CEA Cyber Security Regulations 2026: Compliance Guide

The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 create an auditable cyber security framework for India’s power ecosystem. Most provisions take effect on 1 April 2027 and cover governance, critical IT and operational technology, incident reporting, data residency, vendor security, audits and evidence retention. Six provisions will commence later through separate CEA orders. Covered organisations should begin with applicability, asset classification, gap assessment and accountable remediation rather than treating compliance as a policy exercise.

Who must comply with the CEA Cyber Security Regulations 2026?

The regulations apply to entities that own, operate or manage OT infrastructure connected with the interconnected power system, together with IT infrastructure physically or logically connected to it. Generating companies, captive plants and organisations operating energy storage systems are covered where installed capacity is 50 MW or more. Power exchanges and over-the-counter platforms are covered with stated exceptions, while vendors must meet Regulations 11 and 12 where applicable. Entities below 50 MW are encouraged to adopt CERT-In’s 15 Elemental Cyber Defense Controls.

What are the main compliance requirements?

Covered entities must appoint a senior-management CISO and Alternate CISO, define reporting lines and maintain board-approved cyber security governance. They must identify cyber assets, classify critical IT and OT systems, document network architecture and maintain a Cyber Risk Assessment and Mitigation Plan.  The technical focus is equally clear. OT systems should be physically isolated from the internet and IT networks. Where an IT-OT connection is necessary, hardened logical separation, documented risk assessment, formal approval, continuous monitoring and retained logs are required. Remote access to critical systems must be limited, approved and protected through measures including least privilege, multi-factor authentication and geo-fencing.

Sensitive information, including cloud-hosted and historical data, must remain encrypted, protected and resident in India. Critical-system backups must be current, separately maintained and restoration-tested. Entities must also establish incident response, cyber crisis management, supply-chain security, vulnerability management and evidence-retention processes.

What deadlines should organisations track?

  • Cyber security incidents: report to CSIRT-Power and CERT-In within six hours.
  • Cyber sabotage affecting critical systems: report within 24 hours once concluded as sabotage.
  • New or replaced critical systems: provide required details to CSIRT-Power within 30 days.
  • Critical Information Infrastructure: approach the Appropriate Government within 60 days of identification.
  • Audit findings: address critical and high risks within one month medium and low risks within three months.

A comprehensive cyber security audit is required every financial year, with a nine-to-fifteen-month gap between consecutive audits. The auditor must issue the report within six weeks of commencement, and the closure report is due within six months. A separate self-audit is also required annually.

A practical readiness roadmap

Start by documenting applicability across legal entities, facilities, OT environments, connected IT systems and vendors. Build a clause-by-clause register linking every requirement to a control owner, implementation status and evidence source. Review network separation, remote access, logging, monitoring, time synchronisation, backups, data residency and vendor contracts.  Next, test operational readiness. Run incident-response and cyber-crisis exercises, validate the six-hour escalation path, test backup restoration and sample evidence retrieval. Establish an audit calendar that tracks assessment, remediation and closure deadlines. Boards should receive regular reporting on readiness, exceptions, residual risk and future CEA or CSIRT-Power directions.

Frequently asked questions

  1. When do the regulations take effect?
    Most provisions take effect on 1 April 2027. Regulations 5(9), 5(24), 5(33), 5(39), 6(2) and 6(7) will commence on dates notified separately.
  2. Is ISO/IEC 27001 certification mandatory?
    Regulation 5(24) requires ISO/IEC 27001 or a Technical Criteria Certificate covering critical systems, but its commencement depends on a separate CEA order.
  3. What should organisations do first?
    Complete an applicability assessment, confirm CISO accountability, inventory critical systems, assess gaps and create a clearly evidence-led implementation plan.

Prepare before the compliance clock starts

The CEA Cyber Security Regulations 2026 require coordinated action across leadership, IT, OT, engineering, procurement, legal, business continuity, internal audit and vendors. QRC Assurance & Solutions supports power-sector entities through regulatory readiness assessments, IT-OT security reviews, VAPT, CERT-In empanelled cyber security audits, evidence validation and remediation tracking. To discuss your readiness programme, contact connect@qrcsolutionz.com or visit qrcsolutionz.com.

Read the full article here :  Central Electricity Authority - Cyber Security Regulations notification

Disclaimer: This article is an executive interpretation for awareness and planning and is not legal advice. The notified Gazette and subsequent competent-authority directions prevail.

LinkedIn Youtube

We use cookies to enhance your user experience. By continuing to browse, you hereby agree to the use of cookies. Know more Privacy Policy & Cookies Policy.

X