Central Electricity Authority Notifies Cybersecurity Regulations for Power Sector
The Central Electricity Authority (CEA) notifies new cybersecurity regulations to protect the power sector from cyber-attacks, and they become effective from April 1, 2027. The regulations prescribe coverage, reporting timelines, IT-OT security requirements, audits, and institutional measures for entities linked to the interconnected power system.
CEA Cybersecurity Regulations:
| Dimension | Key Details |
|---|---|
| Coverage | The regulations apply to entities owning, operating, or managing Operational Technology (OT) infrastructure linked to the interconnected power system, and to IT infrastructure physically or logically connected to OT systems. |
| Coverage threshold | For generating companies, captive plants, and energy storage systems, the regulations apply to 50 MW and above. |
| Key data security measures | Sensitive data, including cloud-hosted and historical data, must be encrypted, securely stored, and protected from unauthorised access. |
| Applicability to service providers | The requirements apply to vendors and cloud service providers. |
| Cyber incident reporting timeline | Cybersecurity incidents must be reported to CSIRT-Power and CERT-In within 6 hours. |
| Cyber sabotage reporting timeline | Cyber sabotage involving critical systems must be reported within 24 hours. |
| IT–OT security | Mandatory segregation of IT and OT systems is mandated. |
| OT procurement | OT equipment and services must be procured from trusted sources. |
| Remote OT operations conditions | Remote OT operations, where required, must be conducted within India and use a dedicated communication channel isolated from the internet. |
| Cybersecurity audits for new critical systems | New critical systems must undergo cybersecurity audits, vulnerability assessment, and penetration testing (VAPT) before commissioning. |
| Vulnerability remediation timeline | Critical and High vulnerabilities must be remediated within 1 month, and Medium and Low vulnerabilities must be remediated within 3 months. |
| Institutional requirements | Appointment of a Chief Information Security Officer (CISO) and an Alternate CISO is mandated, along with a 24×7 information security function. |
| Annual self-audits and documentation | Annual self-audits and maintenance of cyber-risk assessments, asset registers, and incident-response plans are mandated. |
| Capacity building and monitoring | Mandatory cybersecurity training for personnel handling critical systems, continuous monitoring of IT and OT systems, and periodic cybersecurity exercises are mandated. |
| CSIRT-Power status and role | CSIRT-Power has been established at CEA in April 2023 as an extended arm of CERT-In, and it helps power utilities detect, respond to, and manage cyber incidents. |
| Cyberattack reference | The power sector faces nearly 2 lakh cyberattacks during Operation Sindoor, and all of these are discontented. |