Compliance

Compliance as a live state,not an annual project.

Every control carries its current verdict, the evidence behind it, and the clock attached to any failure. Recomputed continuously from live context — not reconstructed the week before an audit.

to notify CSIRT-Power and CERT-In of an incident under CEA 2026

to close a critical finding under Chapter IX — the ledger counts it down

INC-2026-0188 · unapproved firmware on critical protection relay
BALLARI TPS — UNIT 3
CSIRT-POWER · CERT-IN · 6-HOUR WINDOW
04:12:33
remaining · evidence completeness 100%
  1. Detect and open incident07:55
  2. Assess affected assets and business impact08:12
  3. Assemble notification pack from context held08:31
  4. CISO review and sign-off—
  5. Submit to CSIRT-Power · CERT-In—
Generated for illustration — not a live incident

CEA 2026

The Chapter III register as a living object. Chapter IV segmentation proven against observed traffic, not described. Chapter IX critical findings on a 30-day clock, with attribute lineage as the audit trail.

IEC 62443

Zones and conduits declared, then continuously tested. Security levels tracked per zone. Alignment maintained through active enrichment rather than periodic review.

The auditor bundle

Register, verdicts, lineage and closures — generated from the same operational model the engineers use, rather than assembled by hand.

India's OT cyber rules,in one place.

The CEA regulation was notified on 31 July 2026 and commences on 1 April 2027. We keep a plain-language reading of it, the CERT-In Directions, NCIIPC protected systems and CSIRT-Power on one page — with the clause to quote and where each obligation lands in ASTRICS.

  1. CEA Regulations, 2026
  2. CSIRT-Power
  3. CERT-In Directions
  4. NCIIPC and protected systems
  5. Ministry of Power orders
  6. IEC 62443 and ISO 27001
  7. Other sectors
  8. How ASTRICS maps to it

Compliance Console — CEA 2026 & IEC 62443

Compliance as a live state rather than an annual project: every control carries its current verdict, the evidence behind it, and the clock attached to any failure.

Compliance Console — CEA 2026 & IEC 62443 — concept view
Concept product view — not a production screenshot

Zones & Conduits

Chapter IV asks an operator to prove trust-level segmentation, not describe it. Declared zones and permitted conduits are continuously tested against observed traffic, and every mismatch becomes a dated finding.

Zones & Conduits — concept view
Concept product view — not a production screenshot

Statutory Incident Response

CEA 2026 allows six hours to notify CSIRT-Power and CERT-In. The clock, the workflow and the submission all run inside the platform, assembled from context already held.

Statutory Incident Response — concept view
Concept product view — not a production screenshot

See ASTRICS against your own environment.

Book a walkthrough with the ASTRICS team and bring one site's worth of questions.