India critical infrastructure cybersecurity

India's Wind-Turbine Localisation Order Mixes a Real Cybersecurity Case With an Impossible Clock

MNRE gave ALMM wind OEMs 11 days to prove India-only data centres and control rooms — sound security logic, compressed into a deadline that mainly rewards incumbents.

MNRE's Wind Turbine Localisation Squeeze People of Internet Research · India ~45% Chinese OEM market share 2025 Up from ~10% in 2019, the growth c… Aug 31, 2026 Compliance proof deadline Days OEMs had to document India-ba… 1 year R&D centre commitment window Time given to open an India-based … ~25-30% Domestic capacity utilisation Current utilisation of India-quali… peopleofinternet.com
MNRE's Wind Turbine Localisation Squee… People of Internet Research · India ~45% Chinese OEM market share 2025 Aug 31, 2026 Compliance proof deadline 1 year R&D centre commitment window ~25-30% Domestic capacity utilisation peopleofinternet.com

Key Takeaways

The Ministry of New and Renewable Energy (MNRE) issued an office memorandum on August 20, 2026 ordering every OEM on the Approved List of Models and Manufacturers for Wind (ALMM-Wind) to prove, by August 31, that their turbine data centres and servers sit inside India, that real-time turbine control runs only from an India-based control centre, and to commit in writing to opening an Indian R&D centre within a year. Random inspections follow (Mercom India; Saurenergy).

This is not a new rule dressed up as urgent. MNRE amended the ALMM-Wind inclusion procedure on July 31, 2025 to require India-based data centres, India-only real-time operational control, and a bar on exporting live turbine data — a change MNRE later clarified in a September 4, 2025 notice (MNRE clarification notice). The August 20 memorandum is an enforcement checkpoint against a rule OEMs have had thirteen months to absorb — every manufacturer on the current ALMM-Wind list qualified for inclusion under the amended text in the first place.

The security case is real

Wind farms increasingly run on the same SCADA architecture as the rest of the grid: turbine controllers, met-mast telemetry, and park-level dispatch systems that talk to a central operations centre. If that centre sits abroad and the OEM pushes firmware or accepts remote-control sessions from outside India, a compromised vendor — or a vendor legally compelled by its home government — becomes a lever against Indian grid stability. That is not a hypothetical; grid-connected SCADA has been the specific target of state-linked intrusions elsewhere, and India's own national-security establishment has flagged foreign-controlled data servers and unvetted software updates in energy infrastructure as a live exposure. Data localisation and India-only control are the correct first-order fixes for that specific risk. A regulator that ignored the concentration of turbine telemetry and control authority in foreign hands would be negligent, not restrained.

The market backdrop sharpens the case. Chinese OEMs' share of India's wind turbine market rose from roughly 10% in 2019 to about 45% by 2025, largely on landed-cost advantages of 10–15% over Indian manufacturers (Down To Earth). Rapid share gains by vendors headquartered in a jurisdiction with which India has an unresolved border dispute and a documented pattern of state-directed tech leverage is exactly the scenario sectoral security rules exist to address.

Where the memo strains credulity

The problem is not the mandate; it's the sequencing. Standing up a compliant India-based data centre and control room — with the staffing, network segmentation, and audited handover from an overseas SCADA stack — is months of engineering and procurement work, not something a compliance memo can compress into eleven calendar days. MNRE's own July 2025 amendment implicitly recognised this: it gave OEMs over a year before this checkpoint. Framing August 31 as a hard proof date, with random inspections threatened immediately after, reads less like a security deadline and more like a compliance-theatre trigger — useful for generating a paper trail of who has and hasn't localised, less useful for verifying that any given control centre is actually secure.

That matters because the same policy bundle that mandates India-only servers also requires OEMs to source 65–70% of turbine cost — blades, towers, gearboxes, generators, bearings — from domestic suppliers, and now to build an Indian R&D centre within a year. Down To Earth's reporting notes manufacturing capacity utilisation among Indian-qualified suppliers sits around 25–30%, with room to double installations toward 7.1 GW annually if that capacity fills up. None of that is illegitimate industrial policy — India is entitled to build domestic manufacturing capacity — but bundling it with a cybersecurity memo makes it hard to tell which requirement is doing the work. A firm that fully localises its data centre and control room but hasn't yet met the domestic-content threshold gets no credit under ALMM; a firm that localises components but keeps servers offshore fails a different test. Regulators should resist letting an industrial-policy goal ride on a security memo's urgency, because it invites exactly the criticism China-hawks least want: that the rule is protectionism with a security label glued on.

The proportionate fix

MNRE doesn't need to choose between security and speed if it decouples the two asks. Data-centre and control-centre localisation deserves the compliance timeline it was actually given — the thirteen months since July 2025 — with the August 31 checkpoint used to identify laggards for a graduated inspection and remediation schedule, not a pass/fail cutoff. The R&D-centre commitment, which has no direct bearing on today's cyber-risk surface, should run on its own multi-year track tied to the domestic-content ramp, evaluated separately from data-centre audits. Keeping the two tracks distinct would let MNRE credibly claim it is closing a real SCADA-exposure gap — which it is — without handing critics a legitimate complaint that the deadline was designed to be missed.

Sources & Citations

  1. MNRE clarification notice on ALMM-Wind amendment (Sept 4, 2025)
  2. MNRE Approved List of Models and Manufacturers (ALMM-Wind)
  3. Mercom India: MNRE Asks Wind Turbine OEMs to Prove Cybersecurity Compliance by August 31
  4. Down To Earth: Domestic push — India mandates local supply chains and data centres for wind turbines
  5. Saurenergy: MNRE Seeks Cybersecurity Compliance Details From Wind Turbine OEMs