Independent field guideNERC CIP-015

Know your normal.Detect the anomalous.

A live compliance clock and practical guide to building internal network security monitoring that is useful, defensible, and ready before the compliance date.

Phase 1 · High impact + medium w/ ERC LIVE
Days
Hours
Min
Sec
Phase 1 window elapsed —%
FERC approval · Jun 2025 Oct 1, 2028
Target: Oct 1, 2028 · 00:00 EDT days to Phase 2
Approved standardsCIP-015-1 + CIP-015-2 Oct 2028CIP-015-1 first milestone Oct 2029CIP-015-2 becomes effective Through 2031Expanded-scope phases

The requirement, without the fog

Three things every defensible INSM program must do.

CIP-015 is not simply a sensor requirement. It creates a detect-and-evaluate loop, then asks you to preserve and protect the evidence that supports it.

R1

Monitor, detect, evaluate

Use risk-based network data feeds, detect anomalous network activity, and evaluate what you find to determine whether further action is needed.

R2

Retain the evidence

Keep monitoring data associated with an identified anomaly until evaluation and response activities are complete.

R3

Protect the record

Protect collected and retained monitoring data from unauthorized deletion or modification.

The compliance clock

Two approved versions. Four compliance milestones.

For FERC-jurisdictional entities, CIP-015-1 begins the transition in 2028. CIP-015-2 becomes effective in 2029 and completes the expanded-scope rollout in 2031.

CIP-015-1 first milestone

High-impact BCS and medium-impact BCS with ERC at Control Centers and backup Control Centers, together with their associated PCA, reach the first compliance date.

CIP-015-2 becomes effective

CIP-015-1 retires. The expanded scope begins for associated EACMS, PACS, and supporting SCI serving high-impact BCS and applicable medium-impact Control Center environments.

Remaining medium-impact BCS

Remaining medium-impact BCS with ERC, their associated PCA, and supporting SCI reach their compliance milestone.

Expanded scope fully phased in

Associated EACMS, PACS, and supporting SCI for the remaining applicable medium-impact environments reach their compliance milestone.

FERC approved CIP-015-2 on August 10, 2026. Status checked August 2026. Always confirm the implementation plan and jurisdictional dates against NERC's official CIP-015-2 record.

The approved foundation. The approved expansion.

The obligation remains. The scope expands.

CIP-015-1 establishes the INSM foundation. FERC-approved CIP-015-2 carries that foundation into a broader set of applicable systems and in-scope communication paths.

Approved · Future enforcement CIP-015-1

Inside applicable ESPs

The approved scope covers networks protected by the Responsible Entity's ESPs for high-impact BES Cyber Systems and medium-impact BES Cyber Systems with External Routable Connectivity.

High-impact BCS Medium-impact BCS with ERC Associated PCA

The first milestone arrives October 1, 2028. CIP-015-1 retires immediately before CIP-015-2 becomes effective on October 1, 2029.

Approved · Future enforcement CIP-015-2

Across the CIP-networked environment

The approved revision extends the applicable-system scope to associated EACMS and PACS outside the ESP, along with supporting Shared Cyber Infrastructure and the in-scope communication paths between applicable CIP devices.

EACMS PACS Supporting SCI

The expanded-scope milestones begin October 1, 2029 and continue through October 1, 2031.

FERC approved CIP-015-2 by letter order on August 10, 2026 in Docket No. RD26-6-000. NERC lists the standard as subject to future enforcement. Confirm against NERC's official CIP-015-2 record and the FERC approval record.

From clock to capability

A practical readiness path.

The deadline is when the program must be working and defensible. Procurement is only one step.

01 · Map

Identify in-scope communication paths and visibility gaps across applicable BCS and associated PCA, EACMS, PACS, and supporting SCI.

02 · Design

Choose defensible data feeds and document the risk-based rationale behind each one.

03 · Detect

Build a living understanding of normal behavior so anomalous activity stands out.

04 · Operationalize

Define triage, evaluation, retention, protection, and evidence-handling workflows.

05 · Prove

Test the program and produce audit-ready evidence before the compliance date arrives.

Oct 1, 2028

A working, defensible INSM program by the Phase 1 compliance date.

Budget → procure → deploy → tune → prove.
Each step is measured in quarters, not weeks.

Externally hosted · DarktraceRead the countdown article ↗

Analysis & primary sources

Go deeper than the countdown.

Start with the official record. Then explore practical interpretation grounded in real OT environments.

About the author

Portrait of Jeffrey Macre
Jeffrey Macre OT Cybersecurity · Author · Educator

Jeffrey Macre writes and teaches about operational technology, critical infrastructure, and cybersecurity. CIP15Clock is an independent project designed to make an important standard easier to understand and harder to ignore.