CEA Introduces New Cybersecurity Rules to Protect India’s Power Sector
New Delhi: The Central Electricity Authority (CEA) has introduced new cybersecurity regulations. The rules aim to strengthen protection for India’s power infrastructure against growing cyber threats. The rules require power sector organisations to securely store sensitive information, including historical records and data managed through cloud platforms. Such information must be kept in encrypted and protected environments. The same requirements will apply to vendors and cloud service providers handling the data.
The CEA (Cyber Security in Power Sector) Regulations, 2026 will come into effect from April 1, 2027. The framework covers organisations that operate or manage operational technology (OT) connected to the interconnected power system, along with related IT infrastructure. Generating companies, captive power plants and energy storage facilities with capacity of 50 MW or more will also fall under the regulations.
The move comes as India’s electricity infrastructure becomes increasingly dependent on interconnected digital systems. A successful cyberattack on critical systems could affect power generation, transmission or distribution. According to a power ministry official, the sector faced nearly two lakh cyberattack attempts during Operation Sindoor, although the attempts were reportedly prevented and the national power system continued operating.
Under the new framework, organisations must report cybersecurity incidents to CSIRT-Power and CERT-In within six hours. Incidents involving cyber sabotage of critical systems must be reported within 24 hours. Power companies must also keep IT and OT networks separated and use trusted sources for OT equipment and services.
New critical systems will require cybersecurity audits, including vulnerability assessments and penetration testing, before commissioning. Companies must appoint a CISO, maintain round-the-clock information security functions, conduct regular risk assessments and audits, train personnel, and carry out periodic cybersecurity exercises.
English 



































































