frequently overlooked is the one that binds vendors directly rather than through the entities that purchase from them. The regulations define a vendor to include original equipment manufacturers and suppliers, system integrators, suppliers of hardware or software associated with original equipment, contractors and service providers including cloud service providers, and the manufacturers and suppliers of the hardware, firmware and software associated with the original equipment or control systems of a Distributed Generation Resource owned by a prosumer, which is expressly stated to include inverters, communication modules, monitoring systems and the associated control or energy management software.
The consequence of that definition is that a manufacturer of grid-connected inverters, a provider of a monitoring platform, a distributed control system vendor and a cloud service provider are each regulated parties within the Indian power sector in their own right, and not merely counterparties to a regulated entity, which is a position that both utilities and their supply chains will need to reflect in the next procurement cycle.

The Chief Information Security Officer and the Information Security Division
The provisions that most entities will find hardest to satisfy are not the technical ones but those concerning personnel, and the qualification requirements are unusually specific.
Every entity must designate a Chief Information Security Officer and an Alternate Chief Information Security Officer, both of whom must be citizens as well as residents of India, must hold a degree in engineering or its equivalent from a recognised institute, and must have at least fifteen years of experience in the domain of the power sector or of information technology. Both must be regular employees at senior management level, an employee must be designated to the role for a minimum period of three years, and the two positions may not remain vacant at the same time. The officer reports to the head of the entity, and where an entity such as a State Load Dispatch Centre is not independent but forms part of a holding or parent company, that entity must nonetheless have a separate officer reporting to the head of the holding or parent company, together with its own alternate. The contact details of both officers must be placed and maintained in the public domain and communicated to the sectoral response team and to all internal and external stakeholders, and the officer must attend cyber security training for at least five working days in each financial year.
The regulations further provide that the role of the Chief Information Security Officer is to be ring fenced to the tasks of cyber security related matters only, which means that an entity cannot satisfy the requirement by conferring the designation on the head of information technology while leaving the substantive duties of that post in place.
Supporting the officer, and among the provisions whose commencement has been deferred, is a dedicated Information Security Division, which must be established within India, must be headed by the Chief Information Security Officer, and must remain operational round the clock. The division must be deployed with sufficient staffing, every member of staff must hold a valid certificate of successful completion of a domain-specific cyber security course, staff must attend cyber security training associated with the power sector for at least five working days in each financial year, and staff must be deployed to the division for a minimum tenure of three years.
Taken together these requirements represent a substantial and continuing organisational commitment, particularly for a state distribution utility or a mid-sized generating company, and they also carry the longest lead time of any activity in the programme, since a candidate holding fifteen years of relevant experience cannot be recruited within a quarter and a certified division operating round the clock cannot be assembled at short notice. For that reason the recruitment and development work should be commenced before the documentation work rather than after it.
The duties attaching to the office are set out in some detail, and two of them operate to fixed timeframes. Cyber security incidents must be reported to the sectoral response team and to CERT-In within six hours of detection, and where an incident is concluded to be cyber sabotage in critical systems it must be reported within twenty-four hours. Beyond those reporting duties, the officer is responsible for the quarterly review of compliance, for acting upon the directions, guidelines and advisories issued by the Central Government, the Authority, CERT-In and the sectoral response team, for gathering and analysing cyber threat intelligence, for sharing detailed incident reports, action taken reports and root cause analyses, for the custody and retention of the documents the regulations specify, for ensuring that the firmware and software of critical systems are updated, for the random testing of day-to-day operations against the entity's own policy, and for ensuring the development, implementation and annual review of the Cyber Security Policy, the Cyber Crisis Management Plan, the data retention policy and the backup policy.

What the Regulations Require an Entity to Establish
It is worth distinguishing between the requirements that can be satisfied by producing a document and those that can only be satisfied by first establishing the underlying capability, because the second category is where the majority of the effort and the majority of the cost will be found. The regulations name a specific set of artefacts, and each of them rests on a body of engineering and analytical work that has to be completed before the document can honestly be produced.
The cyber asset register. The entity must maintain a register recording all cyber assets together with the requisite details, including ownership and the hardware, firmware, software and patch state of each, and must separately record all critical systems with their configuration, hardware, software and network architecture, depicting the data flows and the communication protocols used within them. The register must be reviewed and updated at least once in every financial year, or upon the commissioning of any new cyber asset or critical system including replacements, whichever occurs earlier. This is the foundational deliverable of the programme, since the classification of critical systems, the risk assessment, the scope of the audit, the backup obligation and the segmentation design all depend upon it, and it is also the requirement that most entities find they cannot meet from existing records, because inventories compiled for maintenance purposes seldom capture controllers, remote terminal units, protection relays, engineering workstations and human machine interfaces at the level of configuration and protocol detail that the regulations expect. Passive discovery is the appropriate method for this work, since conventional scanning is not a safe instrument in a live production environment.
The identification and segregation of critical systems. The entity must identify all of its systems and classify them as critical or non-critical against defined criteria that take account of their impact on the business continuity plan, and must record those systems in a register. The criteria are for the entity itself to define, and that discretion is genuine, but it is also consequential, because the classification determines the scope of the audit and of the certification, the extent of the backup obligation and the controls applying to remote access. A classification arrived at without a documented and defensible method is liable to become an audit finding in its own right.
The Cyber Risk Assessment and Mitigation Plan. For every asset recorded in the register, the entity must maintain a plan identifying the vulnerabilities and threats applicable to that asset and the risk arising from them, together with control and mitigation measures commensurate with the criticality of that risk. The plan must be updated at least once in every six months and reviewed at least once in every financial year, and the regulations require that it be implemented rather than merely maintained.
The Cyber Security Policy. The policy must be aligned with the business continuity plan of the entity, covering the operational technology environment as well as the information technology environment. Because a great many of the operative requirements elsewhere in the regulations direct that work be carried out in accordance with a procedure defined in the Cyber Security Policy, the policy is in practice the instrument upon which the remainder of the framework depends, rather than a statement of intent, and it must be approved and reviewed annually by the head or the board of the entity. Among other matters, it must define procedures for the following:
- Preparing the cyber asset register and classifying assets according to criticality and identified risk
- Identifying critical systems, and identifying and classifying critical web applications
- Cyber risk assessment and mitigation, and the management of vulnerabilities in critical systems
- Identifying and reporting cyber sabotage in critical systems
- Access control governed by the principles of authentication, authorisation and accounting
- Personnel risk assessment, including in respect of personnel deployed by vendors and following termination, resignation and superannuation
- Cyber supply chain risk management
- Remote access to cyber assets, and remote operation of operational technology systems
- Change management, together with the criteria classifying software updates according to whether a prior cyber security audit is required
- Backup, and the encryption of sensitive data in storage, in backup and in transmission
- Selection of a reference time source, and the logical separation of operational technology from information technology
- Classification of data and information permitted to be communicated beyond national boundaries
- Safe and secure disposal of obsolete cyber assets and of sensitive data
- Data retention, specifying the manner, form and period for which records are kept
The Cyber Crisis Management Plan. Prepared in consultation with the sectoral response team, vetted by CERT-In, and approved and reviewed annually by the head or the board, this plan must contain a detailed standard operating procedure for detecting and identifying incidents, the criteria by which an incident is classified as a crisis, and a list of all possible crisis scenarios, together with the stakeholders and their respective responsibilities, the manner and mode of communication during a crisis, and the mitigative measures to be applied. Its efficacy must be tested at least once in every year through exercises and mock drills, and the scenarios selected in any year may not overlap with those tested and verified earlier until the cycle of all listed scenarios has been completed, which makes the breadth of the scenario catalogue a multi-year commitment undertaken at the moment it is written.
The Incident Response and Recovery Plan. Distinct from the crisis plan, this must detail the types of incident, the associated risk analysis and the risk-based, incident-specific response required for the effective and timely restoration of an affected system, and it must be reviewed and updated at least once in every six months.
Backup, and the data retention policy. Online and offline backups of all critical systems must be held in a separate, safe and secure environment, and backup data must be no older than one month. The integrity of that data and its restoration must be tested against the requirements of the business continuity plan, which is a materially different obligation from possessing a backup. The data retention policy must specify the manner and form in which records are retained, and the regulations set minimum periods for cyber security audit reports, certification audit reports, self-audit reports, remote access risk assessments and approvals, and logs and forensic records, while acceptance test reports, including the cyber security testing carried out within them, must be retained throughout the life of the cyber asset.
Critical Information Infrastructure and Protected Systems. The entity must provide the relevant information to the National Critical Information Infrastructure Protection Centre for the identification of Critical Information Infrastructure, and where an asset is so identified it must approach the Appropriate Government within sixty days for that asset to be notified as a Protected System. Information technology networks containing Critical Information Infrastructure must be separated from the internet and from the remainder of the information technology networks, and Critical Information Infrastructure and Protected Systems must not be discoverable on public platforms unless the head or the board has approved on the basis of business requirements, criticality and risk assessment.
Testing before commissioning. A cyber security audit including vulnerability assessment and penetration testing must be carried out before any new critical system is commissioned, and that requirement extends to the replacement of an existing critical system. The details and functionality of every newly commissioned or replaced critical system must then be furnished to the sectoral response team within thirty days.
Awareness and exercise. Cyber security awareness programmes and cyber security exercises, including mock drills and tabletop exercises, must be conducted at least once in every six months.
The common characteristic of all of these requirements is that the regulations do not ask only whether an entity holds a document, but whether the capability described in that document exists, whether it has been exercised, and whether the entity can produce evidence of both, with the result that established engineering practice which leaves no record is treated no differently from an absence of practice.
Requirements Applying to Operational Technology Systems
Where the preceding requirements describe a management system, those applying to operational technology describe an architecture, and it is here that the outage windows and the capital budget will principally be consumed.
The default position established by the regulations is the physical isolation of the operational technology system from the internet and from the information technology system. Where isolation from the information technology system is not possible on account of business requirements, an interconnection may be permitted in accordance with the procedure defined in the Cyber Security Policy, with suitably hardened logical separation, on the basis of a risk assessment of that interconnection and with the approval of the head or the board of the entity, and the interconnection must then be continuously monitored for the detection of malicious activities, with the approval and the associated logs retained in accordance with the data retention policy. Where data and information are identified as needing to pass in each direction between the two environments, they must flow through a separate communication channel and a unidirectional gateway.
The operational technology environment must itself be segmented into different trust levels on the basis of criticality, security requirements and risk assessment, and the communication system of the operational technology environment must be isolated from that of the information technology environment, which is a distinct obligation from network separation and one that a number of utilities do not presently meet, since operational and corporate traffic is frequently carried over shared transmission infrastructure.
At the point where the operational technology system meets the communication system of the power system, suitable perimeter level cyber security devices including a firewall are required, and the deployed security system must satisfy requirements that include the detection and filtering of operational technology protocols and traffic, deep packet inspection, content, user and application based filtering, intrusion detection, geo-fencing and detection based on signature and behavioural anomalies. The regulations further provide that updates including signatures for the devices forming part of that security system must be carried out in offline mode, which reflects the position that a security device deployed on a control network should not be given an outbound internet dependency. Security devices are separately required at the Electronic Security Perimeter, and the logs of those devices must record the exchange of data and information passing through them, with the rules and policies of perimeter security devices reviewed and updated at least once in every year.
Two of the provisions concern the movement of information across national boundaries, and they should be read together. The control and operation of power system elements, and the exchange of information including real-time data, must take place over a dedicated communication channel isolated from the internet through perimeter level cyber security devices, and must be confined to national boundaries only, while an entity having cross-border power system elements may exchange information beyond those boundaries only through a dedicated separate communication system and a unidirectional gateway, isolated from the internet, subject to continuous monitoring for anomalies and unauthorised attempts. Separately, sensitive information and sensitive data, including such data hosted on cloud platforms and the associated historical data, must be stored in an encrypted, secured and protected environment and must reside within India only.
Remote operation and remote access are treated as distinct matters and both are constrained. Remote operation of an entity's systems, where it is necessary for business requirements, must be carried out from within India, with the prior approval of the head or the board, in accordance with the procedure specified in the Cyber Security Policy, over a dedicated communication channel isolated from the internet. Remote access to cyber assets is permitted only for troubleshooting and emergency requirements, and in the case of cyber assets associated with non-critical systems it requires the approval of the Chief Information Security Officer together with suitable security control measures, while in the case of critical systems it may be granted only after a comprehensive risk assessment and the identification of effective measures, must be continuously monitored to detect any anomaly or attempt at unauthorised use, and must be supported by a retained record of the risk assessment, the physical document of approval and the associated logs.
Three further requirements are easily overlooked and consistently consequential. The systems, networks and applications associated with the physical security of critical systems must be physically separated from the networks of those critical systems, or logically separated where physical separation is not feasible and the head of the entity has approved. Updates including patches applied to operational technology systems must be digitally signed by the original equipment manufacturer and may be deployed in offline mode following risk assessment and successful testing in a simulated environment, and where the manufacturer's digital signature is not available for a patch the validity and authenticity of that patch must be verified. Finally, the reference time source selected for the operational technology system must be either terrestrial or India specific satellite based and independent of the internet, with a detailed cyber risk assessment carried out before that source is selected, which is a requirement of wide application given that a considerable number of operational environments presently synchronise over public internet time services.
Cyber Security Audit and Self-Audit
A comprehensive cyber security audit encompassing all critical systems must be conducted at least once in every financial year by an auditor empanelled with CERT-In, or by any other auditor designated by the Ministry of Power through a separate order, and the interval between two consecutive audits must be not less than nine months and not more than fifteen months. The auditing agency engaged must deploy its own qualified personnel, excluding any staff already deployed for that entity, and no three consecutive audits may be carried out by the same auditing agency or the same personnel. The scope of each audit must include verification that the findings identified in the previous audit have been closed. Separately, and among the deferred provisions, the entity must ensure compliance with and acquire either an ISO/IEC 27001 certificate or a Technical Criteria Certificate encompassing all critical systems, with no four consecutive certification audits carried out by the same auditing agency or personnel.
The timelines that follow the commencement of an audit are the aspect of the framework that requires the most careful planning, and they are as follows.
| Stage | Deadline |
|---|---|
| The auditor submits the cyber security audit report | Within six weeks of the audit commencing |
| Critical and high-risk vulnerabilities addressed | Within one month of the report being submitted |
| Medium and low-risk vulnerabilities addressed | Within three months of the report being submitted |
| The auditor submits the audit closure report | Within six months of the audit commencing |
One month in which to close every critical and high-risk finding is a demanding interval in an environment where remediation frequently requires a planned outage, and the regulations anticipate this by providing that appropriate compensatory controls shall be deployed to contain such vulnerabilities until audit clearance is obtained. That provision rewards preparation, in that an entity which has agreed in advance the compensating control patterns it will apply to the classes of finding it expects, whether by segmentation, by restriction of access or by enhanced monitoring, will be able to meet the interval, whereas an entity that begins to consider remediation only upon receipt of the report will not.
Alongside the independent audit, the entity must conduct a self-audit in every financial year to assess its compliance with the regulations, and it may designate a member of its board or of senior management as responsible for that compliance. Any non-compliance identified must be addressed in a time-bound manner and, in any event, before the self-audit scheduled for the following financial year. As noted earlier, both the audit closure report and the self-audit compliance report may be called for and independently verified at the Ministry's initiative and at the entity's cost.
Requirements Applying to Vendors
The chapter dealing with vendors is short, and it places obligations directly upon the vendor rather than routing them through the purchasing entity. A vendor must do each of the following.
- Provide the entity with documented and tested procedures, together with a recovery plan, for the restoration of the systems it has supplied from potential cyber crisis scenarios.
- Ensure that security patches and updates, either digitally signed or validated and authenticated, remain available to the entity throughout the contract period or the useful life of the systems supplied, whichever is later.
- Provide a detailed document setting out the requirements and processes, including the security patches and updates required on third-party components, for integrating any component or sub-system it has supplied.
- Provide details of the end of support or end of life of the software, hardware and systems supplied, including those sourced from third parties.
- Provide a bill of materials to the entity, in accordance with the guidelines issued by CERT-In from time to time, comprising a detailed list of all components supplied for applications including firmware deployed in critical systems.
- Ensure that hardware and software are hardened before being supplied to the entity, by enabling all inherent security capabilities and applying secured configuration and controls.
- Establish a formal, structured process through which entities may report vulnerabilities in its products and services, and furnish those vulnerabilities to the sectoral response team through its vulnerability disclosure and management programme.
A separate provision addresses Distributed Generation Resources owned by prosumers and places the responsibility upon the vendor. Any application, the associated monitoring and control servers, and the real-time data of such systems, including any data or information hosted on cloud platforms together with the associated historical data, must be stored in an encrypted, secure and protected environment and must reside exclusively within India. Remote access and remote operation of the grid-connected devices, and the exchange of their real-time data and information with remote applications, aggregators and distribution licensees, must be established through a secure channel following mutual authentication, and that communication must be encrypted.
For entities, the practical route to assurance in respect of these obligations is the procurement specification rather than the contractual dispute, since the regulations already require that the procurement process mandate the inclusion of Factory Acceptance Testing and Site Acceptance Testing including the testing of cyber security requirements, and that is the stage at which commercial leverage over a vendor is at its greatest.
Common Findings in Assessment
From Beacon Security's assessment work across generation, transmission and distribution environments, the shortfalls that arise most consistently against the requirements described above are the following.
- No qualified Chief Information Security Officer in post, or an officer who also carries the responsibilities of the head of information technology, against a requirement that the role be ring fenced and that the officer hold fifteen years of relevant experience.
- Information technology and operational technology interconnected without governance, where the connection exists for sound operational reasons such as a historian, a reporting feed or an enterprise integration, but the risk assessment, the approval of the head or board, the hardened logical separation and the continuous monitoring that the regulations require of such a connection have not been put in place.
- Vendor remote access granted through standing accounts, frequently with shared credentials, rather than being confined to troubleshooting and emergency requirements, risk assessed in advance, approved, continuously monitored and logged.
- Asset registers that extend only to the server estate, with controllers, remote terminal units, protection relays, engineering workstations and human machine interfaces omitted, and with the configuration, data flow and protocol detail the regulations require recorded nowhere.
- Controller logic and engineering project files outside the backup scope, so that servers are protected while the files that actually determine how quickly a process can be restored are not, and restoration is seldom tested against the business continuity plan.
- Operational technology clocks synchronised over the internet, against a requirement for a terrestrial or India specific satellite based source independent of it.
- Monitoring that ends at the corporate boundary, with the information technology network well instrumented while the operational environment produces logs that nothing collects and no one reviews.
- Patches applied to operational technology systems without verification of the manufacturer's signature or testing in a simulated environment.
- Crisis management plans that have never been exercised, against a requirement for annual testing through a non-repeating scenario catalogue and for awareness programmes and exercises every six months.
- Established engineering practice that leaves no evidence, where experienced personnel carry out the right activity without a documented procedure, a named owner or a retained record that an auditor is able to credit.
Each of these corresponds to an identifiable requirement, and each can be addressed within the compliance window through a focused and well-sequenced programme rather than a wholesale rebuild.
How Beacon Security Can Help
The greater part of this framework consists of engineering and analytical work rather than documentation, and it is there that the effort is genuinely required. Beacon Security works alongside operations, engineering and leadership teams to establish the capability that the regulations expect, rather than presenting a list of tasks to be completed.
- Through a gap assessment against the regulations, we establish your current position requirement by requirement, record the supporting evidence for each, and set out a prioritised remediation plan sequenced against the commencement date and against the provisions whose commencement has been deferred.
- Through cyber asset inventory and risk assessment, we build the cyber asset register and the critical system register to the level of configuration, data flow and protocol detail the regulations require, using passive discovery methods that are safe in a live production environment, and we produce and maintain the Cyber Risk Assessment and Mitigation Plan on the cycle the regulations specify.
- Through critical system identification, we help you define and document classification criteria that will hold up under examination, since that classification governs the scope of your audit and certification, your backup obligations and your access controls.
- Through Cyber Security Policy and procedure development, we build the complete policy framework and the subordinate procedures it is required to define, in a form that the head or the board can approve and an auditor can verify.
- Through Cyber Crisis Management Plan development, we prepare the plan for CERT-In vetting, build the scenario catalogue that will carry you through the non-repeating annual exercise cycle, and facilitate the mock drills and tabletop exercises required every six months.
- Through operational technology architecture and segmentation design, we design the trust level segmentation, the governed interconnection between the two environments, the unidirectional gateway arrangement, the perimeter capability, the separation of communication systems and the time synchronisation architecture, sequenced so that the work can be implemented within realistic maintenance windows.
- Through remote access and remote operation design, we establish the risk-assessed, approved, time-bound and recorded access model that the regulations require of vendor and support connections.
- Through vulnerability assessment and penetration testing in operational technology environments, we deliver the testing required before the commissioning of any new or replaced critical system, using passive and safe methods where production impact is a genuine concern.
- Through audit readiness and remediation support, we prepare you for the empanelled audit, design the compensating control patterns that make the one-month closure interval achievable, and support closure through to the audit closure report and the annual self-audit.
- Through vendor and supply chain security, we help entities write these requirements into procurement, acceptance testing and service level agreements, and we help vendors establish the bill of materials, hardening and coordinated disclosure capability that the regulations now require of them directly.
- Through training and capability building, we prepare the Chief Information Security Officer, the Information Security Division and the engineering, operations and contractor personnel whom the deferred training provision will bring into scope.

The Compliance Timeline
The regulations do not take effect all at once, and the dates acquire their full meaning only once the obligations sitting behind them are understood, which is the reason they appear here rather than at the beginning of this guide.
| Date | What takes effect |
|---|---|
| 07 October 2025 | The draft regulations are made available to the public on the Authority's website and objections and suggestions are invited. |
| 31 July 2026 | The regulations are notified in the Gazette of India, Extraordinary. |
| 1 April 2027 | The regulations come into force. All provisions apply from this date other than the six identified below. |
| To be notified separately | The round-the-clock Information Security Division; the ISO/IEC 27001 certificate or Technical Criteria Certificate; mandatory cyber security courses for personnel engaged in the operation and maintenance of critical systems; and trusted source procurement for information technology and for operational technology equipment and services. These commence on such dates as the Authority may specify through separate orders with the prior approval of the Central Government. |
The deferral of those six provisions should not be understood as relief, since taken together they are the most substantial obligations in the document and they depend either upon national schemes that do not yet exist, such as the Technical Criteria Certificate and the trusted source designation, or upon recruitment, certification and training programmes whose lead times are measured in quarters rather than in weeks. They will commence on dates the Authority determines rather than on dates an entity would choose, and the prudent course is to begin them on the assumption that the enabling orders are imminent rather than distant.
For every other provision, 1 April 2027 is the operative date, and it is worth being clear about what that date requires. It is not the date by which a file must be complete, but the date by which a qualified officer must be in post, a cyber asset register and risk assessment must exist and be current, a Cyber Security Policy and a Cyber Crisis Management Plan must be approved, the boundary between the information technology and operational technology environments must be governed in the manner the regulations describe, and the audit and self-audit cycles must be in operation. The period between now and that date is best understood as the time available in which to carry out that work rather than as a grace period preceding it.

Reading the Notification
This guide is a summary written to assist operators and vendors in planning, and it is not a substitute for the notification itself, so where anything set out here differs from the gazette text, the gazette text prevails. A number of matters are expressly reserved to later orders of the Authority and to directions of the sectoral response team, and those instruments will govern once they are issued.
The full gazette notification of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 is available here:
Read the full CEA (Cyber Security in Power Sector) Regulations, 2026 notification
The document is bilingual, with the Hindi text appearing first and the English text following it.
The 2021 Guidelines, the establishment of the sectoral response team and the audit practice that developed alongside them all pointed toward this notification, and what the 2026 Regulations add is the element that guidance was never able to supply, namely an obligation that names the officer accountable for it, sets the timeframes against which performance is measured, and can be enforced. For entities that have found it difficult to secure budget and attention for operational technology security, the regulations provide the mandate on which that case can now be made, and for those beginning from an early position the work is substantial but well defined and capable of being sequenced sensibly against the commencement date.
This is a general awareness guide and is not legal advice, nor a substitute for the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 or any order, direction or guideline issued under them, all of which take precedence. Beacon Security helps power sector entities and vendors across India establish and evidence compliance with these regulations. If you are scoping your programme against the 1 April 2027 date, contact us and we will help you establish where you stand and what the path from here involves.

