Blitz Bureau
NEW DELHI: India has written its first binding cyber-defence rulebook for electricity. Read the text rather than the summary, and the sharpest instrument in it is not a firewall — it is a job description that cannot be quietly rewritten.
The Central Electricity Authority’s Cyber Security in Power Sector Regulations, 2026, were published in the Gazette of India on 31 July and their mandatory provisions take effect on 1 April 2027. They are made under Section 177 read with Section 73(c) of the Electricity Act, 2003, with the concurrence of the Ministry of Electronics and Information Technology — which matters, because it converts what had been a decade of advisories, guidelines and best-practice notes into statutory obligation. Until now, a distribution utility that ignored a cyber advisory was ignoring advice. From next April it will be in breach of a regulation.
The coverage is deliberately drawn wide. Every transmission utility, every distribution licensee, every load despatch centre, every power exchange and every over-the-counter trading platform is inside the perimeter. So is every generating company, captive plant and energy storage system of 50 megawatts and above. That 50 MW threshold is the line India has drawn between an asset whose failure is a commercial problem and one whose failure is a system problem — and by including storage, the rules acknowledge something the older grid codes never had to: that batteries are now large enough, and networked enough, to be worth attacking.
Inside the perimeter: transmission utilities, distribution licensees, load despatch centres, power exchanges and every generator, captive plant or storage system of 50 MW and above now fall under a statutory cyber-security regime.
The regulation’s sharpest clause is not technical. It requires a senior regular employee as Chief Information Security Officer, for a minimum tenure of three years — long enough to outlast the incident.
At a Glance
• Instrument: CEA (Cyber Security in Power Sector) Regulations, 2026
• Gazette: 31 July 2026 · mandatory provisions from 1 April 2027
• Enabling law: Section 177 read with Section 73(c), Electricity Act, 2003
• Concurrence: Ministry of Electronics and Information Technology
• Covered: transmission utilities, distribution licensees, load despatch centres, power exchanges, OTC platforms
• Also covered: generators, captive plants and energy storage systems of 50 MW and above
• CISO: a senior regular employee · minimum three-year tenure · alternate CISO mandatory
• Information Security Division: staffed round the clock, 24 hours
• Incident reporting: generally within six hours
• Cyber sabotage of critical systems: within 24 hours
• Nodal agency: CSIRT-Power, coordinating with CERT-In and NCIIPC
Read the personnel clause carefully and it is the most demanding line in the document. The Chief Information Security Officer must be a senior regular employee — not a consultant, not a retainer, not a shared resource borrowed from a parent company — appointed for a minimum tenure of three years, with a named alternate. Alongside sits a requirement for an Information Security Division staffed round the clock by trained professionals. Anyone who has watched compliance functions in the sector will recognise what is being closed off: the practice of designating a nominal officer on paper, rotating the post every few months, and outsourcing the actual watch. A three-year floor means the person who signs the incident report is still in the chair when the audit arrives.
The reporting clocks do the rest of the work. A cyber-security incident must generally reach the authorities within six hours; an act of cyber sabotage touching critical systems within 24. Both funnel to CSIRT-Power, the Computer Security Incident Response Team for the electricity sector, which issues alerts, writes the standard operating procedures and coordinates with CERT-In and the National Critical Information Infrastructure Protection Centre. The honest challenge now is capacity rather than intent: hundreds of distribution utilities, many of them state-owned and thinly staffed on information technology, have roughly nineteen months to find, pay for and retain senior security professionals in a market that is short of them. That is a training and financing problem with a clear path forward — sector-wide skilling through the regional load despatch centres, shared security operations centres for smaller licensees, and budget lines written into the next tariff cycle. The clock started on 31 July. It is a good clock, and it now needs people to run it.













