← Blog

NERC CIP in 2026: the deadlines utilities can't miss

NERC CIP has a reputation for arriving in waves, and 2025 through 2026 is a big one. Three separate standards are taking effect in close succession, and while they read as distinct compliance obligations, they point at the same underlying shift: perimeter defense is no longer enough. Regulators want utilities to see inside the network, protect the data paths that keep the grid coordinated, and prove that segmentation and change control are actually working. Here’s a practical read of what’s landing and what it means for the network you run.

Three deadlines, one direction of travel

CIP-015-1 — Internal Network Security Monitoring (INSM). Effective 2 September 2025, with phased compliance running through 2030, this is the standard that changes the mental model most. For years, CIP has been heavily perimeter-oriented: guard the electronic security perimeter, control who gets in. INSM says that’s not sufficient. You now need visibility into east-west traffic and activity within your trusted zones — the assumption being that an attacker who gets past the perimeter, or a change that quietly alters internal reachability, has to be detectable from the inside. The phased timeline gives breathing room, but the direction is unambiguous: you’re expected to know your own interior.

CIP-003-9 — expanded requirements for low-impact systems. Enforcement began 1 April 2026. Low-impact assets have historically carried the lightest obligations, which is precisely why they became a soft target. CIP-003-9 tightens that, with a particular focus on vendor remote access and supply chain risk. The uncomfortable truth for many utilities is that low-impact sites are numerous, distributed, and often the least instrumented — the substations and remote facilities where nobody is watching the network closely. Extending scope here means those sites now need the same discipline around access paths and configuration that higher-impact assets have long required.

CIP-012-2 — protecting real-time data between control centers. Effective 1 July 2026, this standard strengthens protection for the real-time operational data exchanged between control centers — the telemetry and control signals that keep the grid synchronized. This is data in motion across the paths that tie your operations together, and its integrity and confidentiality are what let operators trust what they’re seeing. Protecting it means knowing exactly which network paths carry it, and being able to show those paths haven’t quietly changed.

What these actually ask of the network

Strip away the standard numbers and three practical demands emerge.

First, you must see inside, not just at the edge. INSM makes internal visibility a compliance requirement, not a nice-to-have. That means understanding routing, reachability, and how traffic moves between zones — continuously, not as a quarterly snapshot. A change that alters an internal path is now something you’re expected to notice.

Second, you must protect and prove your real-time data paths. CIP-012-2 turns the question “where does our inter-control-center data actually flow?” into an auditable one. If a routing or circuit change reroutes that traffic, you need to know, and you need a record.

Third, segmentation and change control are table stakes across every tier. With low-impact scope expanding, the boundary discipline you apply can’t stop at your most critical assets. Vendor remote access, in particular, is a path into the network that has to be understood and controlled wherever it exists. If you want the conceptual grounding for that boundary work, our note on OT/IT segmentation covers it.

Turning deadlines into evidence

The common thread is that all three standards reward the same capability: continuously tracking deep network state — routing, BGP, VRF and MPLS boundaries, circuits, and configuration — and keeping a history you can query. That history is what turns INSM from a monitoring aspiration into something you can demonstrate, what lets you prove a real-time data path hasn’t shifted, and what shows an auditor that segmentation held across every change window.

Predicting the impact of a change before it ships matters here too. Catching a routing edit that would reroute control-center traffic, or open an unintended path into a low-impact site, before it happens is far cheaper than reconstructing it after a finding. That’s the assurance our utilities and energy solutions are built to provide — and because Phantom runs entirely on your own infrastructure, none of that state ever leaves your network. If you’d like to see it against your own environment, book a demo.

Change the network with confidence.

Book a demo