Key Takeaways
- The CEA Cyber Security in Power Sector Regulations, 2026 take effect on April 1, 2027. DISCOMs are within scope, with no capacity threshold stated for distribution.
- Existing IT/OT infrastructure and vendor contracts may need changes, including network separation, data protection, remote access controls and new vendor requirements.
- The six-hour incident-reporting window makes continuous monitoring and visibility critical for detecting, assessing and escalating incidents quickly.
- IT/OT separation can affect everyday processes such as loss analysis, making controlled data exchange important to maintain operational visibility.
CEA notifies new cybersecurity regulations
The Central Electricity Authority (CEA) has notified the CEA (Cyber Security in Power Sector) Regulations, 2026, putting mandatory cybersecurity requirements in place for the power sector’s IT and operational technology (OT) systems. The regulations were published in the Gazette of India on July 31, 2026 and come into force on April 1, 2027.
For DISCOMs, this is a significant shift. There is no capacity threshold stated for distribution, so the regulations apply across the distribution environment. The rules set requirements for how IT and OT systems are protected, how data and remote access are managed, how technology vendors secure the systems they supply, and how cybersecurity incidents are handled.
This gives utilities less than a year to examine whether their existing architecture, vendor arrangements and cybersecurity processes meet the new requirements and address any gaps before the compliance deadline.
The regulations also introduce specific requirements for technology vendors supplying hardware, software and cloud services to the power sector.
What the rules require
The regulations cover 4 broad areas that utilities will need to address. For utilities with existing IT and OT environments, meeting these requirements may also mean changing infrastructure, contracts and day-to-day processes that have been in place for years.
- Technical controls
The rules require OT networks to be physically separated from the internet and conventional IT networks, with operational data moving through dedicated and secure communication channels. They also introduce requirements around data residency, encryption, remote access, multi-factor authentication, monitoring and logging. Entities must obtain ISO/IEC 27001 certification or meet equivalent technical requirements.
What this could mean for existing utility environments:
- OT network architecture may need to change. Utilities that currently depend on internet-connected or closely integrated OT environments may need to redesign network architecture and establish dedicated communication channels.
- Software updates and maintenance could become more complex. Where vendors currently rely on remote or internet-based access to update and maintain OT systems, tighter separation may require new methods for testing, transferring and deploying software.
- New communication infrastructure may be required. Dedicated and secure channels for OT data can involve additional network infrastructure, implementation effort and recurring connectivity costs.
- Data and backup arrangements may need to be moved. Utilities using offshore cloud infrastructure or data centres may need to migrate critical data and backups to systems located in India. Existing backup processes may also need to be redesigned around encryption and residency requirements.
- Remote access processes will need tighter controls. Vendor and internal access may need to move to controlled emergency access using multi-factor authentication, monitoring and logging, which could require new security tools and changes to existing support processes.
- Cybersecurity becomes an ongoing compliance cost. ISO/IEC 27001 certification or equivalent controls require more than a one-time implementation. Utilities will need to maintain the necessary controls, processes and evidence over time.
- Vendor requirements
The regulations also extend into the technology supply chain. Suppliers of hardware, software and cloud services must provide tested recovery plans, digitally signed software patches and a comprehensive Bill of Materials.
These requirements can affect how existing products are maintained and updated. Vendors may need to change their patching processes, provide additional documentation and establish recovery procedures that were not part of older contracts. For OT environments where software updates already require controlled testing and deployment, adding digital-signature requirements and additional validation can make upgrades more involved.
This also brings existing technology contracts into the discussion. A head-end or MDM contract signed before these requirements existed may not contain the controls now expected under the regulations. Utilities may therefore need to review and amend existing agreements, renegotiate responsibilities with suppliers or account for additional services and compliance requirements when contracts are renewed.
- Governance
The regulations establish a more formal cybersecurity structure for the sector. CSIRT-Power will act as the coordinating and nodal agency for areas including incident analysis, alerts and advisories, assessments and audits, exercises, capacity building and supply-chain security.
At the utility level, entities will need a Chief Information Security Officer (CISO) and an alternate, along with a 24-hour Information Security Division staffed by trained professionals. Utilities will also need a Cyber Security Policy, Cyber Crisis Management Plan and updated Asset Register, with annual reviews and mandatory annual cybersecurity audits.
For utilities that do not already have these functions in place, this means additional people, training, processes and technology. A 24-hour security function also creates a recurring operational cost rather than a one-time implementation expense. Annual audits, policy reviews, asset-register updates and training add to that ongoing compliance workload.
- Incident reporting
Cybersecurity incidents must generally be reported to CSIRT-Power within 6 hours, and cyber-sabotage incidents involving critical systems within 24 hours.
The six-hour requirement has an important operational implication. A utility needs to be able to detect an incident, assess what has happened, escalate it and begin the reporting process within that window. Utilities may therefore need stronger monitoring, alerting and incident-response capabilities, along with continuous visibility into their IT and OT environments, so that incidents can be detected and assessed as they happen rather than through periodic checks or after an issue has already surfaced. Where these capabilities do not already exist, putting them in place can mean additional technology, staffing and training costs.
How the new rules will affect the existing processes
The new cybersecurity rules draw a hard line between IT and OT. The two environments can no longer share data through open or informal connections. Direct access from one to the other has to be restricted, and any data that moves between them has to go through a controlled, auditable route.
Loss analysis is a good example. Feeder and distribution-transformer readings typically come from the OT environment, while consumer consumption data sits within systems on the IT side. Comparing the two helps utilities identify where losses may be occurring. The analysis itself does not disappear under the new cybersecurity rules. What changes is how the data can move between these environments.
A utility that currently relies on informal or loosely controlled access between IT and OT may need to redesign that connection. The data will still need to reach the people and systems responsible for energy accounting and loss analysis, but the route needs to follow the security controls required by the new regulations.
This is where cybersecurity and day-to-day utility operations meet. A separation requirement may be straightforward from a security perspective, but implementing it without disrupting existing workflows requires careful planning.
The design question that follows is where the energy-accounting work sits. A layer that reads OT data through a controlled interface has less to rebuild than one that depends on direct access to the control environment. In practice, this can be straightforward: an air-gapped OT system can write a scheduled data dump to an intermediate server, and the analytics layer can collect it over SFTP. The two systems are never directly connected, while the data can still be refreshed as often as operations require, including several times a day.
This is the model WorkOnGrid is built around. Its integration layer brings data from existing utility systems into a controlled environment where teams can monitor processes, analyse information and act on exceptions without depending on direct access to every underlying system.
What to establish before April 2027
The transition period gives DISCOMs an opportunity to understand where they stand today and where changes will be needed.
- Where is operational data and its backup physically stored, including cloud instances and historian archives?
- How does loss analysis cross the IT and OT boundary today, and can that path be rebuilt through a governed interface without losing visibility?
- How are vendors accessing systems today, and is that access standing or granted per incident?
- What do current vendor contracts actually require, and do they cover signed patches, recovery plans and a Bill of Materials?
- Can a cyber incident be detected, assessed and reported within six hours, at any hour of the day?
The first two questions may be difficult because they often involve architecture and hosting decisions made years ago. Those decisions may be spread across contracts, system configurations and processes that have not been reviewed together.
With less than a year before the regulations take effect, the immediate priority for utilities is to understand the gap between their current environment and the requirements that will apply from April 1, 2027.


.png)






