Check applicability and commencement before planning
The CEA (Cyber Security in Power Sector) Regulations, 2026 are notified, but generally commence on 1 April 2027. Regulation 1(2) reserves separate dates for 5(9), 5(24), 5(33), 5(39), 6(2) and 6(7). Treat those as a separate tracking list, not as already active requirements. CEA regulations 1–2: commencement and applicability
Who this can reach beyond the obvious utility
Regulation 2 covers entities owning, operating or managing OT connected to the interconnected power system, and physically or logically connected IT. For generating companies, captive plants and energy-storage organisations, the stated threshold is 50 MW. Power exchanges and OTC platforms have specified exclusions. Apply the exact text to the legal entity and infrastructure.
Vendors must comply with regulations 11 and 12 as applicable. Distinguish these direct provisions from additional requirements passed through a customer contract; supplying something near a grid is not, by itself, a complete applicability assessment.
Translate IT and OT dependencies into a preparation plan
IT and OT changes can involve different owners and operating constraints. Agree a shared view of connectivity, maintenance windows, safety approvals and recovery dependencies before scheduling testing. Do not use an audit preparation exercise as authorisation to scan or alter a live control system.
Three questions worth resolving before an audit or supplier review raises them: where exactly does the IT/OT boundary sit in your environment, and is that boundary documented rather than assumed; who has remote access into OT systems, and is that access reviewed on the same cadence as IT access; and what does an operational incident exercise actually cover — does it include the OT environment, or only the IT-facing systems that are easier to test.
Building from dependency visibility, not a paper policy
The starting point that tends to hold up is a dependency map — which systems, connections and third parties actually touch the operational environment — built before rather than after a compliance request arrives. Depending on scope, that map, combined with a remote-access control review and an operational readiness plan, is what most engagements in this space actually produce as evidence, rather than a policy document alone.
Create an obligation and evidence register
The following register format is a preparation recommendation. Read each cited provision with its definitions, exceptions and commencement status; these examples are not the entire regulations.
- Applicability owner: record the legal entity, operational role, connected infrastructure and any relevant capacity threshold. Attach the reasoning and reviewer. Keep direct duties, future duties and contractual commitments in separate columns so their status stays visible.
- Asset visibility: regulation 5(25) addresses the asset register. Suggested evidence: dated inventories reconciled to network diagrams and equipment ownership. Mark unknown connections for investigation rather than assuming that an incomplete map proves isolation.
- Risk ownership: regulation 5(26) addresses the cyber risk assessment and mitigation plan. Suggested evidence: a risk-to-asset register with accountable owners, treatment decisions and review records. Track the specified cadence in the obligation register.
- Supplier coordination: identify who supplies updates, who approves remote work and who can restore operation. Ask vendors for a scoped response to the provisions applicable to their role; retain unresolved dependencies in the procurement action list.
- Safe verification: agree permitted techniques, stop conditions, operating supervision and restoration steps before an exercise. Start with documentation and controlled demonstrations where intrusive testing could affect plant availability or safety.
Use the time before commencement to resolve ownership and evidence gaps, while continuing to meet duties already applicable under other instruments. Have the compliance owner monitor separate commencement orders and amendments. A completed checklist supports preparation; it does not establish legal compliance without assessment against the full applicable text.

