Refer to the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 here: [ PDF ]
We missed this earlier: The Central Electricity Authority (CEA) notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, on July 31, 2026. However, these rules will come into effect only on April 1, 2027. Here are the key provisions from the Rules:
The Computer Security Incident Response Team for the Power Sector (CSIRT-Power) will coordinate cybersecurity incident reporting and response in the power sector. This new body comes under the Ministry of Power. It is established to coordinate cyber incident reporting and response for the power sector, issue alerts and advisories, and set sub-sector cybersecurity benchmarks. The team can also request network architecture details, asset information, logs, and forensic records from entities. If this agency issues directives, these are mandatory for all entities and vendors as they have a legally binding status.
The primary duties of this new coordinating agency are:
- Vulnerability analysis: Collect and analyze cyber incidents, vulnerabilities, and threats in the power sector.
- Prediction analysis: Forecast cybersecurity incidents, threats, and vulnerabilities.
- CERT-IN collaboration: Coordinate with CERT-In, NCIIPC, and other agencies to resolve incidents.
- Issuing alerts & guidelines: Issue alerts, advisories, and threat intelligence in coordination with designated agencies.
- Setting standards & policies: Develop SOPs, security policies, benchmarks, and best practices.
- Creating awareness: Conduct capacity-building initiatives to raise cybersecurity awareness.
- Implement assessments & audits: Improve cybersecurity posture through audits, assessments, and mock drills.
- Creating sub-sector cybersecurity rules: Coordinate sub-sector-specific cybersecurity frameworks and protocols.
- Crisis management: Advise entities on Cyber Crisis Management Plans and ensure implementation during crises.
- R&D: Facilitate research and development in cybersecurity with industry and academia.
- Supply chain security: Implement measures to secure the supply chain of specified cyber assets.
- Coordination forums: Establish central and regional forums for review, information sharing, and response planning.
Sensitive data and sensitive information collected or processed must be protected against breaches. It may only be used for cybersecurity purposes by designated government agencies and cannot be disclosed to any third party without explicit communication to the concerned entity.
Who do these regulations apply to: All power-related entities that own or operate, or manage:
- Operational Technology (OT) infrastructure linked to the interconnected power system, and
- Information Technology (IT) systems physically or logically connected to OT infrastructure.
Examples include:
- Power Grid Corporation of India (POWERGRID)
- National Hydroelectric Power Corporation Limited (NHPC)
- Nuclear Power Corporation of India (NPCIL)
Mandatory appointment of a CISO: These concerned entities must appoint a senior manager as Chief Information Security Officer (CISO) and an alternate CISO. These positions cannot remain vacant. The CISO must be an Indian citizen and resident, hold an engineering degree or equivalent, and have at least 15 years of experience in the power or IT sector. As per these regulations, they must report directly to the head of the organization, serve a minimum of three years, and focus exclusively on cybersecurity. Additionally, the rules mandate public disclosure of CISOs’ contact information.
What are the reporting timelines? The CISO must report cybersecurity incidents to CSIRT-Power and CERT-In within six hours. If an incident is determined to constitute cyber sabotage of critical systems, then it must be reported within 24 hours.
Beyond reporting, entities face several other obligations under the new rules. Some of the additional obligations are:
- Continuous surveillance and monitoring of Information Technology and Operational Technology systems to identify threats and vulnerabilities, and provide incident response and remediation support.
- Store sensitive data and backups encrypted and exclusively within India.
- Comply with the IT Act’s directions and requirements and all rules and regulations.
- Physically or logically isolate the IT networks containing Critical Information Infrastructure (CII) from the internet and other IT networks.
- Maintain a cyber asset register and a Cyber Risk Assessment and Mitigation Plan, updating the latter every six months and reviewing it annually.
- Maintain a register of all cybersecurity incidents in the format that will be prescribed by CSIRT-Power.
- Entities should review the Cyber Security Policy annually and ensure the Cyber Crisis Management Plan is vetted by CERT-In.
- The CISO must conduct a quarterly review of compliance mandated in the Cyber Security Policy.
- Public-facing web services may only be deployed after passing a cybersecurity audit. Software updates must be tested and confirmed free of vulnerabilities.
- Procure IT equipment and services from trusted sources, as per Central Government guidelines.
Data retention obligations are:
- Cybersecurity audit reports from the last three years.
- Certification audit reports from the last four years.
- Self-audit reports from the last three years.
- Logs of all ICT systems, OT-IT interconnection logs, and forensic records for 180 days.
- Logs associated with an incident (180 days prior and post) for 365 days from the date of occurrence.
- Remote access records and remote operation risk assessments for one year.
It is important to note that a few of these rules might not come into effect on April 1, 2027. They will come into force on later dates through separate orders.
Why it matters: In 2019, a malware attack on the internet-connected network of the Kudankulam Nuclear Power Plant exposed severe vulnerabilities in India’s power infrastructure, a situation that initially prompted denials and delayed disclosures from the concerned officials. In July 2026, data belonging to Reliance, a contractor associated with the Kudankulam Nuclear Power Plant, was reportedly leaked on the dark web. Later, Reliance confirmed a “partial breach” of data on a server hosted by third-party provider Mumbai-based Yotta.
These new regulations aim to directly close such gaps by enforcing strict six-hour incident reporting to a dedicated agency under CERT-In’s newly formed coordinating agency CSIRT-Power. However, the historical functioning of CERT-In tells a different story of its capabilities and thus raises reasonable skepticism over the capabilities of CSIRT-Power. You may refer to this compilation of 10 issues with CERT-In here.
Nonetheless, mandating the physical isolation of critical operational networks from the internet can be helpful at times. For instance, electricity grids are very important critical infrastructure. If these are targeted during adverse times like wars, the whole nation’s regular and important operations could be disrupted, thus giving an immense cyberattack-driven advantage to the adversarial nation(s). Therefore, the need to protect such critical infrastructure is very important.
Also Read:
