Digital cybersecurity systems and network protection technologies supporting secure power sector operations. Google Images
NATIONAL NEWS

CEA Mandates Cybersecurity Rules for India’s Power Sector

CEA has mandated cybersecurity regulations for India’s power sector, requiring cyber risk management, incident response, security governance and protection of critical power infrastructure.

Editorial Team, RenewEdge

The Central Electricity Authority has notified a mandatory cybersecurity framework for India’s power sector. The regulations introduce legally enforceable requirements for cyber risk management, operational technology security, incident reporting and critical infrastructure protection across the electricity value chain.

The Central Electricity Authority (CEA) has notified a comprehensive cybersecurity framework for India’s power sector, introducing mandatory cyber risk management, incident response and compliance requirements across generation, transmission, distribution and other critical power system operations.

The regulations establish legally enforceable cybersecurity obligations for power sector entities, replacing the earlier advisory-based approach under the Cyber Security in Power Sector Guidelines, 2021. Utilities and power system operators will now be required to implement structured cybersecurity governance, security controls, continuous monitoring and formal incident reporting procedures.

A key element of the framework is the mandatory protection of operational technology (OT) environments, including grid operations, substations, power generation facilities and transmission networks. Entities must maintain asset inventories, conduct cybersecurity risk assessments, implement secure access controls and strengthen the protection of critical infrastructure connected to the electricity system.

The regulations also require the establishment of sector-specific incident response mechanisms coordinated through the Computer Security Incident Response Team for the power sector. Power sector entities will be required to develop incident response plans, conduct regular cyber security drills and report cyber incidents promptly to designated authorities.

The framework places significant emphasis on supply chain and vendor security, recognising the increasing cyber risks associated with digital equipment, software platforms and third-party service providers. Utilities will need to strengthen procurement controls, vendor risk assessments and security compliance across their technology ecosystems.

Conceptual illustration of India’s clean energy transition, showcasing renewable energy infrastructure, carbon markets, sustainable transport, and low-carbon industrial development.

The notification comes as India’s power sector undergoes rapid digital transformation through smart grids, SCADA systems, IoT-enabled monitoring, advanced metering infrastructure and renewable energy integration. While these technologies improve operational efficiency and grid flexibility, they also expand the sector’s cyber risk exposure.

The regulations are aligned with broader national cybersecurity initiatives involving CERT-In and the National Critical Information Infrastructure Protection Centre (NCIIPC), which classifies the power and energy sector as a critical infrastructure domain.

By introducing mandatory and auditable cybersecurity requirements across the electricity value chain, the CEA aims to strengthen grid security, operational resilience and the protection of critical power infrastructure as India continues to modernise its electricity system and expand renewable energy deployment.