Skip to main content

      This article was first published on August 31 2026 in The Economic Times CISO.com. Please click here to read the article.

      The notification of the Central Electricity Authority (CEA) Cyber Security in Power Sector Regulations, 2026 marks a watershed moment in India's efforts to strengthen the security of its critical infrastructure.

      The power sector is undergoing an unprecedented transformation. Rapid digitalisation, the integration of renewable energy sources, increasing deployment of smart grid technologies, and growing interconnectivity across operational systems have created significant opportunities for efficiency and innovation. At the same time, they have expanded the cyber risk landscape facing utilities and energy operators.

      Against this backdrop, the new regulations represent much more than a compliance mandate. They establish a structured and enforceable framework for cyber resilience across India's power ecosystem, reflecting the increasing recognition that cyber security is integral to operational reliability, business continuity, and national security.

      One of the most significant features of the regulations is the acknowledgment that cyber security is a shared responsibility. While power generation, transmission, and distribution entities remain central to implementation, the regulations extend accountability across the broader ecosystem, including original equipment manufacturers (OEMs), system integrators, technology vendors, managed service providers, cloud providers, and other supply chain participants.

      This broader approach reflects the reality of today's threat landscape. Cyber vulnerabilities are often introduced through interconnected technologies, third-party software dependencies, remote access mechanisms, or supply chain relationships. Securing the sector therefore requires collaboration across the entire value chain rather than isolated efforts by individual utilities.

      A rationalised approach to OT security

      A notable development is the introduction of a 50 MW applicability threshold for generation companies, captive power plants, and energy storage systems. This reflects a practical and risk-based approach to regulation.

      By focusing compliance requirements on larger and systemically significant assets, the framework seeks to balance operational realities while ensuring that critical infrastructure remains subject to rigorous oversight. Such an approach allows regulators and organisations alike to prioritise resources where cyber incidents could have the greatest impact on grid stability and public services.

      Operational technology security takes centre stage

      Historically, many organisations have concentrated cyber security investments on enterprise IT systems. However, recent cyber incidents globally have demonstrated that adversaries increasingly target industrial control systems and operational technology (OT) environments.

      The new regulations place considerable emphasis on asset inventories, network segmentation, trust zones, secure communications, remote access controls, continuous monitoring, and incident response capabilities. These requirements underscore the growing need to secure the systems that directly support power generation, transmission, and distribution operations.

      For many organisations, this will necessitate a shift from traditional perimeter focused security models towards more comprehensive cyber resilience strategies that integrate both IT and OT environments.

      Supply chain security emerges as a strategic priority

      Perhaps one of the most consequential aspects of the regulations is the increased focus on supply chain cyber security.

      Requirements relating to trusted sources, Bills of Materials (BOMs), Software Bills of Materials (SBOMs), cyber security validation during Factory Acceptance Testing (FAT) and Site Acceptance Testing (SAT), vulnerability disclosure, lifecycle support, and patch management signal a major evolution in regulatory expectations.

      Strengthening preparedness and response

      The regulations also introduce more structured expectations around vulnerability management and incident preparedness.

      Organisations are expected to establish stronger processes for vulnerability monitoring, remediation, cyber incident reporting, forensic readiness, and coordination with sectoral authorities. These measures align with global trends that increasingly emphasise rapid detection, timely disclosure, and coordinated response mechanisms.

      In an environment where cyber threats continue to grow in sophistication and frequency, resilience depends not only on preventing incidents but also on responding effectively when they occur.

      Data sovereignty gains importance

      A notable feature is the expansion of data localisation requirements. The regulations extend expectations beyond live operational data to include sensitive historical information. As cloud adoption accelerates across industries, power sector organisations may need to reassess data governance frameworks, storage architectures, retention policies, and national infrastructure.

      Supporting a digitally enabled energy future

      The regulations arrive at a time when the power sector is evolving rapidly. Energy storage systems, distributed energy resources, inverter ecosystems, cloud enabled solutions, advanced communication networks, and digital operational platforms are becoming fundamental components of the modern energy landscape.

      The challenge for policymakers and industry leaders is to balance innovation with security. The CEA regulations seek to address risks arising from growing digital convergence while supporting India's broader energy transition and modernisation agenda.

      Beyond compliance

      The implementation journey will undoubtedly require investment, coordination, and sustained effort across the sector. Yet organisations that approach these regulations solely as a compliance exercise risk missing a larger opportunity.

      Cyber resilience is increasingly becoming a competitive differentiator. Utilities and energy companies that proactively strengthen governance, modernise security architecture, improve visibility across operational environments, and build cyber-ready supply chains will be better positioned to maintain operational continuity, protect stakeholder trust, and navigate future risks.

      The power sector forms the backbone of India's economic growth and national development. As cyber threats continue to target critical infrastructure around the world, the CEA Cyber Security Regulations 2026 provide a crucial foundation for building a more secure, resilient, and future-ready energy ecosystem.

      Operational resilience and cyber resilience are now inseparable. As industrial environments become increasingly connected, organisations must move beyond traditional security approaches and embed cyber resilience into the design, operation, and lifecycle of critical systems. Effective OT security is fundamental to ensuring safe, reliable, and sustainable operations in an increasingly digital world.

      Sony Anthony

      Partner and Head of Department – Cyber Defence and Incident Response

      KPMG in India


      The CEA Cyber Security Regulations 2026 elevate OT security from a technical requirement to a strategic business imperative. The future of grid resilience is inseparable from cyber resilience with increasing interconnectivity across and digital operations. Organisations that proactively strengthen OT governance, secure their supply chains, and modernise cyber defenses will be better positioned to protect critical services and build stakeholder confidence in an increasingly connected ecosystem.

      Anish Mitra

      Partner

      KPMG in India

      Author

      Srinivas Potharaju

      Partner, Head of Cyber Security and Technology

      KPMG in India



      KPMG named a “Leader” in the IDC MarketScape for Worldwide OT Security Services


      IDC recognizes KPMG member firms for their lifecycle OT security services, combining deep operational expertise, structured delivery, and advanced innovation

      How can KPMG in India help

      Supporting organisations with integrated cyber security solutions that strengthen resilience, trust, and business continuity

      Transformation driven by data, enabled by digital technology, and led by business initiatives

      Building cyber resilience in an AI-driven threat landscape

      KPMG Insights Edge

      KPMG Insights Edge

      On the go access to KPMG in India’s insights and publications