Shieldworkz
India's CEA Cyber Security Regulations 2026 Now Law
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Central Electricity Authority (CEA) has enacted the Cyber Security in Power Sector Regulations, effective 1 April 2027. This regulation mandates compliance for entities managing Operational Technology (OT) infrastructure in India's power sector, transitioning from voluntary guidelines to statutory requirements. Key provisions include audit requirements, penalties of up to ₹1 crore per incident, and specific roles for Chief Information Security Officers (CISOs). Entities with an installed capacity of 50 MW or more must adhere to these regulations, while smaller entities are encouraged to implement baseline controls. The regulations also specify training requirements for CISOs and the establishment of dedicated Information Security Divisions. The CEA aims to enhance cybersecurity resilience in the power sector through these comprehensive measures.
Key Points: • CEA Cyber Security Regulations 2026 enforce mandatory compliance from 1 April 2027. • Penalties for non-compliance can reach up to ₹1 crore per incident. • CISOs must meet specific qualifications and training requirements under the new regulations.