CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline
By Patrick Miller
FERC approved Reliability Standard CIP-015-2 on August 10, 2026 in a delegated letter order, uncontested and about as short as FERC orders get. The order says the approval is effective as of the date of the order, and that line has caused more confusion than anything else in it. It sets the effective date of the Commission's action, not of anyone's compliance obligation. The internal network security monitoring clock lives in the implementation plan, and it was fixed by CIP-015-1's schedule long before FERC signed. This post walks the two prongs of the effective date calculation, lays out all four compliance dates from October 1, 2028 through October 1, 2031, and explains why the second phase is a carried-forward obligation rather than the one-year extension some entities have read it as.
Overview
FERC approved Reliability Standard CIP-015-2, Cyber Security, Internal Network Security Monitoring (INSM), on August 10, 2026. It came through as a delegated letter order in Docket No. RD26-6-000. Two pages, and one of those is mostly footnotes and a signature block. I think it's probably the shortest FERC order I've ever read. Nobody protested it, which is most of the explanation. The North American Electric Reliability Corporation (NERC) filed in June, three Ameren entities intervened, none of them opposed anything, and the Commission approved the filing as uncontested, so there wasn't a lot left to write down. The order approves the standard, the implementation plan, the violation risk factors and violation severity levels, and the retirement of CIP-015-1. That's the whole package.
What the Order Did, and What It Didn't
Here's the sentence causing most of the trouble.
"Effective as of the date of this order" means the Commission's action took effect on August 10. It doesn't mean anyone has to comply with anything on August 10, or twelve months after August 10, or on any date derived from August 10. The compliance clock lives in the implementation plan, and that plan was written to key off CIP-015-1's schedule.
The rest of the procedural history is rather unremarkable, which is sort of the point. Nobody protested, and nobody opposed the motions. The order states that it constitutes final agency action, with rehearing requests due within 30 days of issuance, so September 9, 2026.
Why August 10 Didn't Move Anything
The implementation plan sets the effective date as the later of two things. Where governmental approval is required, CIP-015-2 becomes effective the later of twelve months after the effective date of CIP-015-1, or the first day of the first calendar quarter that's twelve months after the effective date of the order approving CIP-015-2.
Run both of those against an August 10, 2026 order.
| Prong | Calculation | Result |
|---|---|---|
| 12 months after the CIP-015-1 effective date | 10/1/2028 plus 12 months | 10/1/2029 (controls) |
| First day of the first calendar quarter 12 months after approval | 8/10/2026 plus 12 months is 8/10/2027, next quarter start | 10/1/2027 |
The first prong is later, so it controls. CIP-015-2 becomes effective October 1, 2029.
Which means FERC could have approved this in September 2026, or January 2027, or somewhere in the middle of 2028, and every date below would be identical. The second prong only starts to bind if approval had slipped past October 1, 2028, more than two years after NERC filed. NERC filed in June with the schedule already fixed by CIP-015-1's own clock. The order confirms the timeline. It didn't create it.
The Dates That Actually Matter
| Date | Milestone | What it means |
|---|---|---|
| 9/2/2025 | FERC Order No. 907 takes effect | The approval of CIP-015-1 becomes effective. CIP-015-1's clock runs 36 months from here, to 9/2/2028, then forward to the first calendar quarter that starts on or after that. |
| 10/1/2028 | CIP-015-1 effective date | Internal network security monitoring (INSM) becomes enforceable for the first time. Inside the electronic security perimeter (ESP) only, for high impact BES Cyber Systems (BCS) and medium impact BCS with external routable connectivity (ERC) at Control Centers and backup Control Centers. |
| 10/1/2029 | CIP-015-2 effective date, Phase 1, and CIP-015-1 retirement | Electronic Access Control or Monitoring Systems (EACMS), Physical Access Control Systems (PACS), and supporting Shared Cyber Infrastructure (SCI) associated with high and medium impact BCS with ERC at Control Centers and backup Control Centers. |
| 10/1/2030 | Phase 2a | Remaining medium impact BCS with ERC, associated Protected Cyber Assets (PCA), and supporting SCI at assets other than Control Centers. |
| 10/1/2031 | Phase 2b | EACMS, PACS, and supporting SCI associated with those non-Control-Center medium impact BCS. CIP-015-2 fully enforceable. |
CIP-015-1 retires immediately before CIP-015-2 becomes effective in each jurisdiction, so there's no gap and no overlap. The v1 obligations aren't released, rather they're absorbed. Entities outside FERC jurisdiction run the same sequence off NERC Board of Trustees adoption of CIP-015-1.
Two sourcing notes, because both of these will trip someone up. October 1, 2028 does not appear in the CIP-015-2 implementation plan. That plan works entirely in relative month counts. The date comes from the Project 2023-03 implementation plan for CIP-015-1, which is still fully operative. If you're citing it internally, cite 2023-03.
And if you go pull the CIP-015-2 implementation plan yourself, use the version filed with the June 2026 petition, which is what FERC approved. The December 2025 posting tends to surface first in a search, and it numbers and words the later phases differently enough to put you a year off.
Phase 2a Isn't an Extension
This is the misreading I've run into most often. Be sure to review the table again. If you've got medium impact BCS with ERC at substations or generating plants, and you've been building toward October 1, 2030 under CIP-015-1, your date is still October 1, 2030. It just lives in a different document now.
CIP-015-1 gave non-Control-Center medium impact BCS 24 months past its own effective date, and that lands on October 1, 2030. Since CIP-015-1 retires on October 1, 2029, the obligation had to be re-homed somewhere, and Phase 2a is where it went. This comes with no relief and no acceleration. Outside the Control Centers, the new work shows up in Phase 2b, on October 1, 2031.
The Split That Drives Your Scope
The same class of device can be due in 2029, due in 2031, or out of scope entirely, depending on what it's associated with. A PACS controller or panel associated with a Control Center's high impact BCS, or with a medium impact BCS with ERC at a Control Center, is on the 2029 clock. The same panel associated instead with a medium impact BCS with ERC at a substation or generating plant is on the 2031 clock. And a panel associated only with BCS that are medium impact without ERC, or low impact, isn't in CIP-015-2 at all, wherever it happens to sit.
Be careful about what actually drives your determinations. It isn't where the panel is racked. It's the BES Cyber System the panel is associated with, and that system's impact rating, its ERC status, and whether it sits at a Control Center. Which makes CIP-002 asset identification the thing gating everything downstream, and turns commingled PACS and EACMS from an academic scoping question into a scheduling one. We went through that in some detail after Order No. 907-A clarified the boundaries, and nothing in this order shifts that analysis.
There's also a second thread running through all three phases. Every one of them reaches supporting SCI, and Phase 2b puts it plainly as "EACMS, PACS, and SCI supporting an applicable system." That ties your CIP-015-2 dates to the virtualization standards. If you're hosting EACMS or PACS on shared infrastructure, you pick up INSM obligations on the same schedule, and working out what counts as supporting SCI isn't a five-minute exercise. That one probably deserves its own post.
Why We Keep Saying Start Now
The framing here is that October 1, 2028 is the date most entities are actually building toward right now, and it isn't the date in this order. That's the CIP-015-1 date, INSM inside the ESP. The CIP-015-2 dates push the same discipline outward to the access control layer, a year later for Control Centers and three years later for everything else. Three years will happen fast.
October 1, 2029 is an initial compliance date, not a start date. On that morning you need collection running, evaluation procedures in use, and evidence being retained and protected. Everything that gets you to that state has to happen before it.
The long-lead items are genuinely long. Sensor procurement, network changes that need an outage window, and data ingestion capacity all get measured in quarters. The implementation plan itself points at a "relatively small vendor marketplace" as a constraint, and more or less everyone who waits will be shopping in that market at the same time.
The scoping work, though, has no dependencies. Working out which EACMS and PACS are in scope, where each one sits, and what it's associated with doesn't need procurement, a budget cycle, or a vendor. It needs people who know your architecture, and a decision about how you're going to document what they find. That part can start now.
If you're looking for somewhere to begin, the CIP-015-1 playbook still holds for the v1 obligations, and the NATF guidance is still the most useful practical reference we've seen on collection points, retention, and what counts as good enough visibility. Most of it carries outward to the access control layer without much translation.
What I keep coming back to is how quiet all of this has been. A two-page letter, no protests, and four dates that were settled before most people noticed. The 2029 and 2031 obligations are real and specific, and they land on equipment a lot of entities haven't inventoried yet. I don't think we're behind, maybe. But the scoping conversations I'm having still sound like early conversations, and 2028 isn't that far out.
Our earlier coverage of CIP-015:
CIP-015 Clarified: Mixed-use PACS/EACMS and What's Actually In Scope (August 29, 2025), on Order No. 907-A.
INSM Just Got Clearer: Key Takeaways from the NATF Guidance (October 22, 2025).
CIP-015-1 INSM: A Practical Playbook (August 13, 2025).
Monitoring Meets Mandate: Will the Next CIP-015 Standard Deliver on FERC's Vision? (July 20, 2025), on the Project 2025-02 SAR that became CIP-015-2.
FERC Finalizes INSM Standard: CIP-015-1 and the New Visibility Mandate for the Grid (June 28, 2025), on Order No. 907.
FERC Proposes New Standards for INSM: Internal Network Security Monitoring (CIP-015-1) (September 19, 2024), on the NOPR in Docket RM24-7-000.
CIP-015: The Crucial Role of INSM in Strengthening Grid Security (March 27, 2024), on the drafting history back to Order No. 887.