On July 31, 2026, India's Central Electricity Authority notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026. They come into force on April 1, 2027. For anyone who has spent time inside a control room, this is the moment India's power sector stopped treating OT cybersecurity as guidance and started treating it as law.
The scope is wide. The rules apply to every entity that owns, operates, or manages OT connected to the interconnected power system, with a 50 MW installed-capacity threshold for generating companies, captive plants, and organizations running energy storage. Transmission and distribution licensees, the National, Regional, and State Load Despatch Centres, power exchanges, and OTC platforms are all in. So are vendors, who now carry direct obligations, including a Bill of Materials (i.e., a structured inventory of every component and firmware element in a critical system). The compliance clock is real: six-hour incident reporting to CSIRT-Power, a mandatory annual cyber security audit, and a defined window to close audit findings.
If this reads familiar to North American practitioners, it should. India has just written its NERC CIP moment.
NERC CIP has governed the North American Bulk Electric System since it became mandatory and enforceable on July 1, 2008. Eighteen years and thirteen active standards later (CIP-002 through CIP-014), it is the most mature grid-cyber regime in the world, backed by penalties reaching $1 million per violation per day and routine audits across roughly 1,600 Registered Entities.
Put the CEA regulation next to it and the DNA is unmistakable. Asset registers. Electronic Security Perimeters. Physical separation of OT from IT and the internet. Personnel risk assessment. Incident reporting on a hard clock. Recovery plans, backup discipline, supply-chain obligations, mandatory audit. India did not copy NERC CIP, but it clearly learned from it, and from the fifteen years of implementation scar tissue that followed. That is the advantage of regulating late.
Three differences are worth a practitioner's attention.
First, India binds the vendor directly. Under CIP-013, the supply-chain burden sits entirely on the asset owner, who must manage vendor risk through a plan. The CEA regulation writes obligations onto the vendor itself, SBOM included. That is closer to the EU Cyber Resilience Act than to NERC CIP, and it means OEMs selling into India carry compliance weight they do not carry in North America.
Second, India mandates data sovereignty. Sensitive data, including historical and cloud-hosted data, must be encrypted and reside within India only. NERC CIP has no equivalent. This is a design constraint, not a checkbox, and it will shape how operators architect monitoring and storage from day one.
Third, and most consequential for how work actually gets done, the two regimes classify criticality differently. CIP-002 hands you Attachment 1, an externally defined bright-line that sorts BES Cyber Systems into High, Medium, and Low impact. The CEA regulation asks the entity to define its own criticality criteria, tied to business-continuity impact, and defend it. More flexibility, and a heavier burden of proof. When you set your own bright line, you own every classification decision in the audit.
The regulatory convergence is happening across two power sectors that could hardly be more different in shape.
India is the growth story. Installed generation capacity reached roughly 552 GW in July 2026, up from 249 GW in 2014.1 Non-fossil capacity crossed 300 GW, more than 60% of the way to the 500 GW-by-2030 target.2 Peak demand set a record of 256 GW in April 2026 and the power ministry expects it to approach 300 GW.3 The storage build-out is steep: the CEA projects a requirement of about 74 GW / 411 GWh by 2031–32.4 Every one of those new solar farms, storage sites, and prosumer connections is a new OT endpoint, arriving faster than most security programs mature. The regulation's explicit coverage of energy storage and distributed generation is not incidental. It is aimed squarely at where the attack surface is expanding.
North America is the maturity story, now facing its own shock. US utility-scale capacity stood at about 1,281 GW at the end of 2025.5 The regime is settled; the demand is not. NERC's 2025 Long-Term Reliability Assessment, published in January 2026, forecasts summer peak demand rising 224 GW over ten years, a more than 69% jump over the prior year's forecast, driven mostly by data centers and AI load.6 A mature regulatory framework is now stretched across load growth it was not sized for.
So one market is racing to build a grid and regulate it at the same time. The other has the rulebook but is bolting on unprecedented demand. Both outcomes point the same direction: more OT, more connectivity, more regulatory weight on the asset owner.
Practitioners do not need the case made with alarm, let’s be specific. In February 2021, Recorded Future's Insikt Group documented a campaign it tracked as RedEcho targeting ten Indian power-sector organizations, including four of the five Regional Load Despatch Centres, using the ShadowPad backdoor.7 The link between that activity and the October 2020 Mumbai outage has never been officially established, and the Indian government attributed the outage to human error. The targeting itself is documented, and that is the point worth holding.
North America carries its own file. In February 2024, CISA, the FBI, and the NSA jointly assessed that PRC-linked Volt Typhoon actors were pre-positioning inside US critical infrastructure, energy included, in some cases holding access for five or more years, to enable disruption of OT functions.8 Set alongside the 2015 Ukraine grid attack that cut power to roughly 230,000 people, the pattern is clear. State-capable adversaries treat the grid as a target of record.
Here is the gap we keep running into, and it is the same gap in Mumbai as in Houston.
Both the CEA regulation and NERC CIP mandate largely qualitative outputs. Risk registers. High-medium-low ratings. Audit findings sorted by severity. That machinery satisfies an auditor. It does not answer the question a CFO or a board actually asks: how much money is this exposure worth, and does this control spend reduce it?
The market is already pricing that gap. The industrial control systems security market in energy and power is forecast to more than double, from $7.74 billion in 2025 to $17.12 billion by 2030.9 And the financial stakes that sit underneath the spend are large enough to force the conversation upward. Dragos's 2025 OT Security Financial Risk Report, with analysis from Marsh McLennan's Cyber Risk Intelligence Center, models global OT cyber losses reaching $329.5 billion in a severe one-in-250-year tail event, with $172.4 billion of that from OT-related business interruption alone.10 A number of that magnitude does not belong in a risk register. It belongs in a capital-allocation decision.
This is the throughline between the two markets. A regulation is the on-ramp. It forces every in-scope operator to inventory assets, assess risk, and prove it to an auditor. But the destination is financial: translating OT cyber exposure into production downtime, restart costs, equipment damage, and regulatory penalty, expressed in the currency the board runs the business in. Financial quantification of cyber risk (aka., cyber risk quantification, or CRQ) is how an operator turns a compliance artifact into a decision.
It is part of our work at DeNexus. DeRISK CRQ translates OT cyber exposure into financial currency facility by facility, modeling the path from a network access event to process disruption to recovery economics, rather than starting from how often a sector gets attacked. For an Indian genco standing up a program against an April 2027 deadline, or a North American utility defending a CIP-002 classification, the same capability answers the same question the regulation cannot: what is this worth, and what does fixing it buy back?
India's operators have roughly eighteen months. The smart ones will not treat April 2027 as the finish line. They will treat it as the moment the grid's cyber risk became a number their board has to understand, and they will build toward that number from the start. North America spent fifteen years learning that lesson the long way. India does not have to.
Turn the register into a number. DeRISK CRQ translates OT cyber exposure into financial currency facility by facility — modeling the path from a network access event to process disruption to recovery economics, rather than starting from how often a sector gets attacked. The output is Annual Expected Loss and Value at Risk, rolled up to the portfolio, calibrated on 300+ industrial deployments across the US and EU. Whether you're an Indian genco building toward April 2027 or a North American utility defending a CIP-002 classification, it answers what the regulation cannot: what is this exposure worth, and what does fixing it buy back?
Explore the DeRISK Platform → https://www.denexus.io/derisk-platform
[1] Press Information Bureau, Government of India. “India's Power Sector.” Press Information Bureau, 2026, static.pib.gov.in/WriteReadData/specificdocs/documents/2026/aug/doc2026813954201.pdf; The Hans India. “India's Total Installed Power Capacity Reaches 552 GW.” The Hans India, 13 Aug. 2026, www.thehansindia.com/business/indias-total-installed-power-capacity-reaches-552-gw-1109200.
[2] Upstox. “India Crosses 300 GW Non-Fossil Power Capacity, Hits 60% of 2030 Target.” Upstox, 10 Aug. 2026, upstox.com/news/business-news/latest-updates/india-crosses-300-gw-non-fossil-power-capacity-hits-60-of-2030-target/article-198360/.
[3] Down To Earth. “India's Battery Storage Requirement to Jump to 888 GWh by 2035; Power Demand Likely to Reach 300 GW Next Year.” Down To Earth, 9 July 2026, www.downtoearth.org.in/energy/indias-battery-storage-requirement-to-surge-888-fold-by-2035-36-but-financing-remains-the-biggest-hurdle.
[4] RJ Associates Media. “Govt Targets 47.24 GW Battery Storage by 2032 – ₹3.49 Lakh Crore Investment.” RJ Associates Media, 2026, www.rjassociatesmedia.com/govt-targets-47-24-gw-battery-storage-by-2032-₹3-49-lakh-crore-investment/; Central Electricity Authority. National Electricity Plan (Volume I – Generation), 2022–32. Government of India, 2023, pib.gov.in/PressReleaseIframePage.aspx?PRID=1928750.
[5] U.S. Energy Information Administration. “Electricity Generation, Capacity, and Sales in the United States.” EIA, 2026, www.eia.gov/energyexplained/electricity/electricity-in-the-us-generation-capacity-and-sales.php.
[6] North American Electric Reliability Corporation. 2025 Long-Term Reliability Assessment. NERC, Jan. 2026, www.nerc.com/globalassets/our-work/assessments/nerc_ltra_2025.pdf; Utility Dive. “NERC Forecasts Peak Demand to Rise 24% on New Data Center Loads.” Utility Dive, 30 Jan. 2026, www.utilitydive.com/news/nerc-10-year-peak-demand-forecast-jumps-24-on-new-data-center-loads/810955/.
[7] Insikt Group. “China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions.” Recorded Future, 28 Feb. 2021, www.recordedfuture.com/research/redecho-targeting-indian-power-sector.
[8] Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, and National Security Agency. “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure.” CISA, 7 Feb. 2024, www.cisa.gov/sites/default/files/2024-02/aa24-038a-jcsa-prc-state-sponsored-actors-compromise-us-critical-infrastructure_1.pdf.
[9] MarketsandMarkets. “Industrial Control Systems (ICS) Security Market in Energy & Power, by Solution, Vertical, and Region – Global Forecast to 2030.” MarketsandMarkets, 2026, www.marketsandmarkets.com/Market-Reports/industrial-control-systems-ics-security-market-in-energy-power-250270786.html.
[10] Dragos, Inc. 2025 OT Security Financial Risk Report. Dragos, in partnership with Marsh McLennan Cyber Risk Intelligence Center, 12 Aug. 2025, www.dragos.com/2025-ot-security-financial-risk-report.