CEA notifies new regulations to protect power sector from cyber attack
The Central Electricity Authority (CEA) notified the CEA (Cyber Security in Power Sector) Regulations, 2026, published in the Gazette of India.
The regulations mandate cyber security controls for entities operating Operational Technology (OT) infrastructure connected to the interconnected power system, along with linked Information Technology (IT) systems.
Generating companies, captive generating plants, and entities with energy storage systems of 50 MW capacity and above are directly covered.
Covered entities must appoint a Chief Information Security Officer (CISO) and an alternate CISO, set up a round-the-clock Information Security Division, and maintain a Cyber Security Policy, Cyber Crisis Management Plan, and Asset Register, reviewed annually.
Mandatory provisions of the regulations come into full effect from April 1, 2027, giving covered entities a compliance runway.
CEA's Statutory Role Under the Electricity Act, 2003
The Central Electricity Authority is a statutory body constituted under Part IX of the Electricity Act, 2003. Its functions and duties are laid out under Section 73 of the Act, and it is empowered to make regulations under Section 177. It advises the Central Government on the National Electricity Policy, specifies technical standards for construction and safety of electrical plants and lines, specifies Grid Standards for transmission, and coordinates planning of the power system to ensure reliable and affordable electricity supply.
Key Details
- Constituted under Part IX of the Electricity Act, 2003; functions specified under Section 73
- Section 177 empowers CEA to frame regulations — the legal basis for the 2026 cyber security regulations
- CEA also exercises functions under Section 3 (National Electricity Policy), Section 34 (Grid Standards) and Section 53 (safety and electric supply)
- Functions as a technical regulator distinct from the Central Electricity Regulatory Commission (CERC), which is the economic/tariff regulator
The 2026 cyber security regulations were notified by CEA exercising its rule/regulation-making power (Section 177) read with its safety and technical standard-setting mandate under Section 73, extending its traditional physical-safety oversight into the cyber domain.
Critical Information Infrastructure and "Protected System" — IT Act, 2000, Section 70
Section 70 of the Information Technology Act, 2000 empowers the "appropriate Government" to declare, by gazette notification, any computer resource that directly or indirectly affects the facility of Critical Information Infrastructure (CII) as a "protected system." Unauthorised access to a protected system attracts enhanced criminal penalties under Section 70, including imprisonment up to ten years. Section 70A (inserted by the IT (Amendment) Act, 2008) created the National Critical Information Infrastructure Protection Centre (NCIIPC) as the nodal agency for CII protection.
Key Details
- CII defined as computer resources whose incapacitation would have a debilitating impact on national security, economy, public health, or safety
- NCIIPC established under Section 70A via gazette notification dated January 16, 2014
- NCIIPC has identified power and energy among the designated critical sectors alongside banking, telecom, transport, and government
- Protected-system status requires organisations to undergo periodic security audits and implement an Information Security Management System (ISMS)
Large power generation, transmission, and storage assets fall within the CII framework administered by NCIIPC under the IT Act; the CEA's sector-specific regulations operationalise this protection at the operational-technology (OT) level, which is distinct from, but complementary to, IT Act protected-system status.
Sectoral Cybersecurity Architecture — CERT-In and CSIRT-Power
The Indian Computer Emergency Response Team (CERT-In), functioning under the Ministry of Electronics and Information Technology (MeitY), is the national nodal agency for responding to cyber security incidents under Section 70B of the IT Act, 2000. For sector-specific coordination, CERT-In oversees a network of sectoral Computer Security Incident Response Teams (CSIRTs). In the power sector, the Ministry of Power established CSIRT-Power at the CEA on April 5, 2023, as an extended arm of CERT-In, supported by six sub-sectoral CERTs covering thermal, hydro, transmission, grid operation, renewable energy, and distribution.
Key Details
- CERT-In established under Section 70B of the IT Act, 2000; mandated to collect, analyse, and disseminate cyber incident information
- CSIRT-Power set up April 5, 2023 at CEA; coordinates incident response and threat intelligence for the power sector
- Six sub-sectoral CERTs prepare model Cyber Crisis Management Plans for their respective sub-sectors
- A POWERGRID Centre of Excellence in Cybersecurity has also been set up at IISc Bengaluru to support R&D on grid cybersecurity
The 2026 Regulations institutionalise CSIRT-Power as the coordinating nodal agency for power sector cyber security and make it mandatory for covered entities to align their Cyber Crisis Management Plans with the CSIRT-Power framework, converting what was earlier a voluntary/advisory structure into a binding regulatory requirement.
- Regulations: CEA (Cyber Security in Power Sector) Regulations, 2026
- Published in Gazette of India: July 31, 2026
- Mandatory provisions effective from: April 1, 2027
- Coverage threshold for generating companies/captive plants/energy storage systems: 50 MW and above
- CISO minimum tenure required: 3 years (plus a mandatory alternate CISO)
- CSIRT-Power established at CEA: April 5, 2023
- Enhanced penalty for unauthorised access to a "protected system" under IT Act Section 70: imprisonment up to 10 years
- NCIIPC established under IT Act Section 70A via notification dated January 16, 2014