The Ministry of New and Renewable Energy (MNRE) has directed all Original Equipment Manufacturers (OEMs) listed under the Approved List of Models and Manufacturers of Wind Turbines (ALMM) to submit proof of compliance with India’s local cybersecurity requirements.
In an official memorandum issued on August 20, 2026, MNRE instructed wind turbine manufacturers to report their compliance status along with supporting documents by August 31, 2026. The information will be used for subsequent random checks and inspections.
The directive follows an amendment to the ALMM procedure issued on July 31, 2025, which introduced stricter cybersecurity requirements for the wind energy sector. Under the rules, wind turbine manufacturers are required to establish data centers, servers, and research and development (R&D) facilities within India.
The regulations also prohibit the transfer of real-time operational data outside the country. In addition, operational control of wind turbines must be managed exclusively from facilities located in India. OEMs were provided a one-year period from the amendment’s issuance to establish their local R&D centers.
For compliance verification, manufacturers must classify their status for each requirement as fully compliant, partially compliant, or non-compliant using the format specified in Annexure-I.
OEMs are required to provide details such as the names and locations of local data servers, operational control centers, measures implemented to prevent external remote control of turbines, and details of local R&D facilities and manpower.
The latest memorandum reflects the government’s efforts to strengthen cybersecurity across India’s renewable energy infrastructure. By requiring critical operational data and control systems to remain within the country, the initiative aims to improve domestic oversight and reduce potential cybersecurity risks to wind power assets.











