started · updated
Central Electricity Authority notifies power sector cyber security regulations
The Central Electricity Authority (CEA) has notified the CEA (Cyber Security in Power Sector) Regulations, 2026, aimed at strengthening the security and maintenance of electrical plants and lines. Set to take effect on April 1, 2027, the regulations target entities managing operational technology (OT) infrastructure linked to interconnected power systems and connected information technology (IT) systems.
The rules apply to generating companies, captive generating plants, and energy storage entities with installations of 50 MW or higher, as well as power exchanges and over-the-counter platforms. A key component is the establishment of the Computer Security Incident Response Team – Power (CSIRT-Power), which will serve as the nodal agency for incident analysis, alerts, audits, and supply-chain security.
Under the new framework, entities must appoint a Chief Information Security Officer (CISO) and an alternate CISO, maintain crisis management plans, and conduct regular risk assessments. Reporting requirements are strict: cyber security incidents must generally be reported within six hours, while cyber sabotage involving critical systems must be reported within 24 hours. Additionally, OT systems are required to be physically isolated from IT systems and the internet.
Entities
Central Electricity Authority · Computer Security Incident Response Team – Power