Compliance

The CEA Cyber Security in Power Sector Regulations, 2026: Why They Matter and What Each Chapter Requires

August 6, 20269 min readBy Beacon Security Team

The Central Electricity Authority notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 in the Gazette of India, Extraordinary, on 31 July 2026, and they come into force on 1 April 2027.

The notification states its purpose in its own words, which is to make regulations relating to cyber security in the power sector for ensuring the safe and secure operation and maintenance of electrical plants and electrical lines. What follows is a short walk through its ten chapters, keeping to what each one actually asks an entity or a vendor to do.

CEA Cyber Security in Power Sector Regulations 2026: India's binding cyber security law for the power grid

Why This Regulation Carries So Much Weight

  • Accountability is personal and named. A specific individual must be designated, must meet stated qualifications, must hold the role for a minimum period, must do cyber security work and nothing else, and must have their contact details published.
  • The obligations run on fixed timeframes. Six hours to report an incident, twenty-four hours where it is concluded to be cyber sabotage in critical systems, six weeks for the audit report, and one month to close a critical or high-risk finding.
  • The architecture requirements reach into the plant. Isolation from the internet and from information technology, trust level segmentation, unidirectional gateways and a time source off the public internet all need design work, procurement and outage windows.
  • They apply to what is already installed. The regulations cover the existing as well as the upcoming infrastructure of an entity, so age and an uneventful service history are not an answer.
  • The supply chain is inside the regulation. Vendors carry obligations in their own right, reaching manufacturers, integrators, contractors, cloud service providers and the makers of equipment behind consumer-owned distributed generation.
  • What an entity reports can be independently checked. The Ministry's officer may examine a compliance report or audit closure report and appoint a third-party auditor to verify it, at the entity's cost.

Chapter I: Who Has to Comply

The regulations apply to every entity that owns, operates or manages operational technology infrastructure associated with the interconnected power system, together with the information technology infrastructure physically or logically connected to it.

  • Generating companies, captive plants and energy storage operators are covered at 50 MW installed capacity and above, and those below that threshold are encouraged rather than required to adopt the baseline controls CERT-In has published for smaller enterprises.
  • Transmission and distribution licensees, and the National, Regional and State Load Dispatch Centres are covered with no capacity threshold.
  • Power exchanges and over the counter platforms are covered by everything except the operational technology chapter and the vendor provisions.
  • Vendors must comply directly, and the definition reaches original equipment manufacturers, system integrators, contractors, service providers including cloud providers, and the makers of inverters, communication modules and monitoring systems behind prosumer-owned distributed generation.

Scope of the CEA Cyber Security Regulations 2026: entities, the 50 MW threshold, exchanges and platforms, and vendors

Chapter II: CSIRT-Power

The chapter establishes the Computer Security Incident Response Team, Power as the body through which the sector coordinates its response to cyber incidents.

  • It is the coordinating agency for incident reporting and response, and the nodal agency for analysis, prediction and prevention.
  • It may collect incident-related data from an entity, including network architecture, asset details, logs and forensic records, in the form and manner it specifies.
  • Its directions and guidelines are binding on entities and vendors alike, and the Authority may designate further response teams for generation, transmission, distribution and grid operation.

The notification is therefore a foundation rather than the finished picture, because further binding detail will arrive later as directions from this team and as separate orders of the Authority.

Chapter III: The General Requirements

The longest chapter applies to every entity in scope. The requirements that matter most fall into four groups.

Documents that must exist and be approved annually

  • A Cyber Security Policy, approved and reviewed by the head or the board.
  • A Cyber Crisis Management Plan, prepared with CSIRT-Power and vetted by CERT-In.
  • An Incident Response and Recovery Plan, reviewed at least every six months.

Knowing the estate

  • A cyber asset register covering every cyber asset, and a separate record of every critical system with its configuration and network architecture showing data flows and communication protocols.
  • Identification and segregation of systems as critical and non-critical, against criteria the entity defines itself.
  • A Cyber Risk Assessment and Mitigation Plan for every asset in the register, updated at least every six months.

Boundary, access and data

  • Security devices at the Electronic Security Perimeter, with logging enabled and rules reviewed annually.
  • Remote access confined to troubleshooting and emergency requirements, and for critical systems only after a comprehensive risk assessment, with continuous monitoring and retained records.
  • Sensitive information and data, including anything on cloud platforms and all historical data, stored encrypted and resident within India only.
  • Online and offline backups of all critical systems held in a separate, safe and secure environment.

Assurance and procurement

  • A comprehensive cyber security audit of all critical systems every financial year.
  • Vulnerability assessment and penetration testing before any new or replacement critical system is commissioned, with its details furnished to CSIRT-Power within thirty days.
  • Cyber security requirements built into Factory Acceptance Testing, Site Acceptance Testing and vendor service level agreements.
  • Continuous monitoring of information technology and operational technology systems, and a register recording every cyber security incident.

Chapter IV: The Operational Technology Requirements

This chapter sits on top of the previous one and is where the engineering work is defined.

  • Isolation is the default. Operational technology must be physically isolated from the internet and from the information technology system. Where that is not possible for business reasons, an interconnection requires a risk assessment, approval of the head or the board, hardened logical separation, continuous monitoring, and data crossing through a unidirectional gateway.
  • Trust levels. The operational technology environment must be segmented on the basis of criticality, security requirements and risk assessment.
  • A dedicated perimeter. Perimeter devices are required where operational technology meets the communication system of the power system, capable of detecting and filtering operational technology protocols, with their updates carried out offline.
  • Traffic stays in India. Control and operation of power system elements, and the exchange of real-time data, must run over a dedicated channel isolated from the internet and confined to national boundaries, with cross-border exchange only through a separate dedicated system and a unidirectional gateway.
  • Remote operation is constrained. Where the business requires it, remote operation must be carried out from within India with prior approval of the head or the board, over a dedicated isolated channel.
  • Communication systems must be separate. The operational technology communication system must be isolated from the information technology one, which is distinct from network separation and affects anyone carrying both over shared transmission infrastructure.

Chapter V: The Security Officer and the Division

The provisions most entities will find hardest to satisfy concern people rather than technology.

  • The Chief Information Security Officer and the Alternate must be citizens as well as residents of India, hold a degree in engineering or its equivalent, and have at least fifteen years of experience in the power sector or in information technology.
  • Both must be regular employees at senior management level, the officer is designated for a minimum of three years, the two posts may not be vacant at the same time, and the officer reports to the head of the entity.
  • The role must be ring fenced to cyber security matters only, so the designation cannot simply be added to the responsibilities of the head of information technology.
  • A dedicated Information Security Division must be established within India, headed by the officer, operational round the clock, with certified staff posted for a minimum tenure of three years.
  • Incidents are reported to CSIRT-Power and CERT-In within six hours, and within twenty-four hours where concluded to be cyber sabotage in critical systems.

Since an individual with fifteen years of relevant experience cannot be recruited quickly, and a certified division operating round the clock cannot be assembled at short notice, this chapter carries the longest lead time in the regulations.

The CISO and Information Security Division requirements under the CEA Regulations 2026

Chapter VI: The Cyber Security Policy

This chapter matters more than its length suggests, because a great many requirements elsewhere direct that work be carried out in accordance with a procedure defined in the Cyber Security Policy. Until those procedures exist, the requirements pointing at them have nothing to stand on. Among the procedures the policy must define are the following.

  • Preparing the cyber asset register, and identifying and classifying critical systems.
  • Cyber risk assessment and mitigation, and the management of vulnerabilities in critical systems.
  • Access control on the principles of authentication, authorisation and accounting, and personnel risk assessment covering vendor staff and departing employees.
  • Remote access and remote operation, and cyber supply chain risk management.
  • Change management, including the criteria that classify a software update as requiring a prior cyber security audit.
  • Backup, requiring data no older than a month with integrity and restoration tested against the business continuity plan.
  • Selection of a reference time source, which for operational technology must be terrestrial or India specific satellite based and independent of the internet.
  • Logical separation of operational technology from information technology, and data retention setting how long records are kept.

Chapter VII: The Cyber Crisis Management Plan

  • The plan must contain a procedure for detecting and identifying incidents, the criteria classifying an incident as a crisis, and a list of all possible crisis scenarios, together with stakeholder responsibilities and the manner of communication during one.
  • Its efficacy must be tested at least once a year through exercises and mock drills, and the scenarios chosen in any year may not repeat those already tested until the full catalogue has been worked through.
  • After an actual crisis the entity must report on the experience gained and the lapses observed, share the relevant information with CSIRT-Power, and update the plan accordingly.

Chapter VIII: What Vendors Must Do

Short, and the chapter vendors serving this sector are least likely to have read, since it binds them directly rather than through the purchasing entity.

  • Provide documented and tested restoration procedures and a recovery plan for the systems supplied.
  • Keep security patches and updates, digitally signed or validated and authenticated, available for the contract period or the useful life of the system, whichever is later.
  • Disclose end of support and end of life dates, including for anything sourced from third parties.
  • Provide a bill of materials per CERT-In guidelines, listing all components supplied for applications including firmware in critical systems.
  • Harden hardware and software before supply, with inherent security capabilities enabled and secure configuration applied.
  • Operate a formal process for entities to report vulnerabilities, and furnish those vulnerabilities to CSIRT-Power.

A separate provision covers prosumer-owned distributed generation, requiring the vendor to keep the application, control servers and real-time data encrypted and resident exclusively within India, with remote access established over a secure channel after mutual authentication.

Chapter IX: The Cyber Security Audit

The audit is conducted by an auditor empanelled with CERT-In, or another auditor designated by the Ministry of Power, and its scope must include verifying that the previous audit's findings have been closed. No three consecutive audits may be carried out by the same agency or personnel.

StageTimeframe
Interval between two consecutive auditsNot less than nine months and not more than fifteen months
The auditor submits the audit reportWithin six weeks of the audit commencing
Critical and high-risk vulnerabilities addressedWithin one month of the report being submitted
Medium and low-risk vulnerabilities addressedWithin three months of the report being submitted
The auditor submits the audit closure reportWithin six months of the audit commencing

Until a critical or high-risk vulnerability receives audit clearance, appropriate compensatory controls must be deployed to contain it, and that provision is what makes the one-month timeframe workable where a permanent fix has to wait for a planned outage.

Chapter X: Miscellaneous

  • The entity must conduct a self-audit every financial year, and address any non-compliance before the self-audit scheduled for the following year.
  • The Chief Information Security Officer of the Ministry of Power may examine an entity's compliance or audit closure report and appoint a third-party auditor to verify it, at the entity's cost, and may recommend proceedings under the Information Technology Act, 2000 or a petition before the Appropriate Commission.
  • The Authority may relax any provision, for reasons recorded in writing, to remove hardship arising from its operation for a class of persons.

The two Schedules complete the document, and both are short. The First lists the records the security officer must hold in custody, from the policy and the crisis plan through to the asset register, the bill of materials and the remote access procedures. The Second sets out when a software update requires a cyber security audit before deployment, covering changes affecting core operational processes, authentication and privileges, third-party integration, encryption and protocols, new interfaces, previously identified critical vulnerabilities, and monitoring and incident response tooling.

The Dates

DateWhat happens
07 October 2025The draft regulations are made available to the public on the Authority's website, and objections and suggestions are invited.
31 July 2026The regulations are notified in the Gazette of India, Extraordinary.
1 April 2027The regulations come into force, other than the six provisions below.
To be notified separatelyThe round-the-clock Information Security Division; the ISO/IEC 27001 certificate or Technical Criteria Certificate; mandatory cyber security courses for personnel operating and maintaining critical systems; and trusted source procurement for information technology and for operational technology equipment and services.

The six deferred provisions depend either on schemes yet to be established or on recruitment, certification and training that take time to complete, so beginning them on the assumption that the enabling orders are close is the safer course.

Timeline of the CEA Cyber Security in Power Sector Regulations 2026: notified 31 July 2026, in force 1 April 2027

How Beacon Security Can Help You Meet These Regulations

Beacon Security is a specialist consultancy in operational technology and industrial control system cyber security, working with asset owners and equipment suppliers across the power, oil and gas, chemicals, manufacturing and automotive sectors in South Asia, the Middle East and Europe.

One point is worth making clearly at the outset. We do not simply advise you on what these regulations require and leave the delivery to you. Our teams build the cyber asset register, write the Cyber Security Policy and its procedures, prepare the Cyber Crisis Management Plan, design the segmentation and the governed interconnection, carry out the testing before commissioning, and sit alongside your people through the audit and its closure.

What the regulations require of youWhat we build with you
A cyber asset register and a record of every critical system with its configuration, data flows and protocolsThe complete register, compiled in live plant using non-intrusive discovery, at the level of detail an auditor will look for
Identification and classification of critical systems against criteria you define yourselfDocumented classification criteria that will withstand examination, applied across your estate
A Cyber Security Policy defining every procedure the other chapters point back toThe full policy framework and each subordinate procedure, in a form the board can approve and an auditor can verify
A Cyber Crisis Management Plan, with annual exercises that cannot repeat scenariosThe plan prepared for vetting, the scenario catalogue, and the mock drills and tabletop exercises facilitated
Isolation, trust levels, unidirectional gateways and the perimeterSegmentation and boundary design phased around your outage planning, with support through implementation
Remote access confined, approved, monitored and recordedAn access model to replace the standing accounts most environments have accumulated
Testing before a critical system is commissionedVulnerability assessment and penetration testing in live industrial environments
An annual audit and self-audit, with findings closed to timeAudit preparation, compensating control positions agreed in advance, and remediation support
Obligations placed on vendorsRequirements written into procurement and contracts, and capability built for vendors who now carry duties of their own

How we work

  • We assess without disturbing the process. Where production continuity is at stake we use passive and non-intrusive techniques, and every activity is judged first by its effect on the plant.
  • We design around the access you will actually get. Sequencing is agreed against your outage calendar before any drawing is issued.
  • We build from the plant as it stands. Registers and architectures that do not match how a plant genuinely runs are the ones that come apart under audit.
  • We leave the capability behind. The people who will sustain this framework are the same people keeping the plant running.

There is time, provided you start with a clear picture

The size of this notification can make the obligation look heavier than it is. The requirements are finite, they are already published, and they can be arranged into a programme with a defined beginning and a defined end. What we consistently find is that organisations are further ahead than they expected in some areas and further behind in others, and the difficulty is rarely the volume of work but knowing which is which while there is still time to act. You will not be working through this on your own.

If you would like an informed view of where you stand, use the Book a Free 15-Minute 1:1 Call button on this page. It is with a senior consultant rather than a sales team, at no cost and with no obligation, and you will come away with a clearer understanding of your own position regardless of what you decide.

Beacon Security working alongside utility engineering and operations teams to build CEA 2026 compliance

Reading the Notification

This guide summarises the regulations to help entities and vendors plan, and where anything here differs from the gazette text the gazette text prevails, particularly since several matters are reserved to later orders of the Authority and to directions of CSIRT-Power.

Read the full CEA (Cyber Security in Power Sector) Regulations, 2026 notification

The document is bilingual, with the Hindi text appearing first and the English text following it.

This is a general awareness guide and is not legal advice, nor a substitute for the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 or any order, direction or guideline issued under them, all of which take precedence. Beacon Security helps power sector entities and vendors across India establish and evidence compliance with these regulations.

Industrial infrastructure
OT Cybersecurity Experts

Your OT Environment Deserves
Expert Protection

IT security tools were not built for Modbus, OPC, or safety-rated controllers. Get a dedicated OT cybersecurity team that understands industrial protocols, control system architecture, and the operational constraints of your environment.

IEC/ISA 62443 Aligned
NIST 800-82 Compliant
OTCC Ready
ECC Aligned
Zero Operational Disruption