Ampyx Cyber Blog

The Intersection of Regulation & Resilience

CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline

FERC approved Reliability Standard CIP-015-2 on August 10, 2026 in a delegated letter order, uncontested and about as short as FERC orders get. The order says the approval is effective as of the date of the order, and that line has caused more confusion than anything else in it. It sets the effective date of the Commission's action, not of anyone's compliance obligation. The internal network security monitoring clock lives in the implementation plan, and it was fixed by CIP-015-1's schedule long before FERC signed. This post walks the two prongs of the effective date calculation, lays out all four compliance dates from October 1, 2028 through October 1, 2031, and explains why the second phase is a carried-forward obligation rather than the one-year extension some entities have read it as.

Read More
CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope

FERC Order 907-A clarifies CIP-015 on shared networks. INSM must monitor only east-west traffic used for access monitoring of EACMS and PACS. Non-CIP assets and data flows are out of scope, even in mixed-use or commingled PACS/EACMS environments. Learn practical patterns to filter collection, segment analytics, and produce audit-ready evidence.

Read More
FERC Finalizes INSM Standard: CIP-015-1 and the New Visibility Mandate for the Grid
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Finalizes INSM Standard: CIP-015-1 and the New Visibility Mandate for the Grid

On June 26, the Federal Energy Regulatory Commission issued Order No. 907, approving the new NERC Reliability Standard CIP-015-1: Cyber Security – Internal Network Security Monitoring (INSM). This marks a critical shift in how we approach cybersecurity within the Bulk Electric System. It also raises the bar significantly on what’s expected for visibility inside the network perimeter.

Read More