FERC’s orders in 2025 and 2026 packed more CIP changes into the next four years than the previous eight. Here is the timeline, what each change means, and a sensible order of work for a small compliance team.
Already in force
April 1, 2026: CIP-003-9. Low impact entities must control vendor electronic remote access (Attachment 1 Section 6): determine it, disable it, and detect malicious communications. See our practical guide.
July 1, 2026: CIP-012-2. Control Center communication plans must now address loss of availability and the recovery of communication links, not only disclosure and modification. See the CIP-012 guide.
Coming next
| Date | Change | Who is affected |
|---|---|---|
| July 1, 2028 | Virtualization package: CIP-002-7/-8, CIP-003-10, CIP-004-8, CIP-005-8, CIP-006-7.1, CIP-007-7.1, CIP-008-7.1, CIP-009-7.1, CIP-010-5, CIP-011-4.1, CIP-013-3, plus new and revised glossary terms | Everyone. Heaviest for entities using virtual machines, hypervisors or shared infrastructure |
| July 1, 2028 | CIP-002-8: revised Control Center definition and criterion 2.12 | Entities with Transmission Operator Control Centers |
| October 1, 2028 | CIP-015-1 phase 1: internal network security monitoring | High impact and medium impact with ERC at Control Centers |
| July 1, 2029 | CIP-003-11: further low impact controls (FERC Order No. 918) | Low impact entities |
| October 1, 2029 | CIP-015-2: INSM extended to EACMS and PACS outside the ESP | Same population as CIP-015 |
| October 1, 2030 | CIP-015 phase 2 | Remaining medium impact systems with ERC |
CIP-014-4 (transmission station physical security) has been filed with FERC and would take effect 24 months after approval. NERC’s supply chain project responding to FERC Order No. 912 (draft CIP-013-4) is also in development.
A sensible order of work
- Close the 2026 gaps first. If your low impact plan doesn’t have a Section 6 inventory, or your CIP-012 plan doesn’t mention availability and recovery, those are live obligations today.
- Map virtualization exposure in 2027. List every hypervisor, virtual machine, shared storage system and virtual network in or near your ESPs. The new terms (Cyber System, Virtual Cyber Asset, Shared Cyber Infrastructure) change how these are described and protected.
- Start INSM planning now if you have high or medium-with-ERC systems. Sensors, network changes and outages take time, and NERC itself notes a small vendor marketplace. Pilot at one Control Center in 2027.
- Keep low impact plans modular. CIP-003-11 will add to Attachment 1. A plan organized by section and site is an update, not a rewrite.
Where teams get caught
The biggest risk is not the new standards. It is effective-date confusion: using the wrong version’s requirement numbers in evidence, or assuming a future requirement already applies (or doesn’t). Keep a single, dated list of which version is enforceable for each standard, and review it every quarter. Our standards hub does this publicly.
CIP Sentry already includes modules for CIP-012 and CIP-015 and a low impact plan built around Attachment 1, so new requirements land in a structure you already use. Request a quote.

