The Central Electricity Authority has notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 under the Electricity Act, 2003, replacing voluntary advisories with binding statutory obligations.
The regulations come into force from 1 April 2027 and cover generating companies, captive generating plants and energy storage entities of 50 MW and above, as well as power exchanges and over-the-counter electricity trading platforms.
CSIRT-Power is designated the nodal agency for cyber security coordination in the power sector, working alongside CERT-In, the national incident response agency.
General cyber incidents must be reported within six hours of detection; incidents amounting to cyber sabotage of critical systems must be reported within 24 hours.
Operational Technology systems must be segregated from IT networks and the internet, and sensitive operational and historical data must be stored encrypted within India, including by third-party cloud providers.
IT systems handle data, email, billing and business processes. OT systems are the hardware and software that directly monitor and control physical equipment — the relays, breakers, turbines and SCADA consoles that keep a grid synchronised. The regulations require OT to be logically or physically segregated from IT networks and from the internet, because an attacker who enters through an ordinary office network must not be able to walk sideways into equipment that can trip a grid. Most catastrophic power-sector attacks worldwide have followed exactly that IT-to-OT path.
Simple Analogy: It is the difference between someone stealing the letters in a power station's post room and someone reaching the switch that turns off a city.
Statutory body under the Electricity Act, 2003 that advises the government on electricity policy and frames technical standards for the power system; it has issued these cyber security regulations.
Sector-specific Computer Security Incident Response Team for power, designated the nodal agency for cyber security coordination, audits, drills and incident response for grid-linked entities.
India's national nodal agency for computer security incident response, operating under the Information Technology Act, 2000 and the Ministry of Electronics and Information Technology.
GS Paper 3 > Internal Security > Challenges to internal security through communication networks; critical infrastructure protection
General Awareness > Current affairs, government bodies and acts
General Awareness > Regulatory and cyber security developments
General Awareness > Institutions and current events
Systems that monitor and control physical industrial processes such as generation, transmission and distribution equipment.
The power sector's dedicated computer security incident response team, designated nodal agency for cyber security coordination in the sector.
A requirement that specified categories of data be stored on servers physically located within the country.