HomePolicies & Regulations ›CEA Notifies Cybersecurity Norms for Power Plants, ESS of Over 50 MW to be Effective from April 2027

CEA Notifies Cybersecurity Norms for Power Plants, ESS of Over 50 MW to be Effective from April 2027

The Central Electricity Authority has notified the Cyber Security in Power Sector Regulations, 2026, introducing mandatory cybersecurity, data localisation, incident reporting and system-isolation requirements for power sector entities, including ESS projects of 50 MW and above, effective April 1, 2027.

August 19, 2026. By Mrinmoy Dey

The Central Electricity Authority (CEA) has officially notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 under Section 177 of the Electricity Act, 2003, following concurrence from the Ministry of Electronics and Information Technology (MeitY). These comprehensive regulations, which are set to take effect on April 1, 2027, establish stringent physical and digital operational security standards across India's energy grid infrastructure.
 
The framework applies to entities managing Operational Technology (OT) and connected Information Technology (IT) assets, specifically targeting power generation plants, captive facilities, and Energy Storage Systems (ESS) with an installed capacity of 50 MW or higher, as well as power exchanges and Over-the-Counter (OTC) platforms.
 
To enforce robust governance, regulated entities are mandated to appoint a senior management employee as Chief Information Security Officer (CISO) for a minimum term of three years, who will directly report to the head of the organisation. Additionally, organisations must set up a dedicated 24/7 Information Security Division based entirely within India.
 
The Computer Security Incident Response Team – Power (CSIRT-Power) has been designated as the primary sectoral nodal agency responsible for coordinating incident responses alongside CERT-In and NCIIPC.
 
Under these mandates, entities face strict operational reporting timelines, requiring them to disclose standard cyber incidents within six hours and confirmed cyber sabotage on critical assets within 24 hours.
 
The new framework prioritises complete data localisation and system isolation, decreeing that all operational data, cloud hosting, and system backups remain exclusively within Indian borders.
 
Critical OT networks must be physically air-gapped from the internet and IT networks, utilising unidirectional gateways and strong encryption where data exchange is unavoidable. Entities must also undergo mandatory annual cybersecurity audits and maintain ISO/IEC 27001 or Technical Criteria certifications.
 
Furthermore, stringent compliance extends to supply chain security, requiring third-party vendors to provide software Bills of Materials (BOM), regular security patch updates, and full compliance with local data storage requirements.
  Download the attached file
Please share! Email Buffer Digg Facebook Google LinkedIn Pinterest Reddit Twitter
If you want to cooperate with us and would like to reuse some of our content,
please contact: contact@energetica-india.net.
 
 
Next events
 
 
Last interviews
 
Follow us