Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Top 10 Computational Load Accountability Mapping Questions for Leaders
NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.
An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind [Updated]
Water utilities in at least seven states reported cyber incidents this summer, and Congress now has two answers that point in opposite directions. One bill gives EPA direct authority. The other certifies a sector-led body to write and enforce the requirements, modeled on the electric sector. A close read of what H.R. 2594 borrows from the Federal Power Act, where it departs, and what twenty years inside that model cost.
Executive Order 14421 and the Bulk-Power System Supply Chain
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
The Computational Load Entity Just Became Two
NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.
Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend
There is no rulebook for securing an OT environment, and there never could be. Two utilities can make entirely different choices and both be defensible. Here is how to build an OT risk management program you can stand behind: map your environment, rank the consequences you will not tolerate, choose controls deliberately, and document why, so you can defend every decision an auditor asks about.
What Is a Computational Load Entity?
A large AI data center used to be just a customer of the grid. On July 16, 2026, FERC changed that, directing NERC to create the Computational Load Entity, a new class of registered entity subject to mandatory federal reliability standards. A plain-English guide to what the category is and why it exists, and the anchor for the AI Reliability Boundary series.
NERC Computational Load Alert: August 3 Deadline for Utilities 2026
The NERC Level 3 alert on computational load looks voluntary, but Rule 810 makes the August 3 response mandatory, and a July FERC order turns the guidance into standards due by the end of 2026. What to file before the deadline, which gaps to start closing by role, and why unpriced AI load risk surfaces in prudency reviews, interconnection revenue, and daily penalties.
NERC Computational Load Standards: FERC Sets December 2026 Deadlines
FERC did not accelerate NERC's timeline, it made the calendar a directive and moved registration onto the critical path. The order creates the computational load entity, sets the December 31 and March 1 deadlines, and leaves the AI Reliability Boundary, the line between what the grid must command and what it leaves to private contract, for Phase II to draw. What is settled, what is not, and what to do in the next ninety days.
Cloud Comes to NERC CIP: The 100-Series and Project 2023-09
NERC did not revise the CIP Standards for the cloud. It forked them. Project 2023-09 introduces a parallel 100-Series, an entity can elect into per system, built on a new foundation called BES Cyber Services and Systems (BCSS), with System Security Plans replacing asset lists and Cyber Security Zones replacing the Electronic Security Perimeter. Here is how the parallel track works, what the first drafts actually say, and the open problems worth commenting on before August 21.
Using the Work of Others in NERC CIP and O&P Compliance
The work of others lets you lean on someone else's assessment as compliance evidence. It does not transfer accountability. This breakdown maps the ERO guidance stack, the two-part test auditors apply, worked examples for CIP-013 vendor assessments and BCSI in the cloud, the FERC FY2025 findings on delegation gone wrong, and the audit prep questions to answer first.
NERC MSPP Rules of Procedure: Standards Committee Retired in May 2026 Draft
NERC's May 2026 draft Rules of Procedure revisions retire the Standards Committee, eliminate ballot pools, restructure the Registered Ballot Body, and create a new Reliability Standards Body under the RISC. The MSPP Task Force implementation package is the most consequential governance change to NERC standards development since the ERO model was certified in 2006.
Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure
Documented load losses approaching one thousand megawatts in seconds. A Level 3 Essential Action Alert. A final Reliability Guideline. Proposed registration of a new Computational Load Entity. NERC's May 2026 actions mark a structural shift in how data centers, hyperscale AI training, and cryptocurrency mining are treated under the North American grid reliability framework.
FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do
FERC unanimously approved Order Nos. 918 and 919 on March 19, 2026, finalizing CIP virtualization standards and new low-impact BES Cyber System controls, plus an updated "Control Center" definition. All CIP-registered entities are affected. Implementation windows are 24 and 36 months respectively. Compliance programs should begin gap assessments now.
Redesigning the Machine: NERC Board Accepts Transformational Standards Modernization Plan
The NERC Board has approved a historic transformation of the standards development process to meet the speed of the modern grid. Aiming for a 12–18 month timeline, the new framework re-engineers how NERC addresses risks from data centers, IBRs, and VPPs. Read our deep dive into the 2027 roadmap, the new SME pool, and the upcoming shift in voting eligibility.
NERC’s CIP Roadmap and the Future of Grid Cybersecurity
NERC’s new CIP Roadmap signals a major shift in how cyber risk will be regulated across the power grid. This Policy Pulse explains what NERC released, why it matters, what standards and guidance are coming next, and how utilities, generators, and grid operators should prepare for expanding CIP scope and enforcement.
From Firefighting to Foresight: Building CIP Programs for the Future Power Grid
NERC calls grid reliability a “five-alarm fire.” With data centers, AI, and extreme weather straining capacity, CIP programs must evolve from reactive compliance to proactive resilience. This post outlines how utilities can strengthen controls, close documentation gaps, and build CIP programs ready for the future grid.
FERC 2025 CIP Audit Findings: DER Impact Ratings, Vendor Oversight Gaps, and Cloud Compliance Risk
FERC’s latest CIP audit lessons for 2025 highlight three rising compliance risks. Entities are undercounting DERs in GOP control center impact ratings, outsourcing compliance work without adequate oversight, and moving EACMS or PACS functions to the cloud without a defensible evidence path. These issues now represent real audit exposure across the US bulk power system.
Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management
FERC Order 912 marks a shift in supply chain cybersecurity for the Bulk-Power System. It directs NERC to strengthen supply chain protections by closing gaps in risk identification, reassessment, and response, and by extending coverage to Protected Cyber Assets. Vendor data validation is encouraged but not mandated, and NERC has 18 months to deliver new or revised standards.
Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains
FERC’s September 2025 actions reshaped grid reliability standards by tightening security requirements for low-impact assets, adding authentication, encryption, and monitoring; new requirements and new definitions to support secure adoption of virtualization technologies; and expanding supply chain protections to cover Protected Cyber Assets and other connected systems.
CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope
FERC Order 907-A clarifies CIP-015 on shared networks. INSM must monitor only east-west traffic used for access monitoring of EACMS and PACS. Non-CIP assets and data flows are out of scope, even in mixed-use or commingled PACS/EACMS environments. Learn practical patterns to filter collection, segment analytics, and produce audit-ready evidence.