One-day turnaround on PRC-029-2

Eliminate friction. Automate compliance. Simplify NERC with Raptor Comply.

Plus CISA and the FBI on third-party ICS integrators

Welcome to another week of industry insights, product updates and resources!

It's day 2 of the new PRC trio: PRC-029-2; PRC-024-4; and PRC-030-1.

With a few moving goal posts on the definition of design and the late-breaking PRC-029-2, no doubt everyone is keeping busy. At least GOs with non-BES IBRs won't have to tackle the design requirements until January 1, 2027.

NERC's computational loads standards passed initial ballot, and two more SARs are open for comment through October 22. Plus CISA and the FBI published a fact sheet for owners and operators that rely on third-party control system integrators. And, we announce RaptorCon 2027.

Product Update

A quickfire round of quality-of-life improvements:

  • Rename evidence files: you can now rename an evidence file after upload. The rename is recorded in the file's history.

  • Control centers, at invite time: when you invite a user to Raptor Comply, you set their access. We made it easier to configure Control Center access.

  • Questionnaires, now on for every organization: Questionnaires launched as an opt-in Beta last month. It is now available to every organization, still in Beta. Look for Questionnaires in the sidebar.

Industry Update

PRC-029-2, PRC-024-4 and PRC-030-1 Took Effect October 1

FERC approved PRC-029-2 on September 30, by letter order, and it took effect October 1 alongside PRC-024-4 and PRC-030-1. PRC-029-1, which was due to take effect the same day, went inactive on September 30. PRC-029-2 and PRC-030-1 bind GOs only.

The design requirements in R1, R2 and R3 for PRC-029-2 are due now for BES inverter-based resources (IBRs), and on January 1, 2027 for applicable non-BES IBRs. The performance requirements wait on the disturbance monitoring equipment PRC-028-1 phases in.

PRC-029-2 adds two exemptions: projects under active development with an executed interconnection agreement by October 1, 2026 and an equipment procurement contract executed before September 1, 2025 (the U.S. dates), and HVDC-connected IBRs with a well-documented hardware limitation. The revisions came out of Project 2025-05.

NERC's September 9 enforcement discretion practice guide, for GOs unable to secure inverter vendor support for design changes in time, reads design as more than a study: design "necessitates the physical implementation and configuration of these settings on active units." The guide is written for PRC-029-1 and does not mention PRC-029-2, so confirm with your Regional Entity before relying on it.

RaptorCon 2027

RaptorCon is an intimate forum for energy industry executives to discuss and learn how technology developments continue to reshape renewable assets. Diving into frontier use cases of AI and robotics, this year's RaptorCon will focus on how stakeholders across the value chain are already deploying these technologies at scale, and how they see them evolving in the near future. We will be returning to Chicago on March 10th and 11th - more details on how to apply for tickets coming soon.

CISA and the FBI on Third-Party ICS Integrators

CISA and the FBI published a fact sheet on September 23 for critical infrastructure owners and operators that use outside integrators for control system design, installation, support or daily operation. It rests on an FBI finding: between March and April 2025, foreign actors inside a U.S. industrial automation company serving power utilities searched its network for "customers" and "SCADA," then staged about 800 files in nine .zip archives, including customer SCADA information, ICS device details and schematics.

The agencies recommend:

  • Contracts that carry cybersecurity: data storage location, remote access, change and patch management, securing deployed components, and a list of authorized personnel.

  • Monitored, on-demand remote access that the operator has to allow each time.

  • An inventory of every piece of software and hardware the integrator supplied, with how it connects and how it will be updated.

  • The ability to run manually and recover without the integrator.

Existing CIP coverage: For High and Medium Impact BES Cyber Systems, CIP-013-2 R1.2.6 requires a supply chain plan to address "coordination of controls for vendor-initiated remote access." For Low Impact, CIP-003-9 Attachment 1 Section 6 requires methods to determine and disable vendor electronic remote access, and to detect known or suspected malicious communications on it.

Exploited Remote Access and Perimeter Products

CISA has added over 25 entries to the Known Exploited Vulnerabilities catalog since September 11. Several sit in the products that carry remote access into an operations network:

  • Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772), added September 27. Unauthenticated command execution and a memory-handling flaw. Citrix bulletin.

  • Cisco Identity Services Engine (CVE-2026-76460), added September 16. An unauthenticated attacker can bypass the web-based management interface. Cisco advisory.

  • F5 BIG-IP APM (CVE-2026-94127), added September 22. Unauthenticated remote code execution where an access policy and an OAuth profile are configured. F5 article.

  • Check Point Security Gateway and Check Point Spark Firewall (CVE-2026-85102), added September 22. Unauthenticated remote code execution on gateways using Site to Site or Remote Access VPN. Check Point advisory.

  • ConnectWise ScreenConnect (CVE-2026-84869), added September 11. File transfer and execution through an active remote session without host confirmation. ConnectWise bulletin.

CISA's notes on these entries pair the fix with forensic triage, which BOD 26-04 requires of federal agencies.

Compliance Resources

Computational Loads: Initial Ballot Passed, Two More SARs Open

The three new computational loads standards in Project 2026-02 passed initial ballot on September 18, at weighted segment values from 77.93% (CLO-002-1) to 82.40% (CLO-003-1). FAC-001-5 and FAC-002-5 drew 95.45%. NERC says the drafting team will consider comments "toward a planned filing in the last quarter of the year," per its September 19 release.

The Large Loads Working Group has two Standard Authorization Requests (SARs) out for comment through October 22:

Neither SAR names GOs among the entities it would reach.

Important Dates

  • October 5, 2026: Questions due, and one-on-one registration closes, for NERC's Small Group Advisory Session on the CIP standards addressing virtualization. The general session is December 7.

  • October 9, 2026: Responses due on the DOE's voluntary RFI on Executive Order 14421. Ballot pool also closes for the Standard Processes Manual revisions.

  • October 13, 2026: NERC Large Loads Working Group meeting, 2:00 to 3:00 p.m. Eastern, to approve the computational load disturbance performance SAR.

  • October 16-26, 2026: Initial ballot on the Standard Processes Manual revisions.

  • October 22, 2026: Comments close on the two Large Loads Working Group SARs.

  • October 26, 2026: Comments close on the Standard Processes Manual and Rules of Procedure revisions.

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.
Somerville, MA
02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company