Ampyx Cyber Blog

The Intersection of Regulation & Resilience

FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do

FERC unanimously approved Order Nos. 918 and 919 on March 19, 2026, finalizing CIP virtualization standards and new low-impact BES Cyber System controls, plus an updated "Control Center" definition. All CIP-registered entities are affected. Implementation windows are 24 and 36 months respectively. Compliance programs should begin gap assessments now.

Read More
Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains

FERC’s September 2025 actions reshaped grid reliability standards by tightening security requirements for low-impact assets, adding authentication, encryption, and monitoring; new requirements and new definitions to support secure adoption of virtualization technologies; and expanding supply chain protections to cover Protected Cyber Assets and other connected systems.

Read More
FERC Quietly Closes The Books on RM20-12-000
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Quietly Closes The Books on RM20-12-000

FERC has officially closed Docket RM20-12-000, ending a five-year inquiry into potential gaps in the CIP Reliability Standards. While the docket is withdrawn, the underlying concerns—data security, anomaly detection, and coordinated cyberattacks—are being addressed through recent standards like CIP-015-1 (INSM) and proposed updates to CIP-003.

Read More
FERC Chairman's Reliability Report: A Year in Review
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Chairman's Reliability Report: A Year in Review

In 2023, FERC Chairman Willie L. Phillips' report highlighted advancements in U.S. power grid reliability, focusing on enhanced cybersecurity measures, physical grid security improvements, and resilience against extreme weather. Key initiatives included the implementation of new cybersecurity standards, incentive-based cybersecurity investments, and transmission reforms to accommodate evolving energy resources. These efforts underscore FERC's commitment to maintaining a resilient and secure electric grid.

Read More
Inverter-Based Resources - Guide to Potential NERC CIP Impacts of Upcoming Regulatory Changes
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Inverter-Based Resources - Guide to Potential NERC CIP Impacts of Upcoming Regulatory Changes

Upcoming NERC regulatory changes are expected to result in a significant increase in registrations of inverter-based resources, resulting in the likelihood of control centers to be categorized as North American Electrical Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Medium-Impact Control Centers and/or Low-Impact Control Centers and correspondingly to meet the relevant NERC CIP requirements.

Read More
New Low Impact NERC CIP-003-9 Regulations: Vendor Supply Chain Security
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

New Low Impact NERC CIP-003-9 Regulations: Vendor Supply Chain Security

On March 16 2023, FERC issued a new Order approving NERC CIP-003-9 introducing new requirements for vendor electronic remote access security controls to low impact BES Cyber Systems. These new security controls are intended to allow detection and the ability to disable vendor remote access in the event of a known or suspected malicious communication.

Read More
New cybersecurity controls for vendor access to low impact NERC CIP assets
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

New cybersecurity controls for vendor access to low impact NERC CIP assets

FERC has approved new cybersecurity standards to improve risk management practices and supply chain risk management for low impact assets. The new standards, designated CIP-003-9, require utilities to establish and maintain a documented supply chain cyber risk management plan and implement vendor-focused cybersecurity protections for their low impact BES Cyber Systems.

Read More