FERC Approves NERC CIP-015-2: What It Means for Your INSM Program

Table of Contents

On August 10, 2026, the Federal Energy Regulatory Commission (FERC) approved Reliability Standard CIP-015-2 by letter order. The North American Electric Reliability Corporation (NERC) announced the approval publicly on August 17. NERC CIP-015-2 is a significant regulatory milestone for the electric sector, expanding internal network security monitoring (INSM) requirements and changing the scope of what utilities are expected to monitor.

Here is what happened, what it means, and what you should do now.

Internal network security monitoring (INSM) is the continuous monitoring of network traffic inside a trusted zone to detect adversary activity that has already bypassed the perimeter. CIP-015-2 applies INSM requirements to High Impact and Medium Impact BES Cyber Systems with External Routable Connectivity and the following associated asset types (examples of each are noted in parentheses):

  • EACMS (firewalls, authentication gateways)
  • PACS (access control servers, physical security monitoring systems)
  • PCAs (engineering workstations, patch management servers)
  • SCI (virtualization platforms, shared storage infrastructure)

FERC directed the EACMS and PACS expansion through Order No. 907; the standard drafting team added SCI independently to ensure that the Standard addressed these risks for all relevant asset categorizations that will exist upon the effective date of CIP-015-2. SCI is a term defined under Project 2016-02 Virtualization, which FERC approved in Order 919 in March 2026 with an effective date of July 1, 2028.

For a detailed breakdown of the security gap rationale and what each category requires, see NERC CIP-015-2: EACMS, PACS, SCI Monitoring Explained.

The expansion of INSM to EACMS, PACS, and SCI reflects a threat environment that has been getting more specific. Dragos’s 2026 OT Cybersecurity Year in Review documented a meaningful shift in adversary behavior: threat groups are moving beyond pre-positioning into active reconnaissance of control loops, mapping how physical processes can be manipulated.

Threat GroupRelevant Activity
KAMACITEResponsible for Ukraine’s 2015 power outage; conducted systematic reconnaissance of U.S. operator interfaces, actuators, meters, and remote gateways between March and July 2025
VOLTZITEMaintains persistent access in U.S. electric and telecommunications environments, collecting grid topology, GIS, and operational configuration data to support future disruption
ELECTRUMResponsible for Ukraine’s 2016 outage; expanded into Europe in December 2025 targeting wind and solar in the first coordinated attack against distributed energy resources at scale
SYLVANITETargets electric utilities through IT-side intrusions, using that access as a pathway toward OT environments

SYLVANITE’s approach illustrates the broader structural point: the threat to operational technology does not always arrive through the control system network directly. EACMS, PACS, and SCI sit at exactly the boundary where IT and OT intersect, which is why their inclusion in CIP-015-2 scope is not an administrative expansion. It is a response to how adversaries are actually operating.

The gap between adversary capability and utility visibility is measurable. Dragos OT assessments found that only 46 percent of environments had adequate network monitoring deployed, meaning more than half lacked the visibility needed to detect adversary activity inside the network, evaluate it, or connect it to an incident response process. For electric utilities working toward NERC CIP-015 compliance, that statistic is the compliance case in a single number: the monitoring baseline these standards mandate is exactly what most organizations do not yet have.

The standard is catching up to address these types of threats.

There is one near-term date that is not changing: October 1, 2028. That is when CIP-015-1 first becomes enforceable, requiring High and Medium Impact BCS with ERC at Control Centers and backup Control Centers to have INSM in place inside the ESP.

Twelve months later, CIP-015-2 takes effect and CIP-015-1 is retired. From that point forward, the CIP-015-2 implementation plan governs all compliance obligations. The phased schedule for FERC-jurisdictional entities:

Date
Standard
Scope
Oct 1, 2028
CIP-015-1 enforceable
High + Medium Impact BCS with ERC at Control Centers and backup Control Centers
Oct 1, 2029
CIP-015-2 Phase 1 (CIP-015-1 retires)
Cyber Systems that are part of EACMS, PACS, and supporting SCI associated with High + Medium Impact BCS with ERC at Control Centers and backup Control Centers
Oct 1, 2030
CIP-015-2 Phase 2a
Cyber Systems that are part of remaining Medium Impact BCS with ERC + PCAs + supporting SCI
Oct 1, 2031
CIP-015-2 Phase 2b, fully enforceable
Cyber Systems that are part of EACMS, PACS, and supporting SCI associated with all other Medium Impact BCS with ERC

The phasing prioritizes the highest-reliability-risk environments first. Control Centers come first because a compromise there has the broadest potential impact on grid reliability. The more distributed asset population, substations, generation facilities, and other medium-impact sites, follows because those environments involve more complexity: wider geographic spread, varying connectivity, and implementation work that may require scheduled outages.

October 2029 is 26 months away. For entities that have not yet inventoried EACMS and PACS, developed network diagrams sufficient to plan sensor placement, or engaged IT stakeholders who own these systems, that is not a comfortable runway.

With the approval confirmed, the practical priorities are straightforward regardless of where your program stands.

  • Do not design your CIP-015 architecture to stop at the ESP boundary. Entities that build monitoring infrastructure with CIP-015-2 scope in mind now will avoid a costly rework cycle before October 2029. That means choosing technology that supports flexible deployment across both OT and IT-managed environments, and baselining EACMS, PACS, and SCI alongside BES Cyber Systems from the start.
  • Inventory EACMS, PACS, and SCI now. Entities may not have classified these assets with the same rigor as BES Cyber Systems or may maintain multiple asset inventories with individual owners. Review your CIP-002 inventories, engage the IT teams who own these systems, and validate your network diagrams against actual architecture.
  • Engage IT stakeholders early. EACMS, PACS, and SCI frequently live in IT-managed environments. Compliance teams cannot implement CIP-015-2 without them.

For a detailed implementation guide covering collection, detection, analysis, retention, scoping challenges, and sensor placement across all three asset categories, see Preparing for CIP-015-2: How to Implement INSM for EACMS, PACS, and SCI Monitoring.

The Dragos Platform supports the collect, detect, and evaluate framework across both ESP-internal environments that include PCAs and the EACMS, PACS, and SCI environments that CIP-015-2 now brings into scope. Its deployment architecture covers OT and IT protocols, flexible sensor collection methods, and centralized management across distributed sites. OT Watch provides managed threat hunting coverage for entities building toward full internal analyst capability.

For entities evaluating where to start, Dragos offers INSM strategy sessions with practitioners who have worked directly with utilities on CIP-015 implementation planning.

Learn more about the Dragos Platform and INSM.

Phil Tonkin is the Field Chief Technology Officer at Dragos. Before this, he held the position of Chief of Staff as the company’s top strategic advisor to the CEO, Robert M. Lee.
Kristine Martz is Principal Product Advisor for Dragos Inc. and has over fifteen years of experience in power and utilities cybersecurity and regulatory compliance, with expertise in NERC standards and real-time systems security.