Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order

DOE's Request for Information on Executive Order 14421 includes one question, H-3, asking whether industry standards bodies and third-party labs can execute the order instead of the federal government. The electric sector ran something close to this before, under the Electric Reliability Organization. This post looks at what changes when the statute is IEEPA, not the Federal Power Act, and what a working precedent outside the sector suggests.

Read More
Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment

DOE has opened a 30-day request for information on how it will implement Executive Order 14421, the order restricting foreign-produced bulk-power system equipment. The most consequential questions concern equipment already installed, since the order does not grandfather it, and how DOE will define "foreign-produced" in the first place. Comments are due October 9, with a public webinar on September 16.

Read More
Top 10 Computational Load Accountability Mapping Questions for Leaders
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Top 10 Computational Load Accountability Mapping Questions for Leaders

NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.

Read More
Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]

An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.

Read More
The Computational Load Entity Just Became Two
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

The Computational Load Entity Just Became Two

NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.

Read More
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

The AI Reliability Boundary: A Black Hat Debrief for the Grid

Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.

Read More
Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook

Virginia moves cyber into DER interconnection. State Corporation Commission (SCC) Staff proposes adopting IEEE 1547.3-2023 and the NARUC/DOE Baselines, requiring utilities to publish minimum cybersecurity standards, audit & report annually, and align Technical Interconnection (TIIR) settings for secure comms/ports. Bottom line: meeting utility cyber controls becomes a condition of interconnection.

Read More