Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order
DOE's Request for Information on Executive Order 14421 includes one question, H-3, asking whether industry standards bodies and third-party labs can execute the order instead of the federal government. The electric sector ran something close to this before, under the Electric Reliability Organization. This post looks at what changes when the statute is IEEPA, not the Federal Power Act, and what a working precedent outside the sector suggests.
Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment
DOE has opened a 30-day request for information on how it will implement Executive Order 14421, the order restricting foreign-produced bulk-power system equipment. The most consequential questions concern equipment already installed, since the order does not grandfather it, and how DOE will define "foreign-produced" in the first place. Comments are due October 9, with a public webinar on September 16.
Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management
FERC Order 912 marks a shift in supply chain cybersecurity for the Bulk-Power System. It directs NERC to strengthen supply chain protections by closing gaps in risk identification, reassessment, and response, and by extending coverage to Protected Cyber Assets. Vendor data validation is encouraged but not mandated, and NERC has 18 months to deliver new or revised standards.
FERC’s New Proposed Rule on Supply Chain Risk Management (SCRM)
The Federal Energy Regulatory Commission (FERC) has released a new Notice of Proposed Rulemaking (NOPR) under Docket No. RM24-4-000, focusing on supply chain risk management (SCRM) for the Bulk-Power System (BPS). This proposed directive aims to fill critical gaps in existing NERC Critical Infrastructure Protection (CIP) standards and bolster the defenses of our nation’s critical infrastructure.
Is SBOM the answer?
Government and industry experts have recently pointed to software bill of materials (SBOM) as a requirement for organizations, but what are you getting? David Foose spends some time exploring aspects of SBOM fever.
A former vendor's take on CIP-013 Supply Chain Risk Management
David Foose, a former vendor, takes us on a brief walk through the history and the justifications Supply Chain Security and the birth of NERC CIP 13. With this, we explore what might have been and where it may have unfortunately veered off into constant contract negotiation entities find themselves today.