The Central Electricity Authority (CEA) has notified the CEA (Cyber Security in Power Sector) Regulations, 2026 to strengthen cyber security and ensure safe and secure operation and maintenance of electrical plants and lines. The regulations will come into force from April 1, 2027. The regulations cover entities managing operational technology (OT) infrastructure linked to the interconnected power system and connected information technology (IT) systems. For generating companies, captive generating plants and entities with energy storage systems, they apply to installations of 50 MW and above. Power exchanges and over-the-counter platforms are also covered under specified provisions.
The regulations establish Computer Security Incident Response Team – Power (CSIRT-Power) as the coordinating and nodal agency for power sector cyber security. Its functions include incident analysis, alerts and advisories, cyber security assessments, audits, exercises, capacity building and supply-chain security. Further, entities must appoint a Chief Information Security Officer (CISO) and alternate CISO, maintain cyber security policies and crisis management plans, conduct regular audits and risk assessments, and implement data protection measures. Cyber security incidents must generally be reported within six hours, while cyber sabotage incidents involving critical systems must be reported within 24 hours. OT systems must generally be physically isolated from IT systems and the internet. The regulations also prescribe cyber security requirements for vendors.
