Who is covered
- Every entity that owns, operates or manages operational technology associated with the interconnected power system, together with the IT that is physically or logically connected to it (Reg 2(1)(a)).
- Generating companies, captive plants and energy storage owners at an installed capacity of 50 MW or more. Below that, entities are encouraged to adopt CERT-In's 15 elemental cyber defence controls.
- All transmission licensees, distribution licensees and the national, regional and state load despatch centres, with no capacity threshold.
- Vendors, who carry their own obligations, including a bill of materials.
The register, the classification and the risk plan
- A cyber asset register for all cyber assets: ownership, hardware, firmware, software and patch state. For critical systems, also configuration, network architecture, data flows and protocols. Reviewed and updated at least every financial year or on commissioning of a new asset, whichever is earlier (Reg 5(25)).
- Systems classified as critical or non-critical under a procedure in the cyber security policy (Regs 5(16), 8(4)).
- A cyber risk assessment and mitigation plan for every asset in the register, updated at least every six months (Reg 5(26)).
- Vulnerability assessment and penetration testing before any new or replaced critical system goes live, with details to CSIRT-Power within 30 days of commissioning (Regs 5(27), 5(28)).
- Information to NCIIPC to identify critical information infrastructure, and an application within 60 days of identification for the asset to be notified as a protected system (Reg 5(29)).
Architecture and access
- OT physically isolated from the internet and from IT, with OT communications separate from IT's (Regs 6(1), 6(6)).
- The OT environment segmented into trust levels on the basis of criticality, security requirements and risk assessment (Reg 6(8)). In IEC 62443 terms, zones and conduits with target security levels.
- Control, operation and real-time data confined to national boundaries over a dedicated channel; cross-border exchange only through a separate system and a unidirectional gateway (Reg 6(3)).
- Remote access only for troubleshooting and emergencies, with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must be from within India, approved by the head or board, over an isolated channel (Regs 5(17), 6(4), 8(15)).
Governance, incidents and audits
- A ring-fenced Chief Information Security Officer and an alternate at senior management level, designated for at least three years (Regs 5(1) to 5(8)).
- A cyber security policy with the 33 components listed in Chapter VI, approved annually, and a cyber crisis management plan prepared with CSIRT-Power, vetted by CERT-In and drilled at least yearly (Regs 5(10), 5(11), 8, 9, 10).
- Cyber security incidents reported within six hours to CSIRT-Power and CERT-In; an incident concluded as cyber sabotage of a critical system within 24 hours (Reg 7(3)(a)).
- An audit by a CERT-In empanelled or Ministry of Power designated auditor at least once a financial year, at intervals of nine to fifteen months, not three times running by the same agency (Reg 5(22)).
- Critical and high-risk findings closed within one month of the auditor's report, medium and low within three, with compensating controls in the meantime (Reg 13(3)).
- Awareness sessions and tabletop exercises at least every six months (Regs 5(8), 5(18)).
Where to start before April 2027
- Build the cyber asset register first. Everything else in the regulation refers back to it, and it takes longest.
- Classify critical systems and design the trust levels. A zone and conduit model of the plant is the direct answer to Reg 6(8).
- Get remote access under control: an inventory of every vendor path, and a procedure that meets the minimum-duration, least-privilege, MFA and geo-fencing tests.
- Write the incident plan around the six-hour clock, and exercise it.
- Schedule the first audit with the closure timelines in mind. A finding you cannot close in a month is one to fix before the auditor arrives.
Sources
- CEA (Cyber Security in Power Sector) Regulations, 2026, Gazette of India Extraordinary, Part III, Section 4, No. 484, 31 July 2026
- CERT-In Directions of 28 April 2022
- Information Technology Act, 2000, ss. 70, 70A, 70B





