← Back to Reglance
Energy & Infrastructure

Central Electricity Authority Issues Cyber Security Regulations for India's Power Sector

2026-07-31 · Central Electricity Authority
The Central Electricity Authority has notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 under section 177 read with clause (c) of section 73 of the Electricity Act, 2003 (36 of 2003), effective from 1st April 2027. These regulations apply to all entities owning, operating, or managing Operational Technology infrastructure connected to the interconnected power system and their associated Information Technology infrastructure, including generating companies, captive generating plants, organisations with Energy Storage System having installed capacity of 50 MW or more, transmission licensees, distribution licensees, load dispatch centres, power exchanges, and over the counter platforms. The regulations establish Computer Security Incident Response Team – Power under the Ministry of Power as the coordinating agency for cyber security incidents in the power sector, working as an extended arm of the Indian Computer Emergency Response Team. Entities must designate a Chief Information Security Officer at senior management level, establish a dedicated Information Security Division operational round the clock, implement comprehensive Cyber Security Policy and Cyber Crisis Management Plan, maintain asset registers for all cyber assets and critical systems, conduct annual cyber security audits of all critical systems, and achieve ISO/IEC 27001 certification or Technical Criteria Certificate. Specific additional requirements are prescribed for entities with Operational Technology systems, including physical isolation of such systems from internet and Information Technology systems, with permissible interconnections only through secure channels with appropriate risk assessment and approval. All entities must report cyber security incidents within six hours to Computer Security Incident Response Team – Power and Indian Computer Emergency Response Team, with incidents classified as cyber sabotage in critical systems to be reported within twenty-four hours. Vendors supplying equipment and services to the power sector must provide Bill of materials, digitally signed security patches and updates throughout contract period or useful life of systems, and comply with orders issued by the Central Government regarding procurement from trusted sources.

Stay current with Indian legal developments

Explore All Updates →