The Central Electricity Authority (CEA) on July 31, 2026, issued the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026.
The following has been stated:
• The Regulations establish a comprehensive framework to strengthen cybersecurity, cyber resilience, and protection of critical information infrastructure across the power sector. The Regulations apply to Responsible Entities, including generating companies, transmission licensees, distribution licensees, load despatch centres, power exchanges, renewable energy operators, and other notified entities. They require the implementation of a cybersecurity governance framework, appointment of designated cybersecurity personnel, identification and protection of critical systems, adoption of secure network architecture, access controls, asset management, encryption, vulnerability management, and supply chain security measures.
• The Regulations also provide for cybersecurity audits, continuous monitoring, incident reporting, security testing, business continuity and disaster recovery planning, employee awareness and training, maintenance of logs and records, and coordination with sectoral agencies such as CSIRT-Power.
• They further prescribe periodic compliance reviews, timely reporting of cyber incidents, and continuous improvement of cybersecurity practices to ensure the secure, reliable, and resilient operation of India's power sector.
• These regulations shall come into force with effect from April 01, 2027, except regulations 5(9), 5(24), 5(33), 5(39), 6(2) and 6(7).
[Notification No. - CEA-HY-91-19/8/2024-Cyber Security Division]