Energy & Utilities
NERC CIP, pipeline security, and grid resilience
NERC CIP-008-6, Requirement R4 Table Part 4.2: initial notification within one hour after the determination of a Reportable Cyber Security Incident, and by the end of the next calendar day for a Cyber Security Incident that was an attempt to compromise.
Energy and utility companies operate critical infrastructure under mandatory cybersecurity requirements. Thalorin supports the energy sector with compliance infrastructure for NERC CIP, TSA pipeline security directives, and the operational technology security controls essential for grid resilience.
Three versions of CIP-003 are in play at once. CIP-003-9 became enforceable on 1 April 2026, putting vendor electronic remote access at low impact assets under an enforceable control for the first time — methods to determine that access, disable it, and detect known or suspected inbound and outbound malicious communications across it. On 19 March 2026 FERC approved both CIP-003-10, the virtualization revisions, in Docket No. RM24-8-000, and CIP-003-11 in Docket No. RM25-8-000, effective 1 July 2028 and 1 July 2029. An entity operates one version, evidences a second and engineers for a third.
A combination utility is two regulated entities wearing one name. The electric side answers to a NERC Regional Entity under the CIP standards; the gas transmission and LNG side answers to TSA under Security Directives Pipeline-2021-01G and Pipeline-2021-02G, issued under 49 U.S.C. 114(l)(2)(A) without notice and comment. The regimes share neither vocabulary nor clocks. CIP-008-6 requires notification to the E-ISAC within one hour of determining a Reportable Cyber Security Incident; the pipeline directive allows 72 hours to CISA Central. Both start from one detection, made by the same duty analyst.
Internal network security monitoring is the requirement most often mistaken for a purchase. CIP-015-1, approved in FERC Order No. 907 on 26 June 2025, asks for visibility inside the trust zone rather than at its perimeter — east-west traffic between Cyber Systems that a firewall log never records. NERC's own implementation plan justifies the phase-in by a relatively small vendor marketplace, the time to stand up network data feeds, and the generating outages installation requires. Control Centers have until 1 October 2028 and everything else until 1 October 2030 — distant, until the work is scoped as an instrumentation programme across every substation and plant.
One brokered vendor remote-access path can answer CIP-005, the procurement terms CIP-013-2 requires of high and medium impact systems, Section 6 of CIP-003-9 Attachment 1 at low impact assets, and the segmentation section of the TSA directive — but only if the evidence knows which asset produced it. Thalorin binds evidence to the asset and carries each obligation against the registration or TSA notification that imposed it, so a changed impact rating, or a Critical Cyber System TSA adds after approval, raises the affected controls.
Critical infrastructure is under constant threat
Three CIP-003 versions on three clocks
CIP-003-9 is enforceable today, CIP-003-10 arrives with the virtualization revisions on 1 July 2028 and CIP-003-11 on 1 July 2029. Each redefines a low impact obligation, and evidence must survive the handover.
TSA can widen your Critical Cyber Systems
Owner/operators identify their own Critical Cyber Systems, but Section III.A lets TSA disagree, demand the methodology, and require systems it identifies be added to the approved Cybersecurity Implementation Plan. Every measure written against the earlier scope reopens.
One hour to E-ISAC, seventy-two to CISA
The pipeline directive's definition of a cybersecurity incident expressly covers an event still under investigation with no determined root cause. The CIP-008-6 clock does not start until a determination is made, so one event sits at different stages under each regime.
A standing assessment programme, not an audit
SD Pipeline-2021-02G requires at least one-third of the approved Implementation Plan assessed each year and 100 percent over any three-year period, plus an architecture design review every two years.
How Thalorin helps
NERC CIP compliance automation
Assess against the CIP standards enforceable for each asset today, every requirement bound to the BES Cyber Systems categorised under CIP-002, with low impact obligations carried at the asset.
TSA pipeline security directives
Hold the TSA-approved Cybersecurity Implementation Plan and Cybersecurity Assessment Plan as live artifacts, tracking the one-third annual assessment schedule and the two-year architecture design review.
OT/IT convergence security
Model IT and OT interdependencies, every external connection into the OT system and the logical zone boundaries the directive requires, so a new connection registers as a segmentation change.
SCADA system compliance
Categorise control system assets under CIP-002 and carry CIP-012-2, enforceable since 1 July 2026, for Real-time Assessment and Real-time monitoring data moving between Control Centers, against that same inventory.
Grid modernization security
Track Category 2 inverter-based resource registration separately from CIP scope: the first eight Operations and Planning standards became enforceable for Category 2 on 15 May 2026, while CIP-003 still requires modification.
Energy sector reporting
Produce the CIP-008-6 notification to the E-ISAC and NCCIC, the DOE Form OE-417 filing and the report the pipeline directive owes CISA Central from one incident record.
Energy & Utilities: common questions
Does CIP-003-9 apply to our low impact substations?
If those assets contain low impact BES Cyber Systems identified under CIP-002 and permit vendor electronic remote access, yes; the standard became enforceable on 1 April 2026. Section 6 of Attachment 1 requires documented methods for determining that access, disabling it, and detecting known or suspected inbound and outbound malicious communications across it. It is the first enforceable vendor-access control at low impact — CIP-013-2 reaches only high and medium impact systems and their associated EACMS and PACS.
How do the TSA pipeline directives differ from NERC CIP?
In instrument and in mechanics. The CIP standards are Reliability Standards approved by FERC and audited by a Regional Entity against fixed requirements. The pipeline directives are issued under 49 U.S.C. 114(l)(2)(A) without notice and comment, are performance-based, and turn on plans TSA approves for your systems. They also expire and are reissued: SD Pipeline-2021-01G runs 16 January 2026 to 15 January 2027, SD Pipeline-2021-02G 3 May 2026 to 2 May 2027.
When does internal network security monitoring have to be in place?
CIP-015-1 was approved in FERC Order No. 907 on 26 June 2025, the order taking effect 2 September 2025, with compliance phased: high impact BES Cyber Systems, and medium impact systems with external routable connectivity at Control Centers and backup Control Centers, by 1 October 2028; the remaining medium impact systems with such connectivity by 1 October 2030. FERC approved CIP-015-2 on 10 August 2026 in Docket No. RD26-6-000, extending monitoring to EACMS and PACS outside the Electronic Security Perimeter from 1 October 2029.
We registered an inverter-based resource. Are we now under CIP?
Not on registration alone. Category 2 Generator Owner and Generator Operator registration brought a first set of Operations and Planning standards into effect on 15 May 2026 — IRO-010-5, TOP-003-6.1, MOD-032-1, PRC-012-2, PRC-017-1, VAR-001-5, VAR-002-4.1 and BAL-001-TRE-2. CIP-003 is marked as requiring modification before it applies to Category 2 entities, and no compliance date is set. Treat CIP applicability as deferred, not avoided.
Do we report a cyber incident to NERC, TSA or CISA?
Potentially all three, on different clocks and different triggers. CIP-008-6 requires notification to the E-ISAC and the NCCIC within one hour of determining a Reportable Cyber Security Incident, and by the end of the next calendar day for an attempt to compromise. DOE Form OE-417 carries its own filing windows. The pipeline directive requires a report to CISA Central no later than 72 hours after the owner/operator identifies the incident.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Energy & Utilities.
See how one evidence artifact satisfies Energy & Utilities requirements alongside every other framework you carry.