Turbine and Panel
Live
Technologies

SECI Seeks Cybersecurity Auditors for

India's Solar Energy Corporation has invited cybersecurity firms to form a panel for auditing IT and OT systems in renewable energy projects, aiming to

India's Solar Energy Corporation has invited cybersecurity firms to form a panel for auditing IT and OT systems in...

The Solar Energy Corporation of India Limited (SECI) has invited cybersecurity auditing firms to join a new panel. Issued on August 28, 2026, the Request for Empanelment aims to strengthen the security of India's renewable energy infrastructure.

SECI, acting as the designated Sectoral Computer Emergency Response Team for Renewable Energy, is leading this initiative. The move is designed to help renewable energy entities meet the mandates of the Central Electricity Authority Cyber Security Regulations from 2024.

Bidding and Empanelment Process

The bidding process, identified as RfE No. SECI/C&P/EOI/17/0004/26-27, will be conducted online via the ISN-ETS portal. It follows a single-stage, single-envelope competitive e-tendering system. The initial empanelment for selected agencies will last for two years.

SECI may extend this period for up to two additional years. Any yearly extension will depend on satisfactory performance and the continued validity of the auditor's empanelment with India's national CERT-In agency.

Financial and Qualification Requirements

Applicants face specific financial obligations. A non-refundable bid processing fee of ₹5,000 plus GST is required, though Micro and Small Enterprises with valid UDYAM registration are exempt. Selected agencies must then pay an empanelment fee of ₹20,000 plus 18% GST for each geographic zone they cover for the initial two-year term.

No Earnest Money Deposit or Performance Bank Guarantee is needed under this RfE. SECI will evaluate applicants using a Quality Based Selection system, where organizations must score at least 70 out of 100 marks to qualify.

The evaluation criteria are detailed in the table below.

Evaluation CriteriaDetails
Minimum Qualifying Score70 out of 100 marks
Key ConsiderationsAuditing experience, certified technical manpower, previous cybersecurity audits, relevant ISO certifications (e.g., ISO/IEC 27001), expertise in Operational Technology (OT) systems including SCADA, DCS, and Substation Automation Systems.

Assignment and Payment Structure

Empaneled agencies will be deployed across five geographic zones in India. Specific audit assignments will not be awarded automatically. Instead, they will be granted through a secondary competitive bidding process based on the lowest price (L1 selection).

Payment for completed audits will be released in two equal instalments. The first 50% will be paid after the submission of the initial audit report. The remaining 50% is contingent on the final compliance sign-off from the project entity.

The bid validity period is set at 12 months from the last date of submission. According to the source, bidders have 20 days from the RfE's issuance to report any discrepancies in the document.

Related coverage

More from Technologies