Monitor, detect, evaluate
Use risk-based network data feeds, detect anomalous network activity, and evaluate what you find to determine whether further action is needed.
Independent field guideNERC CIP-015
A live compliance clock and practical guide to building internal network security monitoring that is useful, defensible, and ready before the compliance date.
The requirement, without the fog
CIP-015 is not simply a sensor requirement. It creates a detect-and-evaluate loop, then asks you to preserve and protect the evidence that supports it.
Use risk-based network data feeds, detect anomalous network activity, and evaluate what you find to determine whether further action is needed.
Keep monitoring data associated with an identified anomaly until evaluation and response activities are complete.
Protect collected and retained monitoring data from unauthorized deletion or modification.
The compliance clock
For FERC-jurisdictional entities, CIP-015-1 begins the transition in 2028. CIP-015-2 becomes effective in 2029 and completes the expanded-scope rollout in 2031.
High-impact BCS and medium-impact BCS with ERC at Control Centers and backup Control Centers, together with their associated PCA, reach the first compliance date.
CIP-015-1 retires. The expanded scope begins for associated EACMS, PACS, and supporting SCI serving high-impact BCS and applicable medium-impact Control Center environments.
Remaining medium-impact BCS with ERC, their associated PCA, and supporting SCI reach their compliance milestone.
Associated EACMS, PACS, and supporting SCI for the remaining applicable medium-impact environments reach their compliance milestone.
FERC approved CIP-015-2 on August 10, 2026. Status checked August 2026. Always confirm the implementation plan and jurisdictional dates against NERC's official CIP-015-2 record.
The approved foundation. The approved expansion.
CIP-015-1 establishes the INSM foundation. FERC-approved CIP-015-2 carries that foundation into a broader set of applicable systems and in-scope communication paths.
The approved scope covers networks protected by the Responsible Entity's ESPs for high-impact BES Cyber Systems and medium-impact BES Cyber Systems with External Routable Connectivity.
The first milestone arrives October 1, 2028. CIP-015-1 retires immediately before CIP-015-2 becomes effective on October 1, 2029.
The approved revision extends the applicable-system scope to associated EACMS and PACS outside the ESP, along with supporting Shared Cyber Infrastructure and the in-scope communication paths between applicable CIP devices.
The expanded-scope milestones begin October 1, 2029 and continue through October 1, 2031.
FERC approved CIP-015-2 by letter order on August 10, 2026 in Docket No. RD26-6-000. NERC lists the standard as subject to future enforcement. Confirm against NERC's official CIP-015-2 record and the FERC approval record.
From clock to capability
The deadline is when the program must be working and defensible. Procurement is only one step.
Identify in-scope communication paths and visibility gaps across applicable BCS and associated PCA, EACMS, PACS, and supporting SCI.
Choose defensible data feeds and document the risk-based rationale behind each one.
Build a living understanding of normal behavior so anomalous activity stands out.
Define triage, evaluation, retention, protection, and evidence-handling workflows.
Test the program and produce audit-ready evidence before the compliance date arrives.
A working, defensible INSM program by the Phase 1 compliance date.
Budget → procure → deploy → tune → prove.
Each step is measured in quarters, not weeks.
Analysis & primary sources
Start with the official record. Then explore practical interpretation grounded in real OT environments.
A practical look at visibility, anomaly detection, evaluation, evidence, and the work that needs to happen now.
Read article ↗Stay on the clock
Implementation milestones, date changes, new analysis. No noise.