CEA Notifies Cyber Security Rules for Power Sector

CEA Notifies Cyber Security Rules for Power Sector

The Central Electricity Authority (CEA) notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 under the Electricity Act of 2003. The regulations create mandatory cybersecurity standards for the Indian power sector and set 1 April 2027 as the general effective date.

Regulatory Framework for Power Sector Cybersecurity

The regulations apply to generating companies, captive generating plants, and energy storage system entities with an installed capacity of 50 MW or more. They also cover power exchanges and over-the-counter platforms used for electricity trading.

The framework replaces voluntary advisory compliance with a statutory system for cybersecurity governance in the power sector. It covers cyber audits, incident reporting, exercises, and response protocols for grid-linked entities.

Role of CSIRT-Power and CERT-In

The regulations designate Computer Security Incident Response Team – Power (CSIRT-Power) as the nodal agency for cybersecurity coordination in the power sector. CSIRT-Power was created in April 2023 and handles audits, exercises, and incident response for sectoral entities.

Power sector entities must report general cybersecurity incidents to both CSIRT-Power and the Indian Computer Emergency Response Team (CERT-In) within six hours of detection. Incidents classified as cyber sabotage of critical systems must be reported within 24 hours.

Operational Technology, Data Residency, and Grid Security

The regulations require strict logical or physical segregation of Operational Technology (OT) systems from Information Technology (IT) systems and the internet. OT systems control industrial processes, while IT systems handle data processing, communication, and business functions.

The rules also require sensitive operational and historical data to be stored in encrypted and secure environments located entirely within India. The same requirement applies to third-party cloud service providers handling such data for power sector entities.

Important Facts for Exams

  • The Electricity Act, 2003 is the parent law under which the CEA issued the cyber security regulations.
  • CSIRT-Power was created in April 2023 as a sector-specific incident response body.
  • CERT-In is India’s national nodal agency for cyber incident response under the Information Technology Act, 2000.
  • Operational Technology refers to systems used to monitor and control physical infrastructure such as power grids.

Cyber Threat Context in the Power Sector

Power sector entities reportedly thwarted about 200,000 cyberattack attempts during Operation Sindoor. The regulations place cybersecurity obligations on grid-linked entities that operate critical infrastructure and digital trading platforms.

Leave a Reply

Your email address will not be published. Required fields are marked *