NERC's next five years on one page

Three dated waves and a fourth forming: the 2026-2030 compliance horizon, mapped.
If your compliance program feels permanently one step behind, the problem usually isn't effort. It's the horizon. This week we zoomed out and mapped 2026 through 2030 into the waves NERC has been laying down - see the infographic below.
Nearest deadlines first: CISA wants SolarWinds Serv-U patched by June 19 (details below), and CIP-012-2 becomes effective July 1.
Industry Update
CISA: Patch SolarWinds Serv-U by June 19
CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on June 5: an unauthenticated denial-of-service flaw in SolarWinds Serv-U file transfer software, exploited in the wild. A crafted HTTP request crashes the service, no credentials required.
The federal remediation deadline is June 19, and CISA urges all organizations to treat it with the same urgency. Managed file transfer tools sit in the evidence path for many compliance programs; if Serv-U moves files in your environment, apply Serv-U 15.5.4 Hotfix 1 now and confirm your file-transfer dependencies are inventoried.
Texas Approves a New Framework for the Large Loads Wave
On June 2, the ERCOT Board approved PGRR 145, the "Batch Zero" process that replaces one-off large-load interconnection studies with a system-wide, batch-based approach: groups of large loads studied together, transmission capacity allocated year by year. The driver is a queue that jumped almost 300% last year, most of it data centers.
It is another signal that the demand side is the next frontier: NERC launched Project 2026-02 Computational Loads in March, targeting a first bridge standard for Large Loads (data centers, AI compute, crypto mining) by the end of 2026, with a proposed Computational Load Entity registration category already through public comment.
Compliance Resources
CIP-012-2 Effective July 1
Twenty days out. CIP-012-2 extends Control Center communication protections to cover availability of Real-time Assessment and monitoring data, not just confidentiality and integrity.
NERC Standards Process Modernization: Revisions in Motion
NERC is revising the Standard Processes Manual to act on its Modernization of Standards Processes and Procedures Task Force recommendations, changing how reliability standards get initiated, developed, and balloted. Check NERC's Balloting & Commenting page for the active comment windows. Worth tracking even if you don't comment: NERC will trial the recommendations in the Large Loads standards project, so this process shapes how fast the next wave arrives.
Listen: A Regulatory Roundtable on What's Coming
Patrick Miller (Ampyx Cyber), Joy Ditto, and Earl Shockley (INPOWERD) unpack the quarter's biggest policy shifts in the latest Critical Assets "Policy Pulse": the new National Cybersecurity Strategy, the reliability strain Large Loads (data centers, AI compute) are putting on the grid, and how AI now cuts both ways for defenders and attackers.
NERC Roadmap (Infographic)
The 2026-2030 Horizon Resolves Into Waves
Read one at a time, the standards coming into effect over the next five years look like a stream of deadlines. Stepped back, they resolve into waves, each a named FERC initiative:
Wave 1, IBR reliability (2026 onwards). PRC-029-1 and PRC-030-1 take effect October 1, 2026: net-new ride-through and event-mitigation evidence for inverter-based resources, alongside the PRC-024-4 update. The PRC trio phase in under the implementation plan, so confirm your own milestones.
Wave 2, CIP virtualization refresh (July 1, 2028). Eleven CIP standards (CIP-002 through CIP-011, plus CIP-013) re-version on a single day, and every entity re-maps to the per-system-capability framework that replaces the TFE model. Heavy lift if you run virtualized infrastructure; mostly documentation if hardware-based.
Wave 3, INSM visibility (2028-2030). CIP-015-1 phases internal network security monitoring in: Control Centers by October 1, 2028, remaining Medium-impact-with-ERC systems by October 1, 2030.
And a fourth wave is forming. NERC's CIP Roadmap (January 2026) found that the bulk of the OT running the grid now sits outside medium- and high-impact CIP coverage. CIP-003-11 (effective July 1, 2029) is the dated leading edge, with new low-impact controls. The rest is still taking shape: MFA for remote access to low-impact systems, encryption for carrier-provided SCADA links, and cloud security standards, where a drafting team is at work now. Those are recommendations and projects, not standards: no compliance dates yet. The driver behind all of it is the grid itself; per SEIA's US Solar Market Insight, solar and storage made up 91% of new grid capacity in Q1.

Important Dates
June 19, 2026: CISA KEV remediation deadline for SolarWinds Serv-U CVE-2026-28318 (binding on federal agencies; recommended for all)
July 1, 2026: CIP-012-2 becomes effective (Control Center communications: availability protections)
Join our mailing list.
Weekly industry insights, news, and product updates.
More News

One-day turnaround on PRC-029-2
Plus CISA and the FBI on third-party ICS integrators

NERC moves on attempted compromises at Low Impact + DOE RFI
Definitions move reportable cyber incidents, DOE wants equipment metadata, Questionnaires in beta

Executive order reaches grid equipment already contracted and installed
FERC tests the paper burden of EOP-004-5, and we launch a SharePoint integration

NERC proposes standards for data centers
CLO-001-1 starts at 50 MW. Ballot pool closes September 3.