The Indian government has taken a significant step towards fortifying the country's power sector against cyber threats with the introduction of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026. This comprehensive regulatory framework, published in the Gazette of India on July 31, 2026, marks a pivotal moment in India's cybersecurity strategy, particularly for the power industry. The regulations are a testament to the government's proactive approach to safeguarding critical infrastructure from the ever-evolving landscape of cyber threats.
A Holistic Approach to Cybersecurity
The regulations apply to a wide range of entities within the power sector, including generating companies, captive power plants, and Energy Storage Systems (ESS) with a capacity of 50 MW or more. Smaller entities are encouraged to adopt basic cybersecurity measures recommended by the Computer Emergency Response Team (CERT-In) for micro, small, and medium enterprises. This inclusive approach ensures that even smaller players in the sector are not left vulnerable to cyber threats.
One of the key innovations of these regulations is the establishment of the Computer Security Incident Response Team – Power (CSIRT-Power). This central agency will play a pivotal role in coordinating and managing cyber security incidents in the electricity sector. By monitoring threats, issuing alerts, and developing standard operating procedures, CSIRT-Power will act as a critical line of defense against potential cyber attacks.
Strengthening Leadership and Infrastructure
The regulations mandate that covered organizations appoint a Chief Information Security Officer (CISO) with a minimum tenure of three years, along with an alternate CISO. This move ensures a dedicated and experienced leadership team focused on cybersecurity. Additionally, organizations must establish a 24-hour Information Security Division, staffed with trained cyber security professionals, to ensure round-the-clock protection against cyber threats.
Policy and Audit Mandates
Organizations are required to maintain a Cyber Security Policy, Cyber Crisis Management Plan, and an updated Asset Register. These policies must be reviewed annually, ensuring that cybersecurity strategies remain current and effective. Annual cyber security audits are also mandatory, with a restriction that the same audit agency cannot conduct audits for more than two consecutive years. This ensures a fresh perspective and thorough evaluation of cybersecurity measures.
Protecting Operational Technology (OT) Systems
A significant focus of the regulations is the protection of OT systems that control critical power infrastructure. To achieve this, OT networks must be physically separated from the internet and conventional IT networks. Real-time operational data must be transferred through dedicated and secure communication channels, with critical data restricted to systems located within India. This ensures that sensitive information remains within the country's borders, enhancing data security and sovereignty.
Remote Access and Data Security
Remote access to critical assets is permitted only for emergency troubleshooting and must use multi-factor authentication, continuous monitoring, and detailed logging. This stringent approach ensures that even remote access is secure and monitored. Additionally, sensitive information and backups must be encrypted and stored within India, further enhancing data security and privacy.
Vendor Accountability and Cloud Security
Vendors supplying hardware, software, and cloud services are also subject to strict regulations. They must provide tested recovery plans, digitally signed software patches, and a comprehensive Bill of Materials. Procurement must comply with government requirements for trusted sources, ensuring that only reputable vendors are involved in the supply chain. For distributed generation prosumers using cloud platforms, real-time operational data must be hosted within India and transferred through secure, encrypted communication channels.
Incident Reporting and Response
The regulations introduce strict incident reporting requirements. Cyber incidents must be reported to CSIRT-Power within six hours of detection. This rapid response mechanism is crucial in containing and mitigating the impact of cyber attacks. Through mandatory audits, stronger institutional responsibilities, network segregation, data localization, and vendor accountability, the CEA aims to create a more resilient cyber security environment and protect India’s increasingly digital and interconnected electricity infrastructure.
In conclusion, the Central Electricity Authority's regulations represent a significant step towards securing India's power sector against cyber threats. By implementing a comprehensive and inclusive approach, the government is not only protecting critical infrastructure but also ensuring that the power sector remains a reliable and secure source of energy for the country's citizens. As the world becomes increasingly digital, such proactive measures are essential to safeguarding the future of India's energy security.