The NERC CIP Compliance Calendar, 2026 Through 2030

The direct answer: four NERC CIP clocks are running between now and 2030. CIP-003-9 vendor remote access requirements for low-impact systems became enforceable April 1, 2026, so that one is live today. CIP-015-1 internal network security monitoring has two compliance dates: September 2, 2028 for high-impact BES Cyber Systems and medium-impact systems with External Routable Connectivity at Control Centers, and September 2, 2030 for the remaining medium-impact systems with ERC. The eleven virtualization-era standards approved in FERC Order No. 919 become effective April 1, 2028. And CIP-015-2, which would extend INSM to EACMS and PACS, was filed with FERC on June 18, 2026 and is pending. Everything below is the detail behind those four sentences.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
This page is the dates reference. If you need the standards themselves explained, start with NERC CIP requirements explained. If you need a requirement-by-requirement working list, use the NERC CIP compliance checklist for 2026. This page answers one question those do not: what is due, when, and for whom.
The full calendar, 2026 through 2030
| Date | What happens | Who it applies to |
|---|---|---|
| September 2, 2025 | CIP-015-1 (internal network security monitoring) effective date. The compliance clocks below start from here. | Registered entities with high- or medium-impact BES Cyber Systems |
| April 1, 2026 | CIP-003-9 vendor electronic remote access requirements become enforceable. Live now. | All registered entities with low-impact BES assets |
| March 19, 2026 | FERC issues Order No. 919, approving eleven modified CIP standards and new definitions to permit secure virtualization. | All registered entities; most relevant to high- and medium-impact entities |
| May 26, 2026 | Order No. 919 takes effect, starting the 24-month transition to the revised standards. | Same as above |
| June 18, 2026 | NERC files CIP-015-2 (EACMS and PACS extension of INSM) with FERC, Docket RD26-6-000. Pending approval. | Entities in CIP-015 scope, prospectively |
| April 1, 2028 | The eleven revised virtualization-era CIP standards become effective. | All registered entities subject to the modified standards |
| September 2, 2028 | CIP-015-1 compliance deadline, first phase. | High-impact BES Cyber Systems and medium-impact with ERC at Control Centers |
| September 2, 2030 | CIP-015-1 compliance deadline, second phase. | All other applicable medium-impact BES Cyber Systems with ERC |
Two sources anchor this table. FERC's approval of CIP-015-1 and its phased schedule is in the Federal Register notice of July 2, 2025. Order No. 919 and the eleven approved standards are in the Federal Register notice of March 24, 2026.
What is enforceable right now: CIP-003-9
The only new obligation already in enforcement is CIP-003-9. Since April 1, 2026, entities with low-impact BES Cyber Systems must be able to determine and disable active vendor electronic remote access and detect known or suspected malicious communications on those access paths. This lands on the long tail of the industry: municipal utilities, cooperatives, and small generators that historically had the lightest CIP footprint. If a vendor can VPN into your relay network and you cannot enumerate that session and kill it, you have a live compliance gap today, not a future one.
The practical work is an inventory of every vendor remote access path, a kill switch for each, and monitoring on the paths that remain. It overlaps heavily with the vendor and remote access items in the 2026 CIP checklist, so entities working through that list are most of the way there.
CIP-015: why 2026 is the real deadline for a 2028 date
CIP-015-1 requires internal network security monitoring: collecting and analyzing east-west traffic inside the Electronic Security Perimeter, not just at its edge. The first compliance date, September 2, 2028, applies to high-impact systems and medium-impact systems with External Routable Connectivity at Control Centers. The rest of the medium-impact fleet with ERC follows on September 2, 2030.
The trap in that schedule is the deployment timeline. Standing up OT network monitoring at utility scale typically takes 12 to 24 months: traffic baselining, sensor placement, span port and tap engineering across substations and plants, tuning, and the staffing to actually analyze what the sensors produce. Work backward from September 2028 and the procurement decision belongs in 2026, with deployment through 2027 and a tuning year before the deadline. Entities that treat 2028 as a 2028 problem will be selecting tooling under time pressure and negotiating with vendors who know it. Mid-market generation and transmission entities feel this hardest because most have no in-house OT monitoring team to absorb the analysis load.
Facing the 2028 INSM clock?
A Z Cyber advisor can lead a CIP-015 scoping assessment that maps your impact ratings to these dates and recommends a deployment sequence your team can approve.
CIP-015-2: the pending EACMS and PACS question
When FERC approved CIP-015-1, it directed NERC to extend INSM coverage to Electronic Access Control or Monitoring Systems and Physical Access Control Systems. NERC met its September 2, 2026 filing deadline early, submitting CIP-015-2 to FERC on June 18, 2026 in Docket RD26-6-000. As of August 27, 2026 the standard is pending FERC approval, and no compliance dates exist for it yet.
The planning implication is straightforward: if you are scoping an INSM deployment now, assume EACMS and PACS will enter scope and architect sensor coverage accordingly. Retrofitting monitoring onto access control systems after the initial deployment is more expensive than including those network segments in the original design. Treat the pending status as a design input, not a reason to wait.
Order 919: virtualization becomes legal, with a 2028 transition
FERC Order No. 919, issued March 19, 2026 and effective May 26, 2026, approved eleven modified CIP standards: CIP-002-7, CIP-003-10, CIP-004-8, CIP-005-8, CIP-006-7.1, CIP-007-7.1, CIP-008-7.1, CIP-009-7.1, CIP-010-5, CIP-011-4.1, and CIP-013-3, along with new and revised definitions including Shared Cyber Infrastructure and virtual cyber assets. The package finally permits secure virtualization of BES Cyber Systems, which the previous standards' device-centric language effectively blocked. The revised standards become effective April 1, 2028, the first day of the first quarter 24 months after the order took effect.
For entities planning SCADA modernization or a virtualization program, the two years between now and April 2028 are the window to redesign asset identification, change management, and patch processes around the new definitions. Note that the transition touches CIP-007 and CIP-010 directly, so patch and configuration programs built on the current standard versions will need revisiting. If your patch cadence is already strained, read our breakdown of the CIP-007 35-day patch window before layering virtualization on top of it.
How to sequence the work
Reading the calendar as one program rather than four separate obligations, the sequence for a mid-market utility looks like this. In 2026: close any CIP-003-9 gap immediately since it is enforceable, and run CIP-015 scoping and procurement. In 2027: deploy and baseline INSM sensors, and begin redesigning processes against the Order 919 standard versions. In 2028: hit the April virtualization effective date and the September INSM deadline with a tuning year behind you. Then the 2030 medium-impact phase becomes an extension of a running program instead of a second project.
Two related resources help with the framing decisions. If your operation spans both NERC-regulated and non-regulated OT environments, IEC 62443 vs NERC CIP covers where the two frameworks diverge and where one program can serve both. And because CIP compliance evidence maps cleanly onto a broader program structure, many utilities anchor the whole effort to a NIST CSF assessment so board reporting and CIP audit preparation draw from the same records. Our work with utilities and energy companies usually starts exactly there: one assessment, one calendar, one prioritized set of recommendations the client's leadership approves and owns.
What to watch next
Three things can change this calendar. First, FERC action on CIP-015-2 in Docket RD26-6-000: approval will add new compliance dates for EACMS and PACS monitoring, and this page will be updated when the order issues. Second, any FERC or NERC guidance refining the Order 919 transition ahead of the April 1, 2028 effective date. Third, the fixed deadlines themselves: September 2, 2028 for the first CIP-015 phase and September 2, 2030 for the second are set, and the only variable is how much runway entities leave themselves. If you want the dates mapped to your specific asset inventory and impact ratings, talk to a Z Cyber advisor.
Frequently Asked Questions
When do I have to comply with NERC CIP-015?
It depends on your impact rating. CIP-015-1 became effective September 2, 2025 with a phased compliance schedule. High-impact BES Cyber Systems and medium-impact systems with External Routable Connectivity at Control Centers must comply by September 2, 2028. All other applicable medium-impact systems with ERC must comply by September 2, 2030. Because internal network security monitoring typically takes 12 to 24 months to deploy, entities facing the 2028 date are in the procurement window now.
What NERC CIP deadlines fall in 2026?
Three dates matter in 2026. CIP-003-9 vendor electronic remote access requirements for low-impact BES Cyber Systems became enforceable April 1, 2026, so low-impact entities must already be able to determine and disable vendor remote access. FERC Order No. 919, which approved eleven virtualization-era CIP standards, took effect May 26, 2026. And NERC filed CIP-015-2, the EACMS and PACS scope extension, with FERC on June 18, 2026, where it remains pending.
Is CIP-003-9 enforceable right now?
Yes. The CIP-003-9 requirements for vendor electronic remote access to low-impact BES Cyber Systems became enforceable on April 1, 2026. Registered entities with low-impact assets must be able to determine and disable active vendor remote access sessions and detect known or suspected malicious communications on those access paths. This is the CIP obligation most likely to surface in an audit of a municipal utility, cooperative, or small generator today.
What did FERC Order 919 change and when do the new standards take effect?
FERC Order No. 919, issued March 19, 2026 and effective May 26, 2026, approved eleven modified CIP standards, including CIP-002-7, CIP-005-8, CIP-007-7.1, CIP-010-5, and CIP-013-3, plus new definitions such as Shared Cyber Infrastructure and virtual cyber assets. The package permits secure virtualization of BES Cyber Systems for the first time. The revised standards become effective April 1, 2028, which is the first day of the first quarter 24 months after the order took effect.
Does CIP-015-2 extend INSM to EACMS and PACS?
That is what it proposes. FERC's approval order for CIP-015-1 directed NERC to extend internal network security monitoring to Electronic Access Control or Monitoring Systems and Physical Access Control Systems. NERC filed CIP-015-2 with FERC on June 18, 2026, in Docket RD26-6-000, meeting its September 2, 2026 filing deadline. As of August 27, 2026 the standard is pending FERC approval, so EACMS and PACS are not yet in enforceable INSM scope but should be assumed in scoping work.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


