India's OT cyber rules,in one place.

Five instruments decide what an Indian industrial operator has to do about OT cyber security, and they were written by different bodies at different times. This page puts them side by side — what each one is, who it binds, the clocks it starts, and the clause to quote — as we read the notified texts in September 2026.

Last checked against the notified texts: 9 September 2026.
Summaries of the notified texts as we read them. Orientation, not legal advice — check the Gazette or the direction before you rely on a clause.

to report a cyber security incident to CSIRT-Power and CERT-In; twenty-four for cyber sabotage in a critical system. (Reg 7(3)(a))

to address critical and high-risk audit findings from the auditor's report; three months for medium and low. (Reg 13(3))

to furnish CSIRT-Power with the details of any new or replaced critical system after commissioning. (Reg 5(28))

from NCIIPC identifying critical information infrastructure to apply for protected-system notification. (Reg 5(29))

Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026

The first statutory cyber security regulation for India's power sector. It turns the CEA's 2021 Guidelines — issued as interim measures — into binding regulations with a fixed commencement date, a named enforcement officer and a defined audit cycle.

Notified
31 July 2026 — Gazette of India, Extraordinary, Part III, Section 4, No. 484
In force
1 April 2027, for existing as well as upcoming infrastructure (Reg 1(2))
Made under
Section 177(1) read with section 73(c) of the Electricity Act, 2003, with the concurrence of the Ministry of Electronics and Information Technology
Before it
Guidelines on Cyber Security in Power Sector, 2021 (interim); draft regulations published in 2024 and again in October 2025
Enforced by
The Chief Information Security Officer of the Ministry of Power, who can call for closure reports, appoint auditors at the entity's cost, and recommend proceedings under the IT Act or section 142 of the Electricity Act (Regs 14–16)

Who it binds

Every entity with OT on the interconnected power system

Reg 2(1)(a)

Any entity that owns, operates or manages operational technology associated with the interconnected power system, together with the IT that is physically or logically connected to it.

Generators, captive plants and storage at 50 MW or more

Reg 2(1)(a), provisos

Generating companies, captive generating plants and organisations with an energy storage system are in scope only at an installed capacity of 50 MW or more. Below that they are encouraged to adopt CERT-In's 15 elemental cyber defence controls for MSMEs.

Transmission, distribution and despatch — no threshold

Reg 2(1)(a); Reg 3(1)(w)

Transmission licensees, distribution licensees, the National, Regional and State Load Despatch Centres. No capacity floor.

Power exchanges and OTC platforms

Reg 2(1)(b)

In scope, except for the OT-specific chapter and the vendor regulations.

Vendors

Regs 2(2), 11, 12

Vendors must comply with the vendor requirements and, for distributed generation resources of prosumers, carry the obligations themselves.

How the regulation is laid out

ChapterTitleWhat it covers
IPreliminaryShort title, commencement, applicability, definitions
IIComputer Security Incident Response Team – PowerCSIRT-Power as nodal and coordinating agency
IIIGeneral cyber security requirements42 sub-clauses: CISO, policy, asset register, risk plan, VAPT, audits, reporting
IVAdditional requirements for OT systemsIsolation, national boundaries, remote operation, trust levels
VCISO and Information Security DivisionQualifications and functions, including six-hour incident reporting
VICyber Security Policy33 required components
VIICyber Crisis Management PlanPrepared with CSIRT-Power, vetted by CERT-In, drilled yearly
VIIIRequirements for vendorsBill of materials, prosumer distributed generation
IXCyber security auditScope, timelines, one-month closure of critical and high findings
XMiscellaneousSelf-audit, enforcement, power to relax; two schedules

What it requires

Governance

A ring-fenced CISO, and an alternate

Regs 5(1)–5(8), 7(1)

Regular employees at senior-management level, designated for at least three years, reporting to the head of the entity, with contact details in the public domain and with CSIRT-Power. Citizens and residents of India, engineering graduates, fifteen years' experience.

A 24×7 Information Security Division in India

Reg 5(9) — deferred

Staffed by certified personnel with minimum three-year tenure. This provision is deferred to a date the Authority will set.

A Cyber Security Policy, approved annually

Regs 5(10), 8

Approved and reviewed each year by the head or board, covering the 33 components listed in Chapter VI — from the asset register procedure to the OT time source, which must be terrestrial or an India-specific satellite, independent of the internet.

A Cyber Crisis Management Plan

Regs 5(11), 9, 10

Prepared in consultation with CSIRT-Power, vetted by CERT-In, approved by the board every year and tested by mock drill at least annually.

The register and the risk plan

A cyber asset register

Reg 5(25)

For all cyber assets: ownership, hardware, firmware, software and patch. For all critical systems: configuration, hardware, software, network architecture depicting data flows and communication protocols. Reviewed and updated at least once every financial year or on commissioning of any new asset or critical system, whichever is earlier.

Critical and non-critical, classified

Regs 5(16), 8(4)

Systems identified and segregated as critical and non-critical under a procedure in the policy; the register classifies every cyber asset by criticality and risk.

A risk plan every six months

Reg 5(26)

A Cyber Risk Assessment and Mitigation Plan for every asset in the register, updated at least every six months and reviewed every financial year.

Tested before commissioning, reported after

Regs 5(27), 5(28)

Vulnerability assessment and penetration testing before any new or replaced critical system goes live; its details to CSIRT-Power within thirty days.

Protected systems within sixty days

Reg 5(29)

Give NCIIPC the information to identify critical information infrastructure, then apply within sixty days of identification for the asset to be notified as a protected system.

Architecture and access

OT isolated, and segmented by trust level

Regs 6(1), 6(6), 6(8)

Physical isolation of OT from the internet and from IT; OT communications separate from IT's; the OT environment segmented into different trust levels on the basis of criticality, security requirements and risk assessment.

Control traffic confined to India

Reg 6(3)

Control, operation and real-time data over a dedicated channel isolated from the internet and confined to national boundaries; cross-border exchange only through a separate system and a unidirectional gateway, continuously monitored.

Remote access for emergencies only

Regs 5(17), 6(4), 8(15)

Remote access to cyber assets only for troubleshooting and emergencies, under a procedure with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must be within India, approved by the head or board, over an isolated channel.

IT-to-OT flows through a unidirectional gateway

Reg 8(28)

Where information must pass between IT and OT, it goes over a separate channel and a unidirectional gateway.

Procurement and vendors

Government testing orders apply

Regs 5(23), 6(5)

OT equipment, components and parts must comply with the Central Government's orders — in practice the Ministry of Power orders of 2021 on cyber security testing of power-system equipment.

Cyber security in FAT and SAT

Reg 5(31)

Procurement must include factory and site acceptance tests that test the cyber security requirements.

Trusted sources

Regs 5(39), 6(7) — deferred

IT and OT equipment and services procured from trusted sources per Central Government orders. Both provisions are deferred to dates the Authority will set.

Vendors carry a bill of materials

Regs 11, 12

Vendor obligations include a bill of materials in line with CERT-In guidelines, and direct responsibility for prosumers' distributed generation resources.

Incidents and audits

Six hours to CSIRT-Power and CERT-In

Regs 7(3)(a), 7(3)(g), 5(42)

The CISO reports cyber security incidents within six hours to both; an incident concluded as cyber sabotage in a critical system within twenty-four hours. Action-taken reports and root-cause analyses follow; an incident register is kept in CSIRT-Power's format.

Audited every nine to fifteen months

Reg 5(22)

By a CERT-In empanelled auditor or one designated by the Ministry of Power, at least once a financial year, with a minimum gap of nine and a maximum of fifteen months; not three consecutive audits by the same agency.

One month to close critical and high findings

Regs 13(3), 14(1), 15

The auditor reports within six weeks of starting; critical and high-risk vulnerabilities are addressed within one month of the report and medium and low within three, with compensatory controls in the meantime. The closure report is due within six months of commencement, and a self-audit every year.

Awareness every six months

Regs 5(8), 5(18)

Awareness sessions and tabletop exercises at least every six months; five man-days of training a year for the CISO and division staff.

Provisions that start on a later date

Regulations 5(9) (the 24×7 Information Security Division), 5(24) (ISO/IEC 27001 or Technical Criteria certification for critical systems), 5(33) (mandatory courses for O&M personnel), 5(39) and 6(7) (trusted-source procurement) and 6(2) (OT perimeter devices) come into force on dates the Authority will specify by separate order with the Central Government's approval. No such order had been issued when this page was written.

CSIRT-Power and the sectoral CERTs

The Computer Security Incident Response Team – Power was set up by the Ministry of Power at the Central Electricity Authority as an extended arm of CERT-In. The 2026 regulation defines it that way and makes it the nodal and coordinating agency for the sector.

Its directions bind you

Regs 4(3), 13(1)

Directions and guidelines issued by CSIRT-Power must be complied with by entities and vendors; the audit scope itself comes from its guidelines.

It is a recipient, not a substitute

Regs 7(3)(a), 5(28), 5(42)

Incidents go to CSIRT-Power and to CERT-In, within the same six hours. New critical systems are reported to CSIRT-Power within thirty days; the incident register follows its format.

Sub-sectoral teams

Reg 4(4); CEA ISAC-Power

The Authority may designate sub-sectoral CSIRTs. The Ministry of Power already operates sub-sectoral CERTs for thermal, hydro, transmission, grid operation, renewable energy and distribution under the Information Sharing and Analysis Centre for the power sector.

CERT-In Directions of 28 April 2022

Issued under section 70B(6) of the Information Technology Act, 2000 and effective sixty days later, the Directions bind every service provider, intermediary, data centre, body corporate and government organisation in India — which is to say every industrial operator, in every sector. The CEA regulation requires compliance with them in addition to its own terms (Reg 5(40)).

Six hours of noticing

Cyber incidents of the types listed in Annexure I must be reported to CERT-In within six hours of noticing them or being brought to notice. Annexure I names, among others, attacks on critical infrastructure, SCADA and operational technology, and attacks on Internet of Things devices.

180 days of logs, in India

Logs of all ICT systems must be enabled and maintained securely for a rolling period of 180 days within Indian jurisdiction, and provided to CERT-In on order.

Time from NIC or NPL

All ICT system clocks synchronised to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to them.

A point of contact

Every organisation designates a point of contact to interface with CERT-In, in the format the Directions specify.

Audits, since 2025

CERT-In's Comprehensive Cyber Security Audit Policy Guidelines of July 2025 expect at least annual audits whose scope includes OT and ICS, with auditors sharing reports with CERT-In.

A second clock for personal data

Where an incident touches personal data, the Digital Personal Data Protection Act, 2023 and its 2025 Rules add a separate notification to the Data Protection Board, with a detailed report within 72 hours.

NCIIPC and protected systems

The National Critical Information Infrastructure Protection Centre is the national nodal agency for critical information infrastructure under section 70A of the IT Act. Section 70 lets the appropriate government notify a computer resource that is critical information infrastructure as a protected system, restricting who may access it and raising the penalties for unauthorised access.

Identification, then notification

CEA Reg 5(29)

A power entity must give NCIIPC the information it needs to identify critical information infrastructure, and apply within sixty days of identification for the asset to be notified as a protected system.

NCIIPC's guidelines govern the controls

CEA Regs 7(3)(d), 8(2)

Once notified, the controls for a protected system follow NCIIPC's Guidelines for the Protection of National Critical Information Infrastructure (version 2.0, 2015), which the CEA regulation folds into the CISO's functions and the policy.

A steering committee and a 24×7 division

Protected System Rules, 2018

The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 require every organisation with a protected system to run an Information Security Steering Committee chaired by its chief executive, with an NCIIPC representative on it, and to operate a security operations capability round the clock.

Sectors

Power and energy — including generation, transmission, distribution, load despatch and oil and gas assets such as refineries and pipelines — transport, telecommunications, banking and financial services, government, strategic and public enterprises, and health are the sectors NCIIPC lists.

Ministry of Power orders and the 2021 Guidelines

Before the regulation there were the Guidelines on Cyber Security in Power Sector, issued by the CEA in October 2021 as interim measures under the grid connectivity standards. Alongside them the Ministry of Power issued orders on the cyber security testing of power-system equipment, which the 2026 regulation now points to.

The 2021 Guidelines

CEA Guidelines, October 2021

Applied to every responsible entity in the sector and set the shape the regulation follows: CISO, policy, asset register, six-monthly audits, incident reporting, trusted sources. They remain the operative audit framework until the regulation commences.

Testing of power-system equipment

MoP Order 12/13/2020-T&R; CEA Regs 5(23), 6(5)

A Ministry of Power order of July 2020 required imported power-supply equipment to be checked for malware and imports from prior-reference countries to have prior permission. Orders of 8 June 2021 and 24 December 2021 then required cyber security testing of specified equipment — RTUs, PLCs, IEDs, smart meters — at designated Indian laboratories such as CPRI. The regulation requires compliance with such orders for OT equipment, components and parts.

Connectivity, communication and grid code

CEA Connectivity (Amendment) Regulations, 2019, Reg 10; CEA Communication System Regulations, 2020, Reg 14; IEGC 2023, Regs 48–49

Regulation 10 of the CEA connectivity standards, inserted in February 2019, requires every requester and user — including solar and wind generators — to comply with Central Government cyber security guidelines. The CEA communication-system standards of 2020 require a cyber risk programme at every control centre and connected user, and the Indian Electricity Grid Code, 2023 requires a cyber security framework and audit in line with the 2021 Guidelines.

Trusted sources

CEA Regs 5(39), 6(7) — deferred

Procurement of IT and OT equipment and services from trusted sources, as defined by Central Government orders, is written into the regulation but deferred to a later commencement date.

IEC 62443 and ISO/IEC 27001

The regulation names ISO/IEC 27001 and does not name IEC 62443. In practice both matter: 27001 is the management system the regulation will certify against, and 62443 is the series the Bureau of Indian Standards has adopted as Indian Standards for the security of industrial automation and control systems — the vocabulary of zones, conduits and security levels that trust-level segmentation is audited in.

ISO/IEC 27001 for critical systems

CEA Reg 5(24) — deferred

An ISO/IEC 27001 certificate, or a Technical Criteria Certificate, encompassing all critical systems; no four consecutive certification audits by the same agency. Deferred to a date the Authority will set.

IEC 62443 as Indian Standards

BIS; CEA Reg 6(8)

BIS has adopted the IEC 62443 series as Indian Standards (IS/IEC 62443; IS 16335 in the 2021 Guidelines). The regulation's requirement to segment OT into trust levels by criticality and risk is, in 62443 terms, zones and conduits with target security levels.

CERT-In's 15 elemental controls

CEA Reg 2(1), second proviso

For power entities under 50 MW — and as a floor for any small operator — the regulation points to CERT-In's 15 Elemental Cyber Defense Controls for MSMEs.

Beyond the power sector

Outside electricity, India has no sector-specific OT cyber security regulation in force as of September 2026. The CERT-In Directions and the protected-system provisions of the IT Act carry the load, with sector regulators moving at different speeds.

Oil and gas

PNGRB Action Plan 2026–27

The Petroleum and Natural Gas Regulatory Board's action plan for 2026–27 commits to a baseline cyber security framework for regulated entities. Refineries and pipelines fall within the sector NCIIPC covers, and captive power at 50 MW or more is in scope of the CEA regulation.

Renewables and rooftop solar

MNRE, 2025–26 — as reported

Utility-scale solar and wind are generating companies under the CEA regulation. For rooftop systems under PM Surya Ghar, the Ministry of New and Renewable Energy has moved in 2025–26 to require inverter communication devices to connect to, and hold data on, servers in India.

Water and wastewater

No sector rule. Obligations come from the IT Act and CERT-In Directions, from state water boards and urban local bodies, and from the contracts under which schemes are built and run.

Manufacturing

No OT-specific rule. The CERT-In Directions, the Digital Personal Data Protection Act, 2023 for personal data, and good-manufacturing-practice data integrity in pharma apply; captive power at 50 MW or more is in scope of the CEA regulation.

Rail, metro, ports and airports

Transport is a sector NCIIPC covers. Indian Railways applies its ICT Security Policy of 2019 and RDSO guidance; Indian-flag ships have carried cyber risk in their safety management systems since DG Shipping's 2017 circular under IMO resolution MSC.428(98); ports sit with the Ministry of Ports, Shipping and Waterways and the port authorities under the Indian Ports Act, 2025; airports with BCAS and the Airports Authority of India.

Smart cities

CERT-In's Cyber Security Guidelines for Smart City Infrastructure of March 2025 cover integrated command and control centres, ICS and IoT, and tie logging back to the 2022 Directions.

Data centres

Named directly in the CERT-In Directions. Building management, cooling and power systems are OT in the same sense as any plant.

Where the obligation landsin ASTRICS.

ASTRICS was shaped around this regime. Each obligation below is met from the same operational understanding, recomputed continuously — not reconstructed the week before an audit.

ObligationIn ASTRICS
Cyber asset register with ownership, firmware, software, patch, configuration and data flows, reviewed every year or on commissioning
Reg 5(25)
Asset Inventory holds each field as a first-class column and tracks completeness against it. The Asset Passport carries the lineage.
Systems classified as critical and non-critical; register classified by criticality and risk
Regs 5(16), 8(4)
Criticality is a first-class attribute, derived from the process and business context the asset supports.
Risk assessment and mitigation plan updated every six months
Reg 5(26)
The Risk Queue ranks by consequence and is a live state, so the six-monthly plan is a report, not a project.
OT segmented into trust levels; IT and OT isolated; control traffic confined to India
Regs 6(1), 6(3), 6(8)
Zones & Conduits declares the trust levels and tests them continuously against observed traffic. Each mismatch becomes a dated finding.
Remote access only for troubleshooting and emergencies, with MFA, least privilege, minimum duration and geo-fencing
Regs 5(17), 8(15)
Remote sessions are observed, attributed to a named vendor and checked against the window they were approved for.
Incidents reported to CSIRT-Power and CERT-In within six hours
Reg 7(3)(a)
The statutory incident workflow assembles the submission from context already held, with the clock running inside the platform.
Critical and high findings closed within one month of the audit report
Reg 13(3)
The Compliance Console puts each finding on its statutory clock and counts it down, with compensatory controls recorded.
Details of new critical systems to CSIRT-Power within thirty days
Reg 5(28)
Commissioning changes are recorded in the register with their lineage, so the notification is generated rather than assembled.
Audit every nine to fifteen months; evidence the auditor can rely on
Regs 5(22), 13
The auditor bundle — register, verdicts, lineage and closures — is generated from the same model the engineers use.
Native logging and 180-day retention under the CERT-In Directions
CERT-In Directions, 2022
Events & Syslog: native collection, retention and correlation on the asset model, with no second logging product.

Questions operators ask

Is the CEA cyber security regulation in force?

It was notified in the Gazette of India on 31 July 2026 and comes into force on 1 April 2027, for existing as well as upcoming infrastructure. Six provisions — the 24×7 security division, ISO/IEC 27001 certification, mandatory courses, trusted-source procurement for IT and for OT, and OT perimeter devices — start on later dates the Authority will set by separate order.

Does it apply to a solar or wind plant?

Yes, where the generating company's installed capacity is 50 MW or more. Renewable generators are not treated separately; they are generating companies. Energy storage owners have the same threshold. Below 50 MW an operator is encouraged to adopt CERT-In's 15 elemental controls.

What is the difference between CSIRT-Power and CERT-In?

CERT-In is the national incident response agency under the IT Act; its Directions of April 2022 bind every body corporate. CSIRT-Power is the power sector's own team, set up by the Ministry of Power at the CEA as an extended arm of CERT-In. The regulation makes CSIRT-Power the nodal agency for the sector and requires incidents to be reported to both, within the same six hours.

Does the regulation require IEC 62443?

No — the text names ISO/IEC 27001 and does not name IEC 62443. It does require the OT environment to be segmented into trust levels by criticality, security requirements and risk assessment, which is what IEC 62443 calls zones and conduits with security levels. BIS has adopted the IEC 62443 series as Indian Standards, and it is the vocabulary most audits will use.

What is a protected system?

Under section 70 of the Information Technology Act, the appropriate government can notify a computer resource that is critical information infrastructure as a protected system. Access is then restricted to authorised persons and unauthorised access carries higher penalties. The CEA regulation requires power entities to give NCIIPC the information to identify such assets and to apply for notification within sixty days.

Our plant is under 50 MW. Do we have anything to do?

The CEA regulation encourages, rather than requires, plants under 50 MW to implement CERT-In's 15 elemental cyber defence controls. The CERT-In Directions still apply in full — six-hour reporting, 180 days of logs in India, NTP synchronisation — because they bind every body corporate.

What does the regulation say about vendors overseas?

Remote operation of OT must take place within India with the prior approval of the head or board, over a channel isolated from the internet. Remote access more generally is permitted only for troubleshooting and emergencies, under a procedure with minimum duration, least privilege, multi-factor authentication and geo-fencing. Control and real-time data must stay within national boundaries except through a unidirectional gateway.

Primary sources

Summaries of the notified texts as we read them. Orientation, not legal advice — check the Gazette or the direction before you rely on a clause.

See ASTRICS against your own environment.

Book a walkthrough with the ASTRICS team and bring one site's worth of questions.