The Ministry of Power notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, on July 31, 2026. These rules will come into effect on April 1, 2027, aiming to strengthen cybersecurity across the power sector. A new Computer Security Incident Response Team for the Power Sector (CSIRT-Power) will be established under the Ministry to coordinate incident reporting and response, issue alerts, and set cybersecurity benchmarks, according to medianama.com.
The CSIRT-Power will have the authority to request network architecture details, asset information, logs, and forensic records from power sector entities and vendors. Its primary responsibilities include vulnerability analysis, prediction of cybersecurity incidents, collaboration with CERT-In and NCIIPC, and issuing mandatory alerts and advisories. The directives issued by this team will have legally binding status for all entities and vendors in the sector, ensuring compliance with cybersecurity standards.
This regulatory move addresses increasing cyber threats targeting critical infrastructure in India’s power sector. The establishment of CSIRT-Power aligns with global trends where sector-specific cybersecurity agencies coordinate incident responses and threat intelligence. The binding nature of the directives marks a shift from advisory frameworks to enforceable cybersecurity governance, potentially reducing vulnerabilities and improving resilience against cyberattacks in the energy domain.
The Central Electricity Authority’s regulations will officially take effect on April 1, 2027, marking the start of mandatory compliance for all power sector entities and vendors. The CSIRT-Power will begin coordinating cybersecurity efforts from that date, with the goal of enhancing the sector’s cyber defense capabilities.