FERC Proposes to Accept Updated CIP Standards and Calls for New Cybersecurity Controls
Time 3 Minute Read

On July 16, 2015, the Federal Energy Regulatory Commission (“FERC”) issued a new Notice of Proposed Rulemaking (“NOPR”) addressing the critical infrastructure protection (“CIP”) reliability standards. The NOPR proposes to accept with limited modifications seven updated CIP cybersecurity standards. The NOPR also proposes that new requirements be added to the CIP standards to protect supply chain vendors against evolving malware threats and addresses risks to utility communications networks.

The CIP standards govern the cyber and physical security of the bulk electric system. They are mandatory and enforceable. Utilities that violate them are potentially subject to substantial financial penalties. CIP standards are developed, administered, and enforced by the North American Electric Reliability Corporation (“NERC”) subject to FERC’s oversight.

The NOPR identifies malware campaigns targeting supply chain vendors as a serious security threat that is not addressed by existing CIP standards. It therefore proposes to direct NERC to develop CIP requirements relating to supply chain management for industrial control system hardware, software and services. It offers specific guidance as to the elements that FERC believes such standards should have, including that they be forward-looking, objective-driven, and consistent with guidance offered in the National Institute of Standards and Technology (NIST SP 800-161).

In addition, the NOPR builds on earlier FERC orders conditionally accepting “version 5” of the CIP standards. Version 5 made various incremental improvements to earlier iterations of the CIP standards. FERC directed NERC to further revise the version 5 requirements to make them clearer, more specific, and more readily enforceable. It also instructed NERC to develop: (1) enhanced security controls for “low impact” assets; (2) controls to address the risks posed by “transient” electronic devices (e.g., thumb drives and laptops); and (3) a clearer definition of the term “communications networks.”

In response, NERC proposed seven updated “version 6” CIP standards in February that incorporated FERC’s directives. The new NOPR proposes to largely accept version 6 but requires NERC to broaden the scope of communications network protections from a limited group of control centers to “communication network components and data communicated between all bulk electric system Control Centers.” FERC also specifically seeks comments on the sufficiency of existing CIP controls regarding remote access used in relation to bulk electric system communications.

FERC’s actions are consistent with its history of continuously urging NERC to improve, and to broaden the scope of, the CIP standards. But the NOPR is also only the third time that FERC has proposed to use its authority to require NERC to propose a new reliability standard, highlighting the close attention that FERC has devoted to cybersecurity threats generally and its concern about evolving malware vulnerabilities in particular.

Written comments on the NOPR will be due 60 days after its publication in the Federal Register. If the proposed version 6 CIP standards are accepted they would supersede the not yet implemented version 5 standards and become effective no earlier than April 2016.

You May Also Be Interested In

Time 8 Minute Read

On October 23, 2025, the Secretary of Energy, pursuant to his authority under section 403 of the Department of Energy Organization Act, directed the Federal Energy Regulatory Commission to initiate rulemaking procedures and consider an advance notice of proposed rulemaking that sets forth potential reforms to expedite and facilitate the interconnection of “large loads,” notably data centers, to the interstate transmission system.

Time 9 Minute Read

On September 30, 2025, the U.S. Court of Appeals for the D.C. Circuit (D.C. Circuit) issued Sierra Club v. FERC, which upheld the Federal Energy Regulatory Commission’s (FERC) authorization of a 32-mile pipeline that will supply natural gas to a Tennessee Valley Authority (TVA) project at which TVA is replacing a coal-fired power unit with a natural gas turbine. The opinion is significant because the D.C. Circuit recognized, for the first time, that its controversial Sabal Trail opinion was abrogated by the Supreme Court’s recent decision in Seven County Infrastructure Coalition v. Eagle County, Colorado.

Time 3 Minute Read

On October 1, 2025, the Federal Energy Regulatory Commission issued a direct final rule inserting a conditional sunset date into certain regulations in response to Executive Order 14270, “Zero-Based Regulatory Budgeting to Unleash American Energy.”

Time 6 Minute Read

On August 29, 2025, the Secretary of Energy directed the Federal Energy Regulatory Commission to rescind the Updated Certificate Policy Statement pursuant to his authority under section 403 of the Department of Energy Reorganization Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page