India's CEA Cyber Security Regulations 2026 Now Law

India's CEA Cyber Security Regulations 2026 Now Law

First seen 13 Aug 2026, 17:50 UTC Shieldworkz 83% similarity 30.9

Article Content

Browse articles
ThreatCluster

The Central Electricity Authority (CEA) has enacted the Cyber Security in Power Sector Regulations, effective 1 April 2027. This regulation mandates compliance for entities managing Operational Technology (OT) infrastructure in India's power sector, transitioning from voluntary guidelines to statutory requirements. Key provisions include audit requirements, penalties of up to ₹1 crore per incident, and specific roles for Chief Information Security Officers (CISOs). Entities with an installed capacity of 50 MW or more must adhere to these regulations, while smaller entities are encouraged to implement baseline controls. The regulations also specify training requirements for CISOs and the establishment of dedicated Information Security Divisions. The CEA aims to enhance cybersecurity resilience in the power sector through these comprehensive measures.

Key Points: • CEA Cyber Security Regulations 2026 enforce mandatory compliance from 1 April 2027. • Penalties for non-compliance can reach up to ₹1 crore per incident. • CISOs must meet specific qualifications and training requirements under the new regulations.

ThreatCluster AI How this analysis works

Timeline

2026-07-31
CEA Cyber Security Regulations notified
The CEA published the Cyber Security in Power Sector Regulations in the Gazette of India, marking a shift to mandatory compliance.
Shieldworkz
2026-08-12
Compliance Guide published
Shieldworkz released a compliance guide detailing the new regulations and their implications for the power sector.
Shieldworkz
2026-08-13
Key requirements overview published
Shieldworkz provided a summary of key requirements mandated by the CEA Cyber Security Regulations.
Shieldworkz

Community

Browse all →