Expanded Monitoring Requirements
The Federal Energy Regulatory Commission approved Reliability Standard CIP-015-2 by letter order on August 10, 2026. This regulatory update expands internal network security monitoring requirements to High and Medium Impact BES Cyber Systems with External Routable Connectivity, forcing utilities to secure assets that sit at the intersection of IT and operational technology.[1][2]
The updated standard adds EACMS, PACS, and SCI asset categories to the monitoring scope. This expansion targets a vulnerability, as adversary threat groups are moving beyond pre-positioning into active reconnaissance of control loops.[3][4]
Most utilities are not prepared for the change. Dragos OT assessments found that only 46 percent of environments had adequate network monitoring deployed.[5]
The transition follows a strict regulatory timeline. While CIP-015-1 becomes enforceable on October 1, 2028, CIP-015-2 Phase 1 takes effect on October 1, 2029, at which point CIP-015-1 is retired. Phase 2a of the new standard becomes enforceable on October 1, 2030.[6][7][8]
Key takeaways
- CIP-015-2 expands INSM requirements to include EACMS, PACS, and SCI, moving beyond traditional BES Cyber Systems. 1 source
- The expansion is a direct response to threat groups like SYLVANITE, which exploit IT-side access to reach OT environments. 1 source
- Dragos assessments indicate that over 50% of utility environments currently lack the network visibility required for compliance. 1 source
- Inventory all EACMS, PACS, and SCI assets immediately to prepare for the 2029 compliance deadline. 1 source
- Engage IT stakeholders early, as these assets often reside in IT-managed environments outside traditional OT control. 1 source
- Design monitoring architecture to support flexible deployment across both OT and IT-managed environments to avoid costly rework. 1 source
Notable quotes
“the threat to operational technology does not always arrive through the control system network directly.”
“the monitoring baseline these standards mandate is exactly what most organizations do not yet have.”
What’s unresolved
- Specific technical remediation costs for utilities lacking current visibility.
- Potential for further scope expansion beyond EACMS, PACS, and SCI.
Citations
- [1] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program The Federal Energy Regulatory Commission approved Reliability Standard CIP-015-2 by letter order on August 10, 2026. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [2] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program NERC CIP-015-2 expands internal network security monitoring (INSM) requirements to High and Medium Impact BES Cyber Systems with External Routable Connectivity. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [3] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program CIP-015-2 adds EACMS, PACS, and SCI asset categories to the INSM scope. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [4] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program Adversary threat groups are moving beyond pre-positioning into active reconnaissance of control loops. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [5] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program Dragos OT assessments found that only 46 percent of environments had adequate network monitoring deployed. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [6] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program CIP-015-1 becomes enforceable on October 1, 2028. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [7] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program CIP-015-2 Phase 1 takes effect on October 1, 2029, at which point CIP-015-1 is retired. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP
- [8] FERC Approves NERC CIP-015-2: What It Means for Your INSM Program CIP-015-2 Phase 2a becomes enforceable on October 1, 2030. Manifest ID 1787606609034146424 - Dragos - Blog Post - interrogate via MCP