Government Schemes and Policy · 17 August 2026

Central Electricity Authority notifies Cyber Security in Power Sector Regulations, 2026

Exam-focused facts from the 17 August 2026 current affairs briefing.

Key facts

  • The Central Electricity Authority (CEA) notified the 'Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026', which will take effect from April 1, 2027.
  • The regulations require power sector entities to store sensitive data, including cloud-hosted data and historical records, in an encrypted, secure and protected environment, and this requirement also extends to vendors such as cloud service providers.
  • The regulations apply to generating companies, captive generating plants, and energy storage system installations of 50 MW and above.
  • Power sector entities must report cyber-security incidents to CSIRT-Power and CERT-In within six hours, and incidents determined to be cyber sabotage involving critical systems must be reported within 24 hours.
  • Power sector organisations must segregate IT and OT systems, procure OT equipment and services from trusted sources, and carry out remote operation of OT systems only within India through a dedicated communication channel isolated from the internet.
  • New critical systems must undergo cybersecurity audits, including vulnerability assessment and penetration testing, before commissioning; critical and high-risk vulnerabilities must be addressed within one month, and medium and low-risk vulnerabilities within three months.
  • Organisations must appoint a Chief Information Security Officer (CISO) and an alternate CISO, maintain a 24-hour information security function, conduct annual self-audits, and maintain cyber-risk assessments, asset registers and incident-response plans.