MaxZen Energy Advisory | Regulatory & Compliance | 11 min read
The Central Electricity Authority notified the CEA (Cyber Security in Power Sector) Regulations, 2026 on 31 July 2026. For industrial groups operating captive generating plants of 50 MW and above, the regulations come into force from 1 April 2027.
And the hardest part of compliance is not a firewall.
It is deciding who owns the responsibility, rewriting contracts that may have been signed years ago, and redesigning the way plant operational technology is connected, hosted and accessed.
Three numbers tell the immediate story:
50 MW — the threshold for captive generating plants.
15 years — minimum experience required for the CISO.
6 hours — the incident-reporting window to CSIRT-Power and CERT-In.
The regulations therefore move captive power cyber security from an IT-policy issue into an operational and Board-level risk-management issue.
1. First question: Is your captive plant covered?
Regulation 2(1)(a) applies the framework to entities owning, operating or managing operational technology infrastructure connected to the interconnected power system, together with connected IT infrastructure.
For generating companies, captive generating plants and organisations with energy storage systems, the regulation applies where installed capacity is 50 MW or more.
This creates an important distinction for industrial consumers.
An electricity consumer that only purchases power through open access is not listed as an “entity” under Regulation 3(1).
But an industrial consumer operating a 55 MW captive generating plant is within the regulatory framework.
The threshold should therefore be tested against the relevant generating or storage asset and documented formally. Capacity additions should trigger a fresh assessment.
Applicability at a glance
| Asset / entity | Threshold | Position |
| Captive generating plant | ≥50 MW | Covered |
| Generating company | ≥50 MW | Covered |
| Energy storage system | ≥50 MW | Covered |
| Transmission / distribution licensees | No capacity floor | Covered |
| Load despatch centres | No capacity floor | Covered |
| Power exchanges / OTC platforms | No capacity floor | Covered subject to specified provisions |
| Open-access electricity consumer with no generation | Not applicable | Not covered merely as a consumer |
Important: The notified text uses “installed capacity”. Where units or stations sit close to the 50 MW threshold, the exact applicability should be confirmed against the notified text and, where necessary, regulatory or legal advice.
2. 1 April 2027 does not mean every provision starts on that date
One of the most important points in the notification is also one of the easiest to miss.
Six provisions have been deferred:
- Regulation 5(9) — dedicated 24×7 Information Security Division
- Regulation 5(24) — ISO/IEC 27001 or specified technical certification
- Regulation 5(33) — specified cyber-security training for personnel
- Regulation 5(39) — trusted-source IT procurement
- Regulation 6(2) — specified perimeter cyber-security appliances
- Regulation 6(7) — trusted-source OT procurement
These provisions will commence on dates separately specified by the Authority, with prior approval of the Central Government.
As of 15 August 2026, no such separate commencement order had been issued.
The distinction matters.
These provisions are deferred, not cancelled. Industrial groups should therefore avoid treating the deferral as permanent regulatory relief.
The provisions that are already scheduled to apply from 1 April 2027 include the CISO framework, cyber-security policy, crisis management plan, asset register, risk assessment, annual audit, incident reporting, OT/IT isolation, data residency, vendor requirements and self-audit obligations.
3. The scarce resource may be a person, not technology
For many industrial organisations, the most difficult requirement may be Regulation 7(1).
The CISO must be:
- An Indian citizen and resident
- An engineering or equivalent graduate from a recognised institution
- Experienced for at least 15 years in the power sector or IT
The role is also required to be confined to cyber-security matters, while the appointment carries a minimum three-year tenure.
This has a practical consequence.
Many industrial groups do not currently have an employee who meets all these requirements and can be ring-fenced exclusively for cyber-security responsibilities.
The market for suitably qualified people will therefore become an important compliance constraint as multiple covered entities prepare for the same deadline.
This is why the CISO question should not be left to the final quarter before April 2027.
4. The expensive compliance clauses may already be sitting inside your vendor contracts
This is where the regulation intersects directly with plant operations.
A captive plant typically depends on a large technology ecosystem:
- DCS
- SCADA
- PLCs
- turbine control systems
- protection systems
- energy-management systems
- historians
- remote diagnostic platforms
- system integrators
- OEMs
- cloud and analytics providers
Regulation 5(20) requires vendor SLAs to incorporate applicable cyber-security requirements and confidentiality obligations.
Regulation 11 goes further for vendors associated with critical systems. Requirements include documented restoration procedures, digitally signed or validated security patches, end-of-support and end-of-life disclosure, a Bill of Materials, pre-supply hardening and vulnerability-reporting processes.
Consider a DCS contract signed in 2019.
It may have been commercially adequate when signed. But if it does not provide the restoration, patching, lifecycle and cyber-security commitments now required, the organisation may have a contractual gap.
That makes every AMC renewal, retrofit order and control-system procurement between now and April 2027 an opportunity to introduce the required clauses.
Waiting until the regulation becomes operational is likely to be the more expensive route.
5. Six-hour incident reporting changes the operating model
The regulations require cyber-security incidents to be reported within six hours to CSIRT-Power and CERT-In.
Cyber sabotage involving a critical system carries a 24-hour reporting requirement.
This means compliance cannot be reduced to an annual audit.
A plant needs a functioning detection, escalation and decision-making process.
For an industrial captive plant, the practical question is not merely:
“Do we have cyber-security controls?”
It is:
“If a cyber incident occurs at 2:00 AM during a plant disturbance, who detects it, who decides whether it is reportable, who informs the CISO, and who makes the six-hour submission?”
That operating model needs to be established before the regulation takes effect.
6. OT–IT separation and Indian data residency will affect digitalisation plans
The regulations also create an important constraint on the way industrial energy systems are being digitised.
Regulation 5(19) requires sensitive information and data, including cloud-hosted and historical data, to reside in India in an encrypted and protected environment.
Regulation 6(1) requires OT systems to be physically isolated from the internet and IT systems. Where business requirements make physical separation infeasible, logical separation is permitted subject to specified controls, risk assessment, approval and continuous monitoring.
Regulations 6(3) and 6(4) further address dedicated communication channels, real-time data exchange and remote operation. Remote operation, where permitted for business reasons, requires prior approval and must be undertaken from within India.
This does not mean that industrial companies must abandon cloud-based energy analytics.
It means that the architecture must be designed around the regulatory boundaries.
For example, an industrial group planning a new:
- Energy Management System
- plant historian
- condition-monitoring platform
- predictive-maintenance solution
- OEM remote-diagnostics system
- energy analytics platform
should address data location, OT–IT segregation and remote access during specification, rather than attempting to retrofit compliance after implementation.
This is fundamentally a design problem before it becomes a retrofit problem.
7. What could compliance cost?
The regulation does not prescribe a single compliance cost.
The economics will depend heavily on the plant’s existing cyber maturity, control-system vintage, OT architecture, hosting arrangements, vendor contracts and organisational structure.
An illustrative MaxZen assessment for a 90 MW captive station operating at an 80% PLF estimates:
| Component | One-time | Annual |
| OT/IT separation and perimeter architecture | ₹120 lakh | — |
| India-resident data migration | ₹25 lakh | — |
| Asset register, risk assessment, policies | ₹20 lakh | — |
| Dedicated CISO | — | ₹45 lakh |
| Alternate CISO | — | ₹10 lakh |
| Annual third-party audit | — | ₹20 lakh |
| VAPT / new critical systems | — | ₹6 lakh |
| India-resident hosting / backup | — | ₹8 lakh |
| Training | — | ₹4 lakh |
| Mock drills | — | ₹3 lakh |
| Total | ₹165 lakh | ₹96 lakh |
Amortising the one-time expenditure over five years produces an annualised compliance cost of approximately ₹129 lakh, or around 2.0 paise/kWh for the illustrative 631 MU generation.
If the deferred 24×7 Information Security Division is subsequently brought into force, the illustrative cost rises to approximately 3.8 paise/kWh.
These are illustrative MaxZen estimates, not regulatory benchmarks or market quotations. Actual costs can vary materially by plant configuration and existing infrastructure.
The important conclusion is therefore not the exact paise-per-unit number.
For a large captive plant, the direct compliance cost is unlikely to materially change the economics of power sourcing.
The bigger issue is operational resilience and governance.
8. The enforcement risk is broader than the statutory penalty
Section 142 of the Electricity Act, referenced through Regulation 16, provides for penalties of up to ₹1 lakh per contravention and up to ₹6,000 for every day the failure continues.
But the more consequential compliance mechanism may be the audit trail.
The regulations require:
- Annual cyber-security audits
- Defined timelines for audit reports
- Closure of critical/high findings within one month
- Closure of medium/low findings within three months
- Annual self-audit
- Board/senior-management accountability
- Potential third-party re-audit at the entity’s cost
The result is a formal, recurring record of cyber-security compliance.
That record could become relevant not only to the regulator, but also after a significant incident and potentially in discussions with insurers, lenders or acquirers.
9. What should C&I consumers do now?
For an industrial group with a captive plant or large energy-storage asset, we recommend a phased approach.
Within 30 days
1. Determine applicability
Map every generating and storage asset against the 50 MW threshold.
Document the basis of the determination.
2. Identify CISO and alternate CISO candidates
Test internal resources against the citizenship, residency, qualification and 15-year experience requirements.
If the organisation does not have suitable candidates, begin the external search.
Within 90 days
3. Review critical technology contracts
Review DCS, SCADA, PLC, protection, EMS, turbine-control and other critical-system contracts against Regulations 5(20) and 11.
Insert required cyber-security clauses at renewal, amendment or new procurement.
4. Map data locations
Identify where operational, historical and cloud-hosted plant data is physically stored.
Flag any sensitive data residing outside India.
Within 365 days
5. Build the cyber asset register and risk assessment
Create the required asset inventory and risk-management framework.
Conduct a voluntary audit or dry run before the mandatory regime begins.
6. Budget for the deferred provisions
Even though the six provisions are not currently scheduled for 1 April 2027, the FY 2027-28 budget should account for the possibility that they are activated through subsequent orders.
MaxZen Perspective
The market is largely reading the 2026 regulations as a grid-security regulation.
For industrial companies, that is only part of the story.
A captive power plant is an operational asset whose availability directly affects production. Once cyber-security requirements begin influencing OT architecture, remote operation, data flows, vendor access and restoration procedures, cyber risk becomes inseparable from plant availability risk.
That means the compliance programme should not sit entirely within the IT function.
Electrical engineering, instrumentation, plant operations, IT/OT, procurement, legal, risk management and senior management need to work from the same compliance roadmap.
Our view is straightforward:
The compliance cost is manageable. The organisational transition is not.
The scarce resource is likely to be the qualified CISO. The contractual risk sits inside existing OEM and system-integrator relationships. And the architectural constraints are easiest to solve when new systems are being specified—not after they have already been commissioned.
For a 50 MW-plus captive plant, the right question is therefore not:
“How much will cyber compliance cost?”
It is:
“Can we make our plant’s cyber-security architecture, people, contracts and operating procedures compliant without compromising availability?”
That work should begin well before 1 April 2027.
Frequently Asked Questions
Our captive plant is 48 MW. Are we covered?
No, based on the notified threshold. The regulations apply to captive generating plants at 50 MW and above. Below that threshold, adoption of CERT-In’s 15 Elemental Cyber Security Controls for MSMEs is encouraged rather than mandated under these regulations.
The position should be reassessed whenever capacity is added.
We buy power through open access but own no generation. Does this apply to us?
Not merely because you are an electricity consumer. Regulation 3(1) does not list electricity consumers among the covered entities.
Coverage can arise through ownership of qualifying generation or energy-storage assets.
Can our group CIO or IT Head also serve as the CISO?
Not automatically.
The CISO role is required to be confined to cyber-security matters, with the prescribed senior-management, tenure and qualification requirements. Regulation 7(1) requires Indian citizenship and residence, an engineering or equivalent degree and at least 15 years of experience in the power sector or IT.
Is the 24×7 Information Security Division required from 1 April 2027?
No, not based on the notified commencement position as of 15 August 2026.
Regulation 5(9) is one of the six provisions deferred to a separate commencement order requiring prior Central Government approval.
However, industrial groups should budget for it rather than assume that the deferral is permanent.
Do we have to move our energy analytics off the cloud?
Not necessarily.
The regulations require sensitive data, including cloud-hosted and historical data, to reside in India and be appropriately protected.
The requirements become more restrictive where control, real-time operation or remote operation of power-system elements is involved.
What to Watch Next
The compliance roadmap is not static. Industrial consumers should watch for:
- CEA orders activating the six deferred provisions.
- The order determining commencement for Regulation 12’s application to existing distributed-generation installations.
- Any additional CISO qualification requirements.
- Cyber-security audit guidelines and detailed scope from CSIRT-Power.
- The incident-recording format under Regulation 5(42).
- Designation of sub-sectoral CSIRTs under Regulation 4(4).
- Any industry or regulatory movement around the interpretation of the 50 MW threshold.
- Applications for relaxation under Regulation 17.
About MaxZen Energy Advisory LLP
MaxZen Energy Advisory LLP is an independent energy consulting and advisory firm working with large commercial and industrial electricity consumers on power sourcing and portfolio strategy, open access and renewable integration, regulatory compliance, energy cost optimisation and plant electrical systems.
MaxZen Energy Advisory LLP
Powering Decisions. Delivering Outcomes.
This article is provided for general information and does not constitute regulatory, legal or financial advice. Illustrative figures are indicative only. Readers should evaluate their specific circumstances and applicable regulations before acting.
