The Ministry of New & Renewable Energy (MNRE) has directed all wind turbine manufacturers listed under the Approved List of Models and Manufacturers (ALMM) to submit reports on their cybersecurity compliance by August 31. The order mandates that data centres and servers be located in India, with all wind turbine data stored and maintained domestically. Operational control must also be conducted exclusively from Indian facilities, according to medianama.com.
This directive follows a draft amendment issued on April 17, 2025, under the Revised List of Models and Manufacturers of Wind Turbines (RLMM). The amendment requires manufacturers to prohibit transferring real-time operational data outside India and to establish research and development centres within the country by January 31, 2026. The Ministry's move aims to tighten cybersecurity protocols amid rising concerns over foreign cyber threats, as detailed by medianama.com.
The order comes in the context of increasing cyberattacks targeting critical infrastructure, including a recent incident on August 24 involving Iran. By enforcing data localization and operational controls within India, the government seeks to safeguard the renewable energy sector from potential cyber vulnerabilities. This aligns with broader national security efforts to protect key energy assets and critical data, according to medianama.com.
Manufacturers must comply with these requirements and submit their status reports by the end of August. The Ministry's enforcement of these cybersecurity measures is expected to impact all wind turbine makers on the ALMM list, reinforcing India's commitment to securing its renewable energy infrastructure.