Requirements at a glance
INSM process
Implement documented process(es) for internal network security monitoring of networks protected by the ESP: (1.1) implement network data feeds using a risk-based rationale, (1.2) deploy methods to detect anomalous activity, and (1.3) deploy methods to evaluate anomalous activity to determine further action.
Retain INSM data
Implement process(es) to retain INSM data associated with anomalous activity, at least until the R1.3 evaluation and any resulting action is complete.
Protect INSM data
Implement process(es) to protect the INSM data collected under R1 and retained under R2 against the risk of unauthorized deletion or modification.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Why start now
INSM is a technology and process change: sensors to buy, network changes that may need outages, and new analysis work. NERC’s own implementation plan notes a small vendor marketplace and supply chain limits. Utilities that wait until 2028 will compete for the same sensors and consultants.
A practical roadmap
- Scope the ESPs that contain high impact or medium impact systems with ERC. Start with Control Centers.
- Decide data feed locations using a written risk-based rationale (R1.1).
- Baseline normal traffic so anomalies stand out.
- Write the evaluation and escalation process (R1.3) and link it to your CIP-008 incident response plan.
- Plan retention and protection of the data (R2, R3): who can delete it, and how long it is kept.
- Run a pilot at one site well before your phase date and collect the evidence you would show an auditor.
Program versus platform
INSM sensors and analytics platforms detect activity. Auditors will also ask for the process, the rationale, and the record of what you did with each anomaly. That program layer is where CIP Sentry fits alongside whichever monitoring technology you choose.
Evidence auditors typically ask for
- The documented INSM process and the risk-based rationale for data feed locations
- Architecture showing sensors or collection points inside each applicable ESP
- Detection methods and baselines of expected network activity
- Records of anomalies detected and how each was evaluated and escalated (for example into CIP-008)
- Retention records and the controls protecting INSM data from deletion or modification
How CIP Sentry helps with CIP-015
Network Monitoring module, built early
Document your INSM program, data feeds, detection methods and evaluation process now, years ahead of enforcement.
Scoped from CIP-002 and CIP-005
The same high and medium-with-ERC population and ESP records drive CIP-015 scope, so nothing is entered twice.
Works with your sensors
Keep using the INSM technology you choose. CIP Sentry holds the program, evidence and decisions that auditors will ask for.
Phase dates on the calendar
Track your own readiness milestones against the 2028 and 2030 phase dates.
CIP-015 FAQ
When does CIP-015 become enforceable?
CIP-015-1 was approved by FERC in June 2025 (Order No. 907) with a phased plan: high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity at Control Centers first, on October 1, 2028, and remaining medium impact systems with ERC by October 1, 2030. CIP-015-2 carries those dates forward and becomes effective October 1, 2029.
What does CIP-015-2 add?
FERC directed NERC to extend INSM to EACMS and PACS outside the ESP. FERC Order No. 907-A (August 2025) clarified that this covers communications between BES Cyber Systems, EACMS, PACS and PCAs, not traffic between PACS and non-PACS controllers.
Do low impact systems need INSM?
No. CIP-015 applies to high impact systems and medium impact systems with External Routable Connectivity. NERC has studied INSM for other systems, so watch for future changes.
Do we have to keep full packet captures?
No. R2 requires retaining INSM data associated with anomalous activity until its evaluation and actions are complete. There is no blanket full-capture requirement.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

