Draft CEA Cybersecurity Regulation 2024: A Step to Secure India’s Power Sector
Compliance / GRC
GRC

Key Takeaways
- What CSIRT-Power is and why it matters: the sector's central point of contact for incidents, operating since April 2023, with sectoral CERTs for thermal, hydro, transmission, distribution, grid operations and renewables.
- Which 2 roles the draft makes you name on paper: a CISO and an Alternate CISO, with minimum qualifications and security documents handled as per IS 16335.
- Where IT and OT part company in the draft: separate audit cadences, physical and logical segregation between the 2 domains, and tighter remote access rules on the OT side.
- What vendors owe you once the draft applies: security updates and patches across the product lifecycle, and formal notice of end of life and end of support.
The draft runs 13 chapters, from general provisions to CII identification, and it reaches everyone in the chain: generating companies, transmission and distribution licensees, control centres, and the vendors and contractors who supply them. Skimming it tells you it is important. It does not tell you what to do on Monday.
That is the gap this whitepaper closes. Each chapter gets a short, plain-words insight naming what it requires and of whom, followed by a high-level checklist you can walk your own programme through. No clause numbers to decode, no legal phrasing to untangle.
What the 13 pages cover
Look inside












