India's CEA cyber security regulations 2026: what power sector OT has to do by April 2027

Updated 15 September 2026 · 8 minute read

On 31 July 2026 the Central Electricity Authority notified the Cyber Security in Power Sector Regulations, 2026. They replace the 2021 guidelines with a binding regulation, in force from 1 April 2027 for existing and new infrastructure alike. This guide reads them for the people who run the plant. It is orientation, not legal advice: check the Gazette text before relying on a clause.

Who is covered

  • Every entity that owns, operates or manages operational technology associated with the interconnected power system, together with the IT that is physically or logically connected to it (Reg 2(1)(a)).
  • Generating companies, captive plants and energy storage owners at an installed capacity of 50 MW or more. Below that, entities are encouraged to adopt CERT-In's 15 elemental cyber defence controls.
  • All transmission licensees, distribution licensees and the national, regional and state load despatch centres, with no capacity threshold.
  • Vendors, who carry their own obligations, including a bill of materials.

The register, the classification and the risk plan

  • A cyber asset register for all cyber assets: ownership, hardware, firmware, software and patch state. For critical systems, also configuration, network architecture, data flows and protocols. Reviewed and updated at least every financial year or on commissioning of a new asset, whichever is earlier (Reg 5(25)).
  • Systems classified as critical or non-critical under a procedure in the cyber security policy (Regs 5(16), 8(4)).
  • A cyber risk assessment and mitigation plan for every asset in the register, updated at least every six months (Reg 5(26)).
  • Vulnerability assessment and penetration testing before any new or replaced critical system goes live, with details to CSIRT-Power within 30 days of commissioning (Regs 5(27), 5(28)).
  • Information to NCIIPC to identify critical information infrastructure, and an application within 60 days of identification for the asset to be notified as a protected system (Reg 5(29)).

Architecture and access

  • OT physically isolated from the internet and from IT, with OT communications separate from IT's (Regs 6(1), 6(6)).
  • The OT environment segmented into trust levels on the basis of criticality, security requirements and risk assessment (Reg 6(8)). In IEC 62443 terms, zones and conduits with target security levels.
  • Control, operation and real-time data confined to national boundaries over a dedicated channel; cross-border exchange only through a separate system and a unidirectional gateway (Reg 6(3)).
  • Remote access only for troubleshooting and emergencies, with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must be from within India, approved by the head or board, over an isolated channel (Regs 5(17), 6(4), 8(15)).

Governance, incidents and audits

  • A ring-fenced Chief Information Security Officer and an alternate at senior management level, designated for at least three years (Regs 5(1) to 5(8)).
  • A cyber security policy with the 33 components listed in Chapter VI, approved annually, and a cyber crisis management plan prepared with CSIRT-Power, vetted by CERT-In and drilled at least yearly (Regs 5(10), 5(11), 8, 9, 10).
  • Cyber security incidents reported within six hours to CSIRT-Power and CERT-In; an incident concluded as cyber sabotage of a critical system within 24 hours (Reg 7(3)(a)).
  • An audit by a CERT-In empanelled or Ministry of Power designated auditor at least once a financial year, at intervals of nine to fifteen months, not three times running by the same agency (Reg 5(22)).
  • Critical and high-risk findings closed within one month of the auditor's report, medium and low within three, with compensating controls in the meantime (Reg 13(3)).
  • Awareness sessions and tabletop exercises at least every six months (Regs 5(8), 5(18)).

Where to start before April 2027

  • Build the cyber asset register first. Everything else in the regulation refers back to it, and it takes longest.
  • Classify critical systems and design the trust levels. A zone and conduit model of the plant is the direct answer to Reg 6(8).
  • Get remote access under control: an inventory of every vendor path, and a procedure that meets the minimum-duration, least-privilege, MFA and geo-fencing tests.
  • Write the incident plan around the six-hour clock, and exercise it.
  • Schedule the first audit with the closure timelines in mind. A finding you cannot close in a month is one to fix before the auditor arrives.
Sources
  • CEA (Cyber Security in Power Sector) Regulations, 2026, Gazette of India Extraordinary, Part III, Section 4, No. 484, 31 July 2026
  • CERT-In Directions of 28 April 2022
  • Information Technology Act, 2000, ss. 70, 70A, 70B

Questions we get asked

Does the regulation require IEC 62443?
It names ISO/IEC 27001, not IEC 62443. In practice the trust-level segmentation and architecture requirements are what 62443 describes, and the Bureau of Indian Standards has adopted the series as Indian Standards, so most entities use it as the design vocabulary.
We are a 40 MW solar plant. Are we covered?
Generating companies are in scope at 50 MW or more of installed capacity. Below that you are encouraged, not required, to adopt CERT-In's 15 elemental controls. The CERT-In Directions on incident reporting and logging apply to every body corporate regardless.
Can our OEM keep supporting the plant from overseas?
Remote access is limited to troubleshooting and emergencies under a controlled procedure. Remote operation of OT must be from within India with board or head approval. Support arrangements built on standing overseas access need to be redesigned.

Want this applied to your plant?

Tell us the site, the systems and the regulator. A consultant will reply, not a sales queue.