India's OT cyber rules,in one place.
Five instruments decide what an Indian industrial operator has to do about OT cyber security, and they were written by different bodies at different times. This page puts them side by side — what each one is, who it binds, the clocks it starts, and the clause to quote — as we read the notified texts in September 2026.
to report a cyber security incident to CSIRT-Power and CERT-In; twenty-four for cyber sabotage in a critical system. (Reg 7(3)(a))
to address critical and high-risk audit findings from the auditor's report; three months for medium and low. (Reg 13(3))
to furnish CSIRT-Power with the details of any new or replaced critical system after commissioning. (Reg 5(28))
from NCIIPC identifying critical information infrastructure to apply for protected-system notification. (Reg 5(29))
Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026
The first statutory cyber security regulation for India's power sector. It turns the CEA's 2021 Guidelines — issued as interim measures — into binding regulations with a fixed commencement date, a named enforcement officer and a defined audit cycle.
- Notified
- 31 July 2026 — Gazette of India, Extraordinary, Part III, Section 4, No. 484
- In force
- 1 April 2027, for existing as well as upcoming infrastructure (Reg 1(2))
- Made under
- Section 177(1) read with section 73(c) of the Electricity Act, 2003, with the concurrence of the Ministry of Electronics and Information Technology
- Before it
- Guidelines on Cyber Security in Power Sector, 2021 (interim); draft regulations published in 2024 and again in October 2025
- Enforced by
- The Chief Information Security Officer of the Ministry of Power, who can call for closure reports, appoint auditors at the entity's cost, and recommend proceedings under the IT Act or section 142 of the Electricity Act (Regs 14–16)
Who it binds
Every entity with OT on the interconnected power system
Reg 2(1)(a)Any entity that owns, operates or manages operational technology associated with the interconnected power system, together with the IT that is physically or logically connected to it.
Generators, captive plants and storage at 50 MW or more
Reg 2(1)(a), provisosGenerating companies, captive generating plants and organisations with an energy storage system are in scope only at an installed capacity of 50 MW or more. Below that they are encouraged to adopt CERT-In's 15 elemental cyber defence controls for MSMEs.
Transmission, distribution and despatch — no threshold
Reg 2(1)(a); Reg 3(1)(w)Transmission licensees, distribution licensees, the National, Regional and State Load Despatch Centres. No capacity floor.
Power exchanges and OTC platforms
Reg 2(1)(b)In scope, except for the OT-specific chapter and the vendor regulations.
Vendors
Regs 2(2), 11, 12Vendors must comply with the vendor requirements and, for distributed generation resources of prosumers, carry the obligations themselves.
How the regulation is laid out
| Chapter | Title | What it covers |
|---|---|---|
| I | Preliminary | Short title, commencement, applicability, definitions |
| II | Computer Security Incident Response Team – Power | CSIRT-Power as nodal and coordinating agency |
| III | General cyber security requirements | 42 sub-clauses: CISO, policy, asset register, risk plan, VAPT, audits, reporting |
| IV | Additional requirements for OT systems | Isolation, national boundaries, remote operation, trust levels |
| V | CISO and Information Security Division | Qualifications and functions, including six-hour incident reporting |
| VI | Cyber Security Policy | 33 required components |
| VII | Cyber Crisis Management Plan | Prepared with CSIRT-Power, vetted by CERT-In, drilled yearly |
| VIII | Requirements for vendors | Bill of materials, prosumer distributed generation |
| IX | Cyber security audit | Scope, timelines, one-month closure of critical and high findings |
| X | Miscellaneous | Self-audit, enforcement, power to relax; two schedules |
What it requires
Governance
A ring-fenced CISO, and an alternate
Regs 5(1)–5(8), 7(1)Regular employees at senior-management level, designated for at least three years, reporting to the head of the entity, with contact details in the public domain and with CSIRT-Power. Citizens and residents of India, engineering graduates, fifteen years' experience.
A 24×7 Information Security Division in India
Reg 5(9) — deferredStaffed by certified personnel with minimum three-year tenure. This provision is deferred to a date the Authority will set.
A Cyber Security Policy, approved annually
Regs 5(10), 8Approved and reviewed each year by the head or board, covering the 33 components listed in Chapter VI — from the asset register procedure to the OT time source, which must be terrestrial or an India-specific satellite, independent of the internet.
A Cyber Crisis Management Plan
Regs 5(11), 9, 10Prepared in consultation with CSIRT-Power, vetted by CERT-In, approved by the board every year and tested by mock drill at least annually.
The register and the risk plan
A cyber asset register
Reg 5(25)For all cyber assets: ownership, hardware, firmware, software and patch. For all critical systems: configuration, hardware, software, network architecture depicting data flows and communication protocols. Reviewed and updated at least once every financial year or on commissioning of any new asset or critical system, whichever is earlier.
Critical and non-critical, classified
Regs 5(16), 8(4)Systems identified and segregated as critical and non-critical under a procedure in the policy; the register classifies every cyber asset by criticality and risk.
A risk plan every six months
Reg 5(26)A Cyber Risk Assessment and Mitigation Plan for every asset in the register, updated at least every six months and reviewed every financial year.
Tested before commissioning, reported after
Regs 5(27), 5(28)Vulnerability assessment and penetration testing before any new or replaced critical system goes live; its details to CSIRT-Power within thirty days.
Protected systems within sixty days
Reg 5(29)Give NCIIPC the information to identify critical information infrastructure, then apply within sixty days of identification for the asset to be notified as a protected system.
Architecture and access
OT isolated, and segmented by trust level
Regs 6(1), 6(6), 6(8)Physical isolation of OT from the internet and from IT; OT communications separate from IT's; the OT environment segmented into different trust levels on the basis of criticality, security requirements and risk assessment.
Control traffic confined to India
Reg 6(3)Control, operation and real-time data over a dedicated channel isolated from the internet and confined to national boundaries; cross-border exchange only through a separate system and a unidirectional gateway, continuously monitored.
Remote access for emergencies only
Regs 5(17), 6(4), 8(15)Remote access to cyber assets only for troubleshooting and emergencies, under a procedure with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must be within India, approved by the head or board, over an isolated channel.
IT-to-OT flows through a unidirectional gateway
Reg 8(28)Where information must pass between IT and OT, it goes over a separate channel and a unidirectional gateway.
Procurement and vendors
Government testing orders apply
Regs 5(23), 6(5)OT equipment, components and parts must comply with the Central Government's orders — in practice the Ministry of Power orders of 2021 on cyber security testing of power-system equipment.
Cyber security in FAT and SAT
Reg 5(31)Procurement must include factory and site acceptance tests that test the cyber security requirements.
Trusted sources
Regs 5(39), 6(7) — deferredIT and OT equipment and services procured from trusted sources per Central Government orders. Both provisions are deferred to dates the Authority will set.
Vendors carry a bill of materials
Regs 11, 12Vendor obligations include a bill of materials in line with CERT-In guidelines, and direct responsibility for prosumers' distributed generation resources.
Incidents and audits
Six hours to CSIRT-Power and CERT-In
Regs 7(3)(a), 7(3)(g), 5(42)The CISO reports cyber security incidents within six hours to both; an incident concluded as cyber sabotage in a critical system within twenty-four hours. Action-taken reports and root-cause analyses follow; an incident register is kept in CSIRT-Power's format.
Audited every nine to fifteen months
Reg 5(22)By a CERT-In empanelled auditor or one designated by the Ministry of Power, at least once a financial year, with a minimum gap of nine and a maximum of fifteen months; not three consecutive audits by the same agency.
One month to close critical and high findings
Regs 13(3), 14(1), 15The auditor reports within six weeks of starting; critical and high-risk vulnerabilities are addressed within one month of the report and medium and low within three, with compensatory controls in the meantime. The closure report is due within six months of commencement, and a self-audit every year.
Awareness every six months
Regs 5(8), 5(18)Awareness sessions and tabletop exercises at least every six months; five man-days of training a year for the CISO and division staff.
Provisions that start on a later date
Regulations 5(9) (the 24×7 Information Security Division), 5(24) (ISO/IEC 27001 or Technical Criteria certification for critical systems), 5(33) (mandatory courses for O&M personnel), 5(39) and 6(7) (trusted-source procurement) and 6(2) (OT perimeter devices) come into force on dates the Authority will specify by separate order with the Central Government's approval. No such order had been issued when this page was written.
CSIRT-Power and the sectoral CERTs
The Computer Security Incident Response Team – Power was set up by the Ministry of Power at the Central Electricity Authority as an extended arm of CERT-In. The 2026 regulation defines it that way and makes it the nodal and coordinating agency for the sector.
Its directions bind you
Regs 4(3), 13(1)Directions and guidelines issued by CSIRT-Power must be complied with by entities and vendors; the audit scope itself comes from its guidelines.
It is a recipient, not a substitute
Regs 7(3)(a), 5(28), 5(42)Incidents go to CSIRT-Power and to CERT-In, within the same six hours. New critical systems are reported to CSIRT-Power within thirty days; the incident register follows its format.
Sub-sectoral teams
Reg 4(4); CEA ISAC-PowerThe Authority may designate sub-sectoral CSIRTs. The Ministry of Power already operates sub-sectoral CERTs for thermal, hydro, transmission, grid operation, renewable energy and distribution under the Information Sharing and Analysis Centre for the power sector.
CERT-In Directions of 28 April 2022
Issued under section 70B(6) of the Information Technology Act, 2000 and effective sixty days later, the Directions bind every service provider, intermediary, data centre, body corporate and government organisation in India — which is to say every industrial operator, in every sector. The CEA regulation requires compliance with them in addition to its own terms (Reg 5(40)).
Six hours of noticing
Cyber incidents of the types listed in Annexure I must be reported to CERT-In within six hours of noticing them or being brought to notice. Annexure I names, among others, attacks on critical infrastructure, SCADA and operational technology, and attacks on Internet of Things devices.
180 days of logs, in India
Logs of all ICT systems must be enabled and maintained securely for a rolling period of 180 days within Indian jurisdiction, and provided to CERT-In on order.
Time from NIC or NPL
All ICT system clocks synchronised to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to them.
A point of contact
Every organisation designates a point of contact to interface with CERT-In, in the format the Directions specify.
Audits, since 2025
CERT-In's Comprehensive Cyber Security Audit Policy Guidelines of July 2025 expect at least annual audits whose scope includes OT and ICS, with auditors sharing reports with CERT-In.
A second clock for personal data
Where an incident touches personal data, the Digital Personal Data Protection Act, 2023 and its 2025 Rules add a separate notification to the Data Protection Board, with a detailed report within 72 hours.
NCIIPC and protected systems
The National Critical Information Infrastructure Protection Centre is the national nodal agency for critical information infrastructure under section 70A of the IT Act. Section 70 lets the appropriate government notify a computer resource that is critical information infrastructure as a protected system, restricting who may access it and raising the penalties for unauthorised access.
Identification, then notification
CEA Reg 5(29)A power entity must give NCIIPC the information it needs to identify critical information infrastructure, and apply within sixty days of identification for the asset to be notified as a protected system.
NCIIPC's guidelines govern the controls
CEA Regs 7(3)(d), 8(2)Once notified, the controls for a protected system follow NCIIPC's Guidelines for the Protection of National Critical Information Infrastructure (version 2.0, 2015), which the CEA regulation folds into the CISO's functions and the policy.
A steering committee and a 24×7 division
Protected System Rules, 2018The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 require every organisation with a protected system to run an Information Security Steering Committee chaired by its chief executive, with an NCIIPC representative on it, and to operate a security operations capability round the clock.
Sectors
Power and energy — including generation, transmission, distribution, load despatch and oil and gas assets such as refineries and pipelines — transport, telecommunications, banking and financial services, government, strategic and public enterprises, and health are the sectors NCIIPC lists.
Ministry of Power orders and the 2021 Guidelines
Before the regulation there were the Guidelines on Cyber Security in Power Sector, issued by the CEA in October 2021 as interim measures under the grid connectivity standards. Alongside them the Ministry of Power issued orders on the cyber security testing of power-system equipment, which the 2026 regulation now points to.
The 2021 Guidelines
CEA Guidelines, October 2021Applied to every responsible entity in the sector and set the shape the regulation follows: CISO, policy, asset register, six-monthly audits, incident reporting, trusted sources. They remain the operative audit framework until the regulation commences.
Testing of power-system equipment
MoP Order 12/13/2020-T&R; CEA Regs 5(23), 6(5)A Ministry of Power order of July 2020 required imported power-supply equipment to be checked for malware and imports from prior-reference countries to have prior permission. Orders of 8 June 2021 and 24 December 2021 then required cyber security testing of specified equipment — RTUs, PLCs, IEDs, smart meters — at designated Indian laboratories such as CPRI. The regulation requires compliance with such orders for OT equipment, components and parts.
Connectivity, communication and grid code
CEA Connectivity (Amendment) Regulations, 2019, Reg 10; CEA Communication System Regulations, 2020, Reg 14; IEGC 2023, Regs 48–49Regulation 10 of the CEA connectivity standards, inserted in February 2019, requires every requester and user — including solar and wind generators — to comply with Central Government cyber security guidelines. The CEA communication-system standards of 2020 require a cyber risk programme at every control centre and connected user, and the Indian Electricity Grid Code, 2023 requires a cyber security framework and audit in line with the 2021 Guidelines.
Trusted sources
CEA Regs 5(39), 6(7) — deferredProcurement of IT and OT equipment and services from trusted sources, as defined by Central Government orders, is written into the regulation but deferred to a later commencement date.
IEC 62443 and ISO/IEC 27001
The regulation names ISO/IEC 27001 and does not name IEC 62443. In practice both matter: 27001 is the management system the regulation will certify against, and 62443 is the series the Bureau of Indian Standards has adopted as Indian Standards for the security of industrial automation and control systems — the vocabulary of zones, conduits and security levels that trust-level segmentation is audited in.
ISO/IEC 27001 for critical systems
CEA Reg 5(24) — deferredAn ISO/IEC 27001 certificate, or a Technical Criteria Certificate, encompassing all critical systems; no four consecutive certification audits by the same agency. Deferred to a date the Authority will set.
IEC 62443 as Indian Standards
BIS; CEA Reg 6(8)BIS has adopted the IEC 62443 series as Indian Standards (IS/IEC 62443; IS 16335 in the 2021 Guidelines). The regulation's requirement to segment OT into trust levels by criticality and risk is, in 62443 terms, zones and conduits with target security levels.
CERT-In's 15 elemental controls
CEA Reg 2(1), second provisoFor power entities under 50 MW — and as a floor for any small operator — the regulation points to CERT-In's 15 Elemental Cyber Defense Controls for MSMEs.
Beyond the power sector
Outside electricity, India has no sector-specific OT cyber security regulation in force as of September 2026. The CERT-In Directions and the protected-system provisions of the IT Act carry the load, with sector regulators moving at different speeds.
Oil and gas
PNGRB Action Plan 2026–27The Petroleum and Natural Gas Regulatory Board's action plan for 2026–27 commits to a baseline cyber security framework for regulated entities. Refineries and pipelines fall within the sector NCIIPC covers, and captive power at 50 MW or more is in scope of the CEA regulation.
Renewables and rooftop solar
MNRE, 2025–26 — as reportedUtility-scale solar and wind are generating companies under the CEA regulation. For rooftop systems under PM Surya Ghar, the Ministry of New and Renewable Energy has moved in 2025–26 to require inverter communication devices to connect to, and hold data on, servers in India.
Water and wastewater
No sector rule. Obligations come from the IT Act and CERT-In Directions, from state water boards and urban local bodies, and from the contracts under which schemes are built and run.
Manufacturing
No OT-specific rule. The CERT-In Directions, the Digital Personal Data Protection Act, 2023 for personal data, and good-manufacturing-practice data integrity in pharma apply; captive power at 50 MW or more is in scope of the CEA regulation.
Rail, metro, ports and airports
Transport is a sector NCIIPC covers. Indian Railways applies its ICT Security Policy of 2019 and RDSO guidance; Indian-flag ships have carried cyber risk in their safety management systems since DG Shipping's 2017 circular under IMO resolution MSC.428(98); ports sit with the Ministry of Ports, Shipping and Waterways and the port authorities under the Indian Ports Act, 2025; airports with BCAS and the Airports Authority of India.
Smart cities
CERT-In's Cyber Security Guidelines for Smart City Infrastructure of March 2025 cover integrated command and control centres, ICS and IoT, and tie logging back to the 2022 Directions.
Data centres
Named directly in the CERT-In Directions. Building management, cooling and power systems are OT in the same sense as any plant.
Where the obligation landsin ASTRICS.
ASTRICS was shaped around this regime. Each obligation below is met from the same operational understanding, recomputed continuously — not reconstructed the week before an audit.
| Obligation | Clause | In ASTRICS |
|---|---|---|
| Cyber asset register with ownership, firmware, software, patch, configuration and data flows, reviewed every year or on commissioning Reg 5(25) | Reg 5(25) | Asset Inventory holds each field as a first-class column and tracks completeness against it. The Asset Passport carries the lineage. |
| Systems classified as critical and non-critical; register classified by criticality and risk Regs 5(16), 8(4) | Regs 5(16), 8(4) | Criticality is a first-class attribute, derived from the process and business context the asset supports. |
| Risk assessment and mitigation plan updated every six months Reg 5(26) | Reg 5(26) | The Risk Queue ranks by consequence and is a live state, so the six-monthly plan is a report, not a project. |
| OT segmented into trust levels; IT and OT isolated; control traffic confined to India Regs 6(1), 6(3), 6(8) | Regs 6(1), 6(3), 6(8) | Zones & Conduits declares the trust levels and tests them continuously against observed traffic. Each mismatch becomes a dated finding. |
| Remote access only for troubleshooting and emergencies, with MFA, least privilege, minimum duration and geo-fencing Regs 5(17), 8(15) | Regs 5(17), 8(15) | Remote sessions are observed, attributed to a named vendor and checked against the window they were approved for. |
| Incidents reported to CSIRT-Power and CERT-In within six hours Reg 7(3)(a) | Reg 7(3)(a) | The statutory incident workflow assembles the submission from context already held, with the clock running inside the platform. |
| Critical and high findings closed within one month of the audit report Reg 13(3) | Reg 13(3) | The Compliance Console puts each finding on its statutory clock and counts it down, with compensatory controls recorded. |
| Details of new critical systems to CSIRT-Power within thirty days Reg 5(28) | Reg 5(28) | Commissioning changes are recorded in the register with their lineage, so the notification is generated rather than assembled. |
| Audit every nine to fifteen months; evidence the auditor can rely on Regs 5(22), 13 | Regs 5(22), 13 | The auditor bundle — register, verdicts, lineage and closures — is generated from the same model the engineers use. |
| Native logging and 180-day retention under the CERT-In Directions CERT-In Directions, 2022 | CERT-In Directions, 2022 | Events & Syslog: native collection, retention and correlation on the asset model, with no second logging product. |
Questions operators ask
Is the CEA cyber security regulation in force?
It was notified in the Gazette of India on 31 July 2026 and comes into force on 1 April 2027, for existing as well as upcoming infrastructure. Six provisions — the 24×7 security division, ISO/IEC 27001 certification, mandatory courses, trusted-source procurement for IT and for OT, and OT perimeter devices — start on later dates the Authority will set by separate order.
Does it apply to a solar or wind plant?
Yes, where the generating company's installed capacity is 50 MW or more. Renewable generators are not treated separately; they are generating companies. Energy storage owners have the same threshold. Below 50 MW an operator is encouraged to adopt CERT-In's 15 elemental controls.
What is the difference between CSIRT-Power and CERT-In?
CERT-In is the national incident response agency under the IT Act; its Directions of April 2022 bind every body corporate. CSIRT-Power is the power sector's own team, set up by the Ministry of Power at the CEA as an extended arm of CERT-In. The regulation makes CSIRT-Power the nodal agency for the sector and requires incidents to be reported to both, within the same six hours.
Does the regulation require IEC 62443?
No — the text names ISO/IEC 27001 and does not name IEC 62443. It does require the OT environment to be segmented into trust levels by criticality, security requirements and risk assessment, which is what IEC 62443 calls zones and conduits with security levels. BIS has adopted the IEC 62443 series as Indian Standards, and it is the vocabulary most audits will use.
What is a protected system?
Under section 70 of the Information Technology Act, the appropriate government can notify a computer resource that is critical information infrastructure as a protected system. Access is then restricted to authorised persons and unauthorised access carries higher penalties. The CEA regulation requires power entities to give NCIIPC the information to identify such assets and to apply for notification within sixty days.
Our plant is under 50 MW. Do we have anything to do?
The CEA regulation encourages, rather than requires, plants under 50 MW to implement CERT-In's 15 elemental cyber defence controls. The CERT-In Directions still apply in full — six-hour reporting, 180 days of logs in India, NTP synchronisation — because they bind every body corporate.
What does the regulation say about vendors overseas?
Remote operation of OT must take place within India with the prior approval of the head or board, over a channel isolated from the internet. Remote access more generally is permitted only for troubleshooting and emergencies, under a procedure with minimum duration, least privilege, multi-factor authentication and geo-fencing. Control and real-time data must stay within national boundaries except through a unidirectional gateway.
Primary sources
- Gazette notification, CEA (Cyber Security in Power Sector) Regulations, 2026
- CEA Guidelines on Cyber Security in Power Sector, 2021
- CERT-In Directions under section 70B(6), 28 April 2022
- NCIIPC
- CEA — Information Sharing and Analysis Centre for the power sector
- PNGRB Action Plan 2026–27
- Ministry of Power order on cyber security testing of power-system equipment, 24 December 2021
- CEA (Technical Standards for Communication System in Power System Operations) Regulations, 2020
- CERT-In Cyber Security Guidelines for Smart City Infrastructure, March 2025
Summaries of the notified texts as we read them. Orientation, not legal advice — check the Gazette or the direction before you rely on a clause.
See ASTRICS against your own environment.
Book a walkthrough with the ASTRICS team and bring one site's worth of questions.
