Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs

NERC CIP compliance is no longer a checklist exercise. Internal controls are now how the ERO Enterprise measures whether an entity can sustain compliance over time. This post breaks down what internal controls are, the preventive, detective, and corrective types, how entities test and evidence them, and how WECC's ICDCT and the December 2025 ERO Guide put controls at the center of audit scoping.

Read More
How CMEP Version 8 Reshapes NERC’s Compliance Model
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

How CMEP Version 8 Reshapes NERC’s Compliance Model

The CMEP Version 8 does not rewrite NERC compliance, rather it stabilizes it. Building on years of evolution, the updated Manual reinforces risk-based oversight, professional judgment, technical competence, and enterprise consistency across all Reliability Standards. The result is a more mature, defensible compliance model that shapes how audits, enforcement, and reliability governance now operate.

Read More
Strategic Value of Self-Reporting in NERC CIP Compliance
Deep Dive Patrick Miller Deep Dive Patrick Miller

Strategic Value of Self-Reporting in NERC CIP Compliance

Self-reporting in NERC CIP isn’t a weakness. It’s a sign of maturity. Proactive disclosures build regulatory trust, reinforce internal controls, and empower compliance teams to improve. When done right, self-reporting signals ownership, not failure, and positions your program as resilient, transparent, and credible.

Read More