Government Schemes and Policy · 17 August 2026
Central Electricity Authority notifies Cyber Security in Power Sector Regulations, 2026
Exam-focused facts from the 17 August 2026 current affairs briefing.
Key facts
- The Central Electricity Authority (CEA) notified the 'Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026', which will take effect from April 1, 2027.
- The regulations require power sector entities to store sensitive data, including cloud-hosted data and historical records, in an encrypted, secure and protected environment, and this requirement also extends to vendors such as cloud service providers.
- The regulations apply to generating companies, captive generating plants, and energy storage system installations of 50 MW and above.
- Power sector entities must report cyber-security incidents to CSIRT-Power and CERT-In within six hours, and incidents determined to be cyber sabotage involving critical systems must be reported within 24 hours.
- Power sector organisations must segregate IT and OT systems, procure OT equipment and services from trusted sources, and carry out remote operation of OT systems only within India through a dedicated communication channel isolated from the internet.
- New critical systems must undergo cybersecurity audits, including vulnerability assessment and penetration testing, before commissioning; critical and high-risk vulnerabilities must be addressed within one month, and medium and low-risk vulnerabilities within three months.
- Organisations must appoint a Chief Information Security Officer (CISO) and an alternate CISO, maintain a 24-hour information security function, conduct annual self-audits, and maintain cyber-risk assessments, asset registers and incident-response plans.