CIP-015 · Internal Network Security Monitoring

CIP-015: see what moves inside your perimeter.

CIP-015 introduces internal network security monitoring (INSM) for high impact and medium impact systems with External Routable Connectivity. Nothing is enforceable yet: the first phase begins October 1, 2028. Now is the time to plan.

Enforceable nowNot yet enforceable. CIP-015-1 phase 1 begins October 1, 2028
Next versionCIP-015-2 (October 1, 2029) extends INSM to EACMS and PACS outside the ESP
Applies toHigh impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity, and associated PCAs

Requirements at a glance

R1

INSM process

Implement documented process(es) for internal network security monitoring of networks protected by the ESP: (1.1) implement network data feeds using a risk-based rationale, (1.2) deploy methods to detect anomalous activity, and (1.3) deploy methods to evaluate anomalous activity to determine further action.

R2

Retain INSM data

Implement process(es) to retain INSM data associated with anomalous activity, at least until the R1.3 evaluation and any resulting action is complete.

R3

Protect INSM data

Implement process(es) to protect the INSM data collected under R1 and retained under R2 against the risk of unauthorized deletion or modification.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Why start now

INSM is a technology and process change: sensors to buy, network changes that may need outages, and new analysis work. NERC’s own implementation plan notes a small vendor marketplace and supply chain limits. Utilities that wait until 2028 will compete for the same sensors and consultants.

A practical roadmap

  1. Scope the ESPs that contain high impact or medium impact systems with ERC. Start with Control Centers.
  2. Decide data feed locations using a written risk-based rationale (R1.1).
  3. Baseline normal traffic so anomalies stand out.
  4. Write the evaluation and escalation process (R1.3) and link it to your CIP-008 incident response plan.
  5. Plan retention and protection of the data (R2, R3): who can delete it, and how long it is kept.
  6. Run a pilot at one site well before your phase date and collect the evidence you would show an auditor.

Program versus platform

INSM sensors and analytics platforms detect activity. Auditors will also ask for the process, the rationale, and the record of what you did with each anomaly. That program layer is where CIP Sentry fits alongside whichever monitoring technology you choose.

Evidence auditors typically ask for

  • The documented INSM process and the risk-based rationale for data feed locations
  • Architecture showing sensors or collection points inside each applicable ESP
  • Detection methods and baselines of expected network activity
  • Records of anomalies detected and how each was evaluated and escalated (for example into CIP-008)
  • Retention records and the controls protecting INSM data from deletion or modification

How CIP Sentry helps with CIP-015

Network Monitoring module, built early

Document your INSM program, data feeds, detection methods and evaluation process now, years ahead of enforcement.

Scoped from CIP-002 and CIP-005

The same high and medium-with-ERC population and ESP records drive CIP-015 scope, so nothing is entered twice.

Works with your sensors

Keep using the INSM technology you choose. CIP Sentry holds the program, evidence and decisions that auditors will ask for.

Phase dates on the calendar

Track your own readiness milestones against the 2028 and 2030 phase dates.

CIP-015 FAQ

When does CIP-015 become enforceable?

CIP-015-1 was approved by FERC in June 2025 (Order No. 907) with a phased plan: high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity at Control Centers first, on October 1, 2028, and remaining medium impact systems with ERC by October 1, 2030. CIP-015-2 carries those dates forward and becomes effective October 1, 2029.

What does CIP-015-2 add?

FERC directed NERC to extend INSM to EACMS and PACS outside the ESP. FERC Order No. 907-A (August 2025) clarified that this covers communications between BES Cyber Systems, EACMS, PACS and PCAs, not traffic between PACS and non-PACS controllers.

Do low impact systems need INSM?

No. CIP-015 applies to high impact systems and medium impact systems with External Routable Connectivity. NERC has studied INSM for other systems, so watch for future changes.

Do we have to keep full packet captures?

No. R2 requires retaining INSM data associated with anomalous activity until its evaluation and actions are complete. There is no blanket full-capture requirement.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-015 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.