NERC moves on attempted compromises at Low Impact + DOE RFI

Definitions move reportable cyber incidents, DOE wants equipment metadata, Questionnaires in beta
Welcome to another week of industry insights, product updates and resources!
The Department of Energy opened the implementation of Executive Order 14421 with a voluntary request for information on equipment data.
NERC has definitions out for comment on a reportable cyber security incident that could affect CIP Low Impact programs.
NERC stopped work on a block of standards revisions, four of them on generator and inverter-based resource (IBR) modeling.
And CISA added 10 actively exploited vulnerabilities to its catalog.
Product Update
Questionnaires (Beta)
Raptor Comply Questionnaires lets you configure recurring questionnaires across your organization and track the responses centrally. For example: the same monthly attestation to every Site Manager, a different one to each control center, on whatever cadence each obligation runs.
Every response comes back stamped with the reporting period it covers, derived from the dispatch schedule rather than typed in by the person answering, so an auditor sees who attested, for which site, covering which month, with nothing reconstructed after the fact.
Follow the standards with your cadences: each calendar quarter for CIP-004-7 R1 security awareness, every 15 calendar months for R4 access privilege verification. Responses that come back blank, single-word, or contradicting the prior period are flagged for review, so your compliance lead reads the exceptions instead of every submission.
Respondent's view:

Admin's view:

Industry Update
Low Impact Would Report Attempts, Not Just Compromises
The comment period on CIP-003-12 and CIP-008-8 closes on September 23.
A Generator Owner whose only CIP-scoped assets are low impact already reports: CIP-003 Attachment 1 requires it to decide whether an incident is reportable and to notify the Electricity Information Sharing and Analysis Center (E-ISAC). What would change is the trigger. The approved definition of a Reportable Cyber Security Incident covers one that "compromised or disrupted" a system. The proposed definition reads "An Attempt to Compromise targeting, or a Cyber Security Incident impacting, an applicable system," and Attempt to Compromise would be a new Glossary term reaching an action "even if the scope or intent of the action is unknown."
The second change is quieter. At time of writing, the perimeter and access-control limbs of both definitions count only "for a high or medium impact BES Cyber System." That qualifier is gone in the proposed text. CIP-008's own applicability does not move, so the expansion arrives through CIP-003, which would also add CISA alongside the E-ISAC and a step to evaluate anomalous activity and classify what is actionable.
Nothing here can bind before July 1, 2029.
DOE Opens the Implementation of Executive Order 14421
The DOE published a request for information on September 9, its first public step toward implementing Executive Order 14421. Responses are due October 9, and DOE holds a webinar on September 16.
The RFI runs to eight lettered sections of questions. Section D reaches equipment already in the ground, and D-1 asks which data fields owners actually maintain on installed equipment, naming country of manufacture, supplier, component provenance and remote-access pathways among them, then asks what is commonly unavailable and how origin can be estimated. A separate question asks industry which equipment categories in the order's own definition are unclear, and names grid-connected inverters, battery energy storage and industrial control systems in the asking.
The RFI is "issued solely for informational and planning purposes" ahead of the implementing rules the order requires by December 24. One thing is worth knowing before filing: anything submitted through regulations.gov cannot be claimed as confidential business information, and DOE says filing there waives any CBI claim. D-1 asks for exactly the detail most owners would protect, and there is a separate route for it.
How Raptor Maps Customers Can Get a Head Start
Both Raptor Comply and Raptor Solar platforms already carry part of what D-1 asks for. Raptor Solar holds manufacturer, model and a scanned serial number for each module, geolocated and stamped with the date it was scanned, and Raptor Comply holds manufacturer, model, serial number, firmware and operating system version, and network and remote-access detail for each cyber asset.
Reach out to your Raptor Maps representative for more details.
NERC Stops Work on 12 Standards Projects
The Standards Committee dropped 12 standards development projects on August 19, all rated low or medium priority, to be reconsidered under the new intake and prioritization process coming with the Modernization of Standards Processes and Procedures framework.
Four are modeling projects that reach Generator Owners with IBRs, among them EMT Modeling and System Model Validation with IBRs. Others reach Generator Owners and Generator Operators through maintenance and voltage control, including the PRC-005-6 and VAR-002-4.1 revisions. The August 31 bulletin carries the full list.
Nothing enforceable changes. The standards these projects would have revised stay as they are, and the revisions are neither cancelled nor scheduled. NERC expects the new framework "as early as quarter 3 or 4 of 2027," subject to regulatory approval.
With the current pace of standards drafting, this reprieve is perhaps unsurprising.
CISA Added 10 Exploited Vulnerabilities in Three Days
Five of the 10 additions to the Known Exploited Vulnerabilities catalog sit in operational or IT environments:
MikroTik RouterOS (CVE-2026-86060 and CVE-2026-67277), added September 10 with a federal date of September 13. Privilege escalation and an unauthenticated service flaw; see MikroTik's advisory.
N-able N-central (CVE-2026-86218), pre-authentication remote code execution at CVSS 10.0, due September 11. Hotfix 4 carries the fix and on-premises servers need it. Huntress found a fully patched environment compromised on September 4.
Windows (CVE-2026-81963 and CVE-2026-85880), both exploited privilege escalation, due September 22, in Microsoft's September release.
Those dates bind federal civilian agencies, not registered entities. For high and medium impact BES Cyber Systems the clock is CIP-007-6 Requirement R2: evaluate applicable patches at least every 35 calendar days, then act within 35 days of the evaluation. A low-impact-only entity has no equivalent clock, because CIP-003 Attachment 1 has no patch management section.
Compliance Resources
Two New Computational Load Standard Requests, Up for Approval September 15
NERC's Large Loads Working Group meets on September 15, and its agenda puts two Standard Authorization Requests up for approval: one on studying computational load loss in planning and operational studies, one on event reporting, model validation and model quality. Approval sends both out for public comment.
Further along, comments close September 18 on Project 2026-02 and on the Rules of Procedure appendices that would create the Computational Load Owner and Computational Load Operator entity types. The posted drafts reach a Generator Owner with a Computational Load Site interconnection, and all of it remains proposed.
Important Dates
September 14-23, 2026: Initial ballots on CIP-003-12 and CIP-008-8. Comments close September 23.
September 15, 2026: NERC Large Loads Working Group meeting, to approve two computational load Standard Authorization Requests.
September 15-16, 2026: NERC Load Modeling Working Group workshop on data center load modeling.
September 16, 2026: NERC Standards Committee meeting, and separately DOE's webinar on the Executive Order 14421 request for information.
September 18, 2026: Comments close on Project 2026-02 Computational Loads and on the Rules of Procedure appendices.
October 1, 2026: PRC-024-4, PRC-029-1 and PRC-030-1 become effective. Design requirements for BES IBRs come due; applicable non-BES IBRs run to January 1, 2027.
October 9, 2026: Responses due on DOE's request for information. Ballot pool also closes for the Standard Process Manual revisions.
Join our mailing list.
Weekly industry insights, news, and product updates.
More News

NERC moves on attempted compromises at Low Impact + DOE RFI
Definitions move reportable cyber incidents, DOE wants equipment metadata, Questionnaires in beta

Executive order reaches grid equipment already contracted and installed
FERC tests the paper burden of EOP-004-5, and we launch a SharePoint integration

NERC proposes standards for data centers
CLO-001-1 starts at 50 MW. Ballot pool closes September 3.

Four IBR standards, four different compliance clocks
The ERO ran one-on-one IBR sessions with GOs and GOPs. PRC-028, 029, 030 and MOD-026.