regulatory

NERC CIP changes 2026–2030: the timeline every small utility needs

CIP-003-9 and CIP-012-2 are in force, the virtualization package arrives July 2028, CIP-015 INSM starts October 2028 and CIP-003-11 lands in 2029. A dated roadmap and what to do now.

· 6 min read · CIP Sentry

FERC’s orders in 2025 and 2026 packed more CIP changes into the next four years than the previous eight. Here is the timeline, what each change means, and a sensible order of work for a small compliance team.

Already in force

April 1, 2026: CIP-003-9. Low impact entities must control vendor electronic remote access (Attachment 1 Section 6): determine it, disable it, and detect malicious communications. See our practical guide.

July 1, 2026: CIP-012-2. Control Center communication plans must now address loss of availability and the recovery of communication links, not only disclosure and modification. See the CIP-012 guide.

Coming next

Date Change Who is affected
July 1, 2028 Virtualization package: CIP-002-7/-8, CIP-003-10, CIP-004-8, CIP-005-8, CIP-006-7.1, CIP-007-7.1, CIP-008-7.1, CIP-009-7.1, CIP-010-5, CIP-011-4.1, CIP-013-3, plus new and revised glossary terms Everyone. Heaviest for entities using virtual machines, hypervisors or shared infrastructure
July 1, 2028 CIP-002-8: revised Control Center definition and criterion 2.12 Entities with Transmission Operator Control Centers
October 1, 2028 CIP-015-1 phase 1: internal network security monitoring High impact and medium impact with ERC at Control Centers
July 1, 2029 CIP-003-11: further low impact controls (FERC Order No. 918) Low impact entities
October 1, 2029 CIP-015-2: INSM extended to EACMS and PACS outside the ESP Same population as CIP-015
October 1, 2030 CIP-015 phase 2 Remaining medium impact systems with ERC

CIP-014-4 (transmission station physical security) has been filed with FERC and would take effect 24 months after approval. NERC’s supply chain project responding to FERC Order No. 912 (draft CIP-013-4) is also in development.

A sensible order of work

  1. Close the 2026 gaps first. If your low impact plan doesn’t have a Section 6 inventory, or your CIP-012 plan doesn’t mention availability and recovery, those are live obligations today.
  2. Map virtualization exposure in 2027. List every hypervisor, virtual machine, shared storage system and virtual network in or near your ESPs. The new terms (Cyber System, Virtual Cyber Asset, Shared Cyber Infrastructure) change how these are described and protected.
  3. Start INSM planning now if you have high or medium-with-ERC systems. Sensors, network changes and outages take time, and NERC itself notes a small vendor marketplace. Pilot at one Control Center in 2027.
  4. Keep low impact plans modular. CIP-003-11 will add to Attachment 1. A plan organized by section and site is an update, not a rewrite.

Where teams get caught

The biggest risk is not the new standards. It is effective-date confusion: using the wrong version’s requirement numbers in evidence, or assuming a future requirement already applies (or doesn’t). Keep a single, dated list of which version is enforceable for each standard, and review it every quarter. Our standards hub does this publicly.


CIP Sentry already includes modules for CIP-012 and CIP-015 and a low impact plan built around Attachment 1, so new requirements land in a structure you already use. Request a quote.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.