What the CEA Regulations Actually Impose, and by When
The Central Electricity Authority published the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 in the Gazette of India on 31 July 2026, as reported by Renewable Watch on 14 August 2026. The mandatory provisions come into full effect from 1 April 2027, which leaves covered entities roughly an eight-month implementation window from the point the industry began reading the text, according to the Shieldworkz compliance guide to the regulations.
Three obligations matter most for anyone buying or placing insurance on a generating station, a transmission licensee or a distribution utility:
- Cyber incidents must be reported to CSIRT-Power within six hours, as reported by SolarQuarter on 14 August 2026.
- A responsible cyber security officer has to be named, which turns a governance preference into a named role with an accountable holder.
- Operational technology networks have to be kept separated from IT networks, which turns an architecture recommendation into a duty that a regulator can inspect against.
Each of those three lands on a clause in a standard Indian cyber policy wording that was drafted for a different kind of insured. The notification condition assumes days. The warranty machinery assumes a described control state that stays true for the policy year. The insuring agreement assumes the insured's exposure is data. A thermal station, a hydro plant or a state transmission utility fails all three assumptions.
The regulations also create a documented, dated, externally verifiable record of what a power sector entity said about its own controls. That record will be read by an underwriter at renewal and by a claims manager after a loss.
A Generating Station's Cyber Loss Is a Physical Loss
Indian cyber wordings grew out of privacy exposure and financial crime, and the insuring agreements split into breach response, third-party liability, and cyber extortion with business interruption. That structure fits a bank or a BPO, where the IT estate is the business and the loss is information.
For a power sector entity the loss looks nothing like that. An intrusion that reaches a distributed control system, a SCADA master or a protection relay does not produce a notification exercise. It produces a unit trip, a deviation from schedule, and in the worst case mechanical damage to a turbine, generator or transformer that no forensic vendor can put right.
That distinction determines recovery. The question is whether the loss arises from data or from plant that stopped, whether the resulting damage is electronic or mechanical, and whether the policy that responds to mechanical damage excludes the cause while the policy that responds to the cause excludes the damage.
The generation and transmission risk profile is already unusual on the property side, as set out in our note on power and energy sector insurance risks in India. A cyber trigger layered onto that profile mostly exposes the seams between the policies already in place.
The regulations do not create insurance obligations. They create factual obligations that insurance clauses were written to test, and a gap that was theoretical while separation was optional becomes concrete once separation is a duty the insured has certified it meets.
Six Hours to CSIRT-Power Against a Notification Clause Measured in Days
The six-hour reporting requirement to CSIRT-Power sits alongside the existing CERT-In regime that power sector entities already work to. It does not sit alongside the policy notification condition, because that clause almost never runs on hours.
A typical Indian cyber wording requires notice to insurers as soon as practicable, often within a stated period after the insured's designated officer becomes aware of a circumstance, commonly seventy-two hours and sometimes seven days. The practical effect is that the regulatory filing goes out first and the insurer hears about the incident second, from a company that has already committed a set of facts to a government body in writing.
That sequence creates three specific risks.
The filing becomes part of the claim file. Whatever is written to CSIRT-Power in hour five will be read later by a loss adjuster and quite possibly by the insurer's coverage counsel. A filing that speculates on root cause, names a threat actor, characterises the intrusion as an insider act, or estimates a loss quantum before anybody has counted anything, gives the insurer language it did not have to draft itself. The discipline is to file observed facts and nothing else: what was seen, when, on which systems, and what was done in response.
The clocks are measured from different events. The regulatory clock starts on detection of an incident as the regulation defines it. The policy clock often starts on the insured's awareness of a circumstance likely to give rise to a claim. Those are not the same moment, and a claims manager who assumes they are will report late on one of the two. The fix is a written internal protocol that treats detection as the trigger for both, so the six-hour regulatory clock also starts the insurance clock.
The incident response panel may not be usable in six hours. Most cyber policies require use of a panel forensic vendor, or prior consent to a non-panel vendor, before response costs are covered. A six-hour duty means the first hours go to triage and the filing, not to procurement approvals. Pre-agree the panel vendor and the out-of-hours escalation contacts at inception. The reporting overlap is treated in detail in CERT-In incident reporting and insurance.
A Named CISO Turns Governance Into a Warranted Fact
Once the regulations require a named cyber security officer, the answer to the proposal-form question about security governance stops being a description and becomes a verifiable statement about an identified person holding an identified role.
Indian cyber proposal forms already ask about patching cadence, multi-factor authentication, backup regime, network segmentation and incident response testing. Insurers increasingly attach the completed proposal to the policy as the basis of the contract, or impose a minimum-security condition precedent requiring the described controls to remain in place through the period. Where that language appears, the difference between an aspiration and a fact matters at claim stage rather than at inception, and Indian insurance law's duty of utmost good faith applies to what was represented, not to what was intended.
The exposure runs in both directions. If the officer has not been appointed and the proposal form answer implies otherwise, the insurer has an argument on the whole policy rather than on one head of loss. If the officer has been appointed and the mandate documented, that is an underwriting asset worth bringing to the renewal meeting with the appointment record, the reporting line and the escalation matrix.
OT and IT Separation Cuts Both Ways in Underwriting
Separation of operational technology from IT networks is the control an underwriter most wants to see on a power sector risk, because it limits how far an office-network intrusion can travel. The regulations make it a duty, which has two consequences for a placement that pull in opposite directions.
The favourable one is pricing and capacity. An entity that can evidence segmentation, separate credential stores, controlled remote access for OEM vendors and monitoring on the OT side is a materially different risk from one running a flat network, and that evidence supports both a lower rate and a higher limit.
The unfavourable one is the argument it hands an insurer. Once segmentation is a regulatory requirement and a warranted control, an intrusion that crossed from IT into OT is prima facie evidence that the described control failed. The insurer's question stops being whether the loss is covered and becomes whether the control the insured warranted was in place at the time.
What to ask for in the wording
- A segmentation condition drafted against a described architecture, with a named reference document and version, rather than an open-ended requirement to maintain effective segregation.
- An express carve-back so that a control failure affects only the head of loss it caused, rather than voiding the policy.
- Written acknowledgement of the transitional position. The mandatory provisions bite from 1 April 2027, and an entity midway through remediation should have that disclosed and accepted in writing, not assumed to be tolerable.
The same failure pattern in a manufacturing setting is worked through in Bajaj Auto's ransomware disclosure and the OT gap, where the definition of computer system does most of the work.
Where Cyber Cover Stops and the Property Programme Starts
A power sector cyber loss has an unusual habit of ending in physical damage. A malicious command to a governor control, a relay setting change, or the loss of a cooling or lubrication interlock can damage rotating plant, which puts the loss on the boundary between two programmes bought separately and often from different insurers.
Standard Indian cyber wordings exclude physical loss or damage to tangible property. Standard fire and engineering wordings exclude loss caused by a cyber act, or cover it only through a narrow write-back. Between the two sits the exposure that a generating station actually carries.
The three clauses to read together before the next renewal:
- The tangible property exclusion in the cyber policy, and whether there is a write-back for material damage resulting from a covered cyber event.
- The cyber exclusion in the fire and machinery breakdown sections, and how broadly it is drafted. A blanket exclusion for any loss arising from a cyber act removes far more than a malicious-attack exclusion does.
- The business interruption trigger in each policy. Cyber business interruption generally responds to an interruption of computer systems. Property business interruption generally responds to insured physical damage. An event that produces neither in the way the wording defines it produces a gap rather than a dispute.
Waiting periods deserve separate attention on generation risk. A twenty-four to seventy-two hour waiting period on cyber business interruption assumes an office outage. A unit off bars for eighteen hours has already incurred replacement power and deviation costs. Eight to twelve hour periods, or tiered structures that shorten the wait for outages driven by operational technology, fit the exposure better and are negotiable.
The engineering side of a power placement is set out in our overview of engineering and property cover for the sector, and the standing CEA safety framework that generation and distribution entities already work to is covered in CEA electrical safety regulations and insurance.
Using the Implementation Window as a Procurement Calendar
The window to 1 April 2027 is a compliance schedule and also the last clean opportunity to reprice a power sector cyber programme against a documented control uplift, because after the deadline the uplift is simply expected. A sequence that works for an entity renewing before April 2027:
- Baseline the control state in writing. Record what is in place, what is scheduled, and the target date for each item. The same document serves as the compliance plan and the underwriting submission.
- Reconcile the proposal form against that baseline. Every answer that describes a target state rather than a current state is a coverage risk. Restate them as current state plus committed date and disclose the difference.
- Fix the notification protocol before the wording. A one-page internal instruction that says detection starts both the CSIRT-Power clock and the insurer clock, and that the regulatory filing carries observed facts only, costs nothing and removes the most common own-goal.
- Negotiate the three clauses that matter: the definition of computer system extended to industrial control systems and operational technology, the waiting period, and the interaction between the cyber tangible property exclusion and the property programme's cyber exclusion.
- Take the placement to market with the compliance plan attached. Underwriters price uncertainty. An entity that shows a dated remediation plan against a gazetted regulation is easier to underwrite than one that answers the same questions in prose.
For context on how cyber business interruption is being written for Indian corporates generally, see cyber business interruption cover for Indian corporates.
What Boards and Risk Committees Should Be Asking
The regulations give a board a short list of questions with checkable answers. The insurance versions of those questions are shorter still.
- Who is the named officer, and does the escalation matrix reach the insurance team inside the six-hour window?
- Does our cyber policy define computer system to include industrial control systems, SCADA, protection relays and substation automation, or does it describe an office IT estate?
- Does our internal protocol start the policy notification clock at detection rather than at management awareness?
- If a cyber event damages plant, which policy pays, and do we have that in writing from both insurers?
- Are the controls described in our proposal form the ones we have today, or the ones we expect by 1 April 2027?
The last two are the ones that get answered wrongly in practice, because the person filling the proposal form and the person running the remediation programme are rarely the same person and rarely read each other's documents.
Cyber insurance for the sector is available and capacity is not the binding constraint. The wordings on offer were built for information risk, so a power sector buyer has to ask for the amendments rather than assume them. The gazetted regulation is a useful lever for asking, because it gives the buyer a dated external standard to point at.