India's Power Sector Faces New Cybersecurity Requirements
India's power sector will operate under new cybersecurity mandates following notification of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026. The framework applies to entities owning, operating or managing operational technology infrastructure linked to the interconnected power system, with thresholds of 50 MW and above for generating companies and energy storage facilities.
Organisations must encrypt sensitive data, including cloud-hosted information, and ensure vendors handling such data meet security standards. The regulations require segregation of IT and OT systems, with operational technology equipment and services procured exclusively from trusted sources. Remote OT operations must use dedicated channels isolated from the internet and operate within India.
- Report cybersecurity incidents to CSIRT-Power and CERT-In within six hours; cyber sabotage involving critical systems within 24 hours
- Conduct vulnerability assessments and penetration testing before commissioning new critical systems; address critical vulnerabilities within one month
- Appoint a chief information security officer and alternate, maintain 24-hour security functions, and conduct annual self-audits
- Implement mandatory cybersecurity training for personnel operating critical systems and periodic security exercises