A battery storage system is a large, fast, controllable power asset that takes instructions over a network. That combination is exactly what makes it commercially valuable, and exactly what makes it a security question.
India has now put rules around it. The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 were published in the Gazette of India on 31 July 2026, with mandatory provisions coming into full effect from 1 April 2027.
Why storage is a specific concern
Most cybersecurity conversations are about data — someone stealing information. Grid assets invert that. The valuable thing an attacker gains is not information but control.
A battery that can be instructed when to charge and discharge can, in principle, be instructed to do so at the worst possible moment: discharging into a surplus, charging into a shortage, or refusing to respond during a frequency event. At sufficient scale and coordination, that is a grid stability problem rather than a commercial one.
Two features of modern storage make the exposure real. First, these assets are designed to be remotely operated — nobody sends an engineer to a substation to dispatch a battery. Second, the energy management system that makes commercial decisions is software, frequently cloud-connected, and increasingly supplied by a party other than the battery manufacturer.
What the regulations require
Coverage. Generating companies, captive power plants and energy storage systems of 50 MW or more are directly covered. The framework explicitly includes organisations having energy storage systems within its definition of an entity, and recognises grid-connected rooftop solar and energy storage as distributed generation resources.
Remote access. This is the heart of it. Remote access to critical assets is permitted only for emergency troubleshooting, and must use multi-factor authentication, continuous monitoring and detailed logging. For distributed generation resources owned by prosumers, remote access and operation must use secure, authenticated and encrypted channels.
That is a meaningful change of posture. Routine remote operation of critical assets from anywhere, by anyone with a password, is no longer the assumed model.
Incident reporting. Cyber incidents must be reported to CSIRT-Power within six hours. Six hours is not long. It is a requirement to have a process, a named owner and contact details ready before anything happens.
Data localisation. Sensitive operational and historical grid data — including information hosted on cloud platforms — must be encrypted, protected and stored exclusively within India. For distributed resources, vendors must ensure application, monitoring and control data, including cloud-hosted and historical data, is held in encrypted and protected environments within India.
Vendor obligations. The regulations extend cybersecurity obligations to vendors, with the definition specifically covering suppliers of inverters, communication modules, monitoring systems and energy management software associated with distributed generation resources.
That last provision is the one with the widest reach. It means a supplier cannot treat security as the customer’s problem, and it means a buyer’s due diligence properly extends into their supplier’s software practices.
What a buyer should actually ask
Whether or not you cross the 50 MW threshold, these are reasonable questions for any connected storage system:
- Where is my operational data stored? Ask for the country, not the platform name.
- Who can access my system remotely, and how is that access authenticated and logged? Shared vendor credentials are a common and poor answer.
- Is remote access routine or exception-based? The regulations point firmly toward exception-based.
- What happens to access when the supplier relationship ends? Orphaned vendor access is a widespread and under-examined risk.
- What is the incident notification path, and who on your side owns the six-hour clock?
- How is firmware updated, and who authorises an update to equipment that controls megawatts?
These sit naturally alongside the monitoring and 90-day data retention requirements in CEA technical standards for connecting a battery — the same data that must be retained also has to be protected.
The tension worth naming
There is a real trade-off here, and it should be acknowledged rather than glossed over.
The commercial value of a modern battery depends on remote optimisation. An energy management system that responds to market prices, executes a revenue stack, or follows a grid operator’s dispatch has to be connected to be useful. Meanwhile, operations and maintenance economics depend on diagnosing faults remotely rather than sending an engineer to every site.
Security requirements do not remove that connectivity; they discipline it — authenticated, logged, monitored and exception-based rather than open and routine. Well implemented, that costs a little convenience and very little capability. Badly implemented, it is either theatre or an obstacle.
What this means for you
- If you operate a project at or above 50 MW: you are directly covered, with full effect from 1 April 2027. The realistic first step is an access audit — who can reach your control systems today, and can you prove it?
- If you are a C&I buyer below the threshold: the vendor obligations reach you regardless. Ask where your data lives and who holds remote access. Both are reasonable questions with quick answers from a competent supplier.
- If you are a supplier or integrator: security has become a procurement criterion, not a differentiator. Data residency in particular is now a binary qualification question rather than a nice-to-have.
- If you want to review a specific architecture: our systems are supplied with documented control and monitoring architecture, and our team can walk through it — get in touch, or see how we build them at our manufacturing facility.
Cyber security regulations, thresholds, reporting timelines and vendor obligations change by notification and are subject to further guidance. Nothing here is legal or compliance advice. Treat this as an August 2026 snapshot and verify the current text of the CEA regulations and their applicability to your project with your own advisers.