Search Results:
×
The Central Electricity Authority, India, notified the CEA Cyber Security in Power Sector Regulations 2026 on July 31, 2026, with a general effective date of April 1, 2027. Applicability includes qualifying 50 MW generation, captive, and storage facilities and covered IT/OT infrastructure.
Organizations evaluating CEA compliance requirements should assess their applicable systems, vendors, and power-sector operations now. The CEA framework covers entities including NLDC, RLDCs, SLDCs, power exchanges, and OTC platforms, with certain provisions subject to separate commencement orders.
The CEA Cyber Security Regulations 2026 introduce specific access management requirements for critical systems, remote access, authorized personnel, and retained information.
CEA Requirement
Section Number
miniOrange Capability
What It Enables
Reg. 8(11)
miniOrange IAM, SSO, MFA, RBAC
Centralized CEA access management, authentication, authorization, role-based access control, and identity management across supported applications and critical systems
Reg. 8(12)
miniOrange IAM + PAM
Controlled CEA identity management and privileged access for authorized personnel and third parties; supports technical access enforcement alongside the required personnel assessment
Reg. 8(14)
miniOrange PAM
Controlled CEA vendor access, third-party access, vendor privileged access, and monitoring of privileged activity
Reg. 8(15)
miniOrange PAM + MFA
CEA remote access security through least privilege access, minimum-duration and time-bound access, JIT privileged access, MFA for remote access, and geo-fencing where supported
Reg. 8(16)
miniOrange PAM
Controlled remote OT access and privileged remote access for approved operational activities
Reg. 5(17)
miniOrange PAM + MFA
Remote access approval, privileged session monitoring, privileged session recording, and auditable access activity
Reg. 8(26)
miniOrange IAM + PAM + SIEM integration
Identity events, access logs, audit logs, and privileged-session records that can support centralized monitoring, investigation, and evidence collection
Reg. 8(33)
miniOrange IAM, RBAC, MFA, Access Gateway
Role-based access control, strong authentication, and controlled access to retained information; Access Gateway can extend SSO and MFA to supported legacy and custom applications
Second Schedule
miniOrange IAM + PAM
Centralized authentication, authorization, administrative privilege controls, identity-management policies, and controlled access-policy changes
Reg. 5(17) / First Schedule
miniOrange PAM + IAM logging
Maintained access and privileged-session records that can contribute to required audit logs, access evidence, and compliance documentation
Support AAA access management, multi-factor authentication, least privilege access, and privileged access across relevant power-sector requirements.
Bring relevant CEA requirements into your existing security environment across identities, applications, privileged access, vendors, and security operations.
Identify IT/OT environments, critical applications, privileged accounts, vendors, and remote-access pathways.
Configure authentication, authorization, RBAC, MFA, and least-privilege access based on roles and sensitivity.
Apply PAM, JIT privileges, time-bound access, controlled sessions, and administrative monitoring.
Control third-party access and integrate IAM/PAM events with SIEM/SOC workflows.
Connect miniOrange with existing identity sources, SaaS applications, IT/OT environments, and security operations. Extend security and access controls to legacy or custom applications that lack native federation support.
Implement identity security where it fits best while meeting data residency, compliance, and business continuity requirements.
Extend your existing security environment with an access-security layer designed around the identity and privileged-access requirements relevant to CEA compliance.
miniOrange brings IAM, SSO, MFA, and PAM capabilities together, allowing organizations to address multiple access scenarios through one security stack rather than separate point controls.
Extend controlled authentication and privileged-access policies to vendors, OEMs, contractors, and system integrators instead of leaving third-party access outside the organization's access framework.
Support time-bound and JIT privileged access, MFA, least privilege, and session monitoring for applicable remote-access scenarios, helping reduce persistent administrative privileges.
Connect relevant IAM and PAM events with existing SIEM/SOC environments so authentication, access, and privileged-session activity can contribute to centralized monitoring and investigation.
Address CEA power sector cybersecurity requirements with controlled privileged access, remote access, vendor access, and audit-ready visibility.
Talk to a miniOrange ExpertThe regulations apply to generating companies, captive generating plants, and Energy Storage Systems with installed capacity of 50 MW or more. Organizations should assess their capacity and CEA regulations applicability to determine whether the requirements apply.
Yes. NLDC, RLDCs, and SLDCs are covered power-sector entities. Assess NLDC, RLDC, and SLDC cybersecurity responsibilities against applicable provisions covering cybersecurity governance, operations, access, monitoring, and compliance.
Yes. The framework includes specified power exchanges and OTC platforms, subject to applicable provisions. These entities should evaluate power exchanges and OTC platforms cybersecurity requirements alongside relevant governance, reporting, operational, and compliance obligations.
Applicable entities must establish and maintain a Cyber Crisis Management Plan (CCMP) as part of their cybersecurity preparedness and incident-response framework. It supports the organization's approach to preparing for, responding to, and managing significant cybersecurity incidents.
The regulations prescribe retention periods for remote-access records, ICT/OT and forensic records, incident logs, self-audit reports, cybersecurity audit reports, and certification audit reports. Maintaining these records supports CEA cyber security compliance, audit readiness, and compliance evidence.
The regulations define requirements for the CISO and Alternate CISO, covering qualifications, experience, appointment tenure, reporting responsibilities, compliance reviews, and training. These responsibilities form part of the organization's cybersecurity governance and CEA compliance requirements.