FERC orders mandatory NERC standards for data centers

Eliminate friction. Automate compliance. Simplify NERC with Raptor Comply.

A July 16 FERC order gives NERC a year-end deadline to bring large loads under mandatory standards.

Last week FERC ordered NERC to bring large loads, meaning data centers and AI compute, under mandatory reliability standards.

For owners and operators, the compressed timeline is telling and speaks to both FERC/NERC's position on large loads, and the broader efforts to modernize drafting and implementation timelines.

Separately, CISA flagged a new critical-severity vulnerability in OpenPLC v3 affecting the energy sector. If it runs in your environment, the fix is to upgrade, not patch.

Product Updates

New Demo: Getting Audit-Ready Across CIP and O&P

We published a new product demo walking through how Raptor Comply helps you get audit-ready across both the Critical Infrastructure Protection (CIP) and operations and planning (O&P) standards, in one platform.


Watch the Raptor Comply demo

Watch the demo

Nested bullets in the policy editor

The policy document editor now supports multi-level bullet lists. Indent and outdent with Tab or the toolbar so your policies can mirror the hierarchical structure of the standards they map to, instead of flattening everything to one level.

Full titles on the Policies and Evidence pages

Document and policy titles no longer truncate. The title column on both the Policies and Evidence pages is wider by default and you can drag to resize it, so you can read a full title at a glance without opening the record.

Industry Update

Large Loads: FERC Sets an Aggressive Mandatory Timeline

The effort to bring large loads under NERC standards moved from proposal to directive. In a July 16 order, FERC gave NERC a December 31, 2026 deadline to file new Reliability Standards for computational load integration and to revise its Rules of Procedure to require computational-load entities to register, plus a March 1, 2027 deadline for a workplan on the next round of standards. FERC pointed to grid disturbances in which large loads contributed to instability as the reason for acting now.

None of this is enforceable today. The standards still have to be written, filed, and approved. But the registration question owners and operators have been watching now carries a hard year-end deadline, so if you own, co-locate with, or interconnect large load, this is the window to understand where the criteria may land, because building a program takes months and years, not weeks. This builds on the Level 3 Alert NERC issued in May, with an August 3 response deadline for transmission owners and planners.

CISA Flags a Critical Energy-Sector Vulnerability in OpenPLC v3

On July 9, CISA published an ICS advisory for OpenPLC v3 (CVE-2026-14480), listing Energy among the affected critical infrastructure sectors and scoring it 9.9 of 10 on the CVSS scale, in the critical range. The flaw is an authenticated arbitrary file write in the legacy web UI program-upload workflow. An attacker who is already authenticated can write files to the filesystem and escalate that into native code execution through OpenPLC's normal program-compilation process, running code as the OpenPLC runtime user.

There is no patch: OpenPLC v3 is end-of-life, and CISA's remediation is to upgrade to v4. If v3 runs anywhere in your environment, plan that upgrade and restrict network access to the web UI in the meantime. For CIP programs, treat the version change as a baseline configuration change under CIP-010 and log it against your CIP-007 patch management process.

Compliance Resources

GO vs GOP: Two Registrations, Two Compliance Jobs

The Generator Owner (GO) and a Generator Operator (GOP) NERC registrations carry two different compliance footprints. Often those are two different companies, and knowing where their obligations overlap and where they diverge is the first step to resourcing each side correctly.

Both roles carry the CIP standards, scaled to each facility's impact level. They diverge mainly on the O&P standards: the GOP's obligations are mostly real-time, like following operating instructions and maintaining communications capability, while the GO's are per-asset engineering evidence such as protection-system maintenance (PRC-005), facility ratings (FAC-008), and generator modeling (MOD-032). A GO can contract the work out, but it stays ultimately responsible under the standards. That structure is why, in NERC's 2025 enforcement report, the most-cited O&P standards are GO obligations: per-asset, recurring, and evidence-heavy.

We broke it down standard by standard. See the full GO vs GOP breakdown.

Important Dates

  • August 3, 2026: NERC Level 3 Alert entity responses due from transmission owners, transmission planners, and planning coordinators on modeling, study, protection, and communications practices for large loads.

  • December 31, 2026: FERC's deadline for NERC to file new computational-load Reliability Standards and revise its Rules of Procedure to require computational-load entities to register.

  • March 1, 2027: FERC's deadline for NERC to file a workplan for the next round of computational-load reliability standards.

This post does not constitute legal or other advice and we encourage you to verify any of the information independently.

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.
Somerville, MA
02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company