What SCOTUS ruling could mean for FERC

Patch PROMOD V and e-mesh EMS. The July 13 webinar on Large Loads registration changes. Plus what SCOTUS ruling could mean for FERC.
CISA published two industrial control system advisories for Hitachi Energy on July 7: PROMOD V and e-mesh EMS. Vendor fixes are available for both. Read on below.
Separately, the Supreme Court cleared a path this week to test whether FERC commissioners can be removed by the President at will.
NERC's additional ballot for draft PRC-029-2 closes Monday, July 13. If your fleet includes IBRs, confirm your registered ballot body representative has voted. Also next week, NERC sheds light on upcoming registration thresholds for large loads.
Product Update
NERC Standards Widget Gets an Applicability Column
The NERC Standards dashboard widget shows you what standards are coming and when. We just added an Applicability column. Now you can also see at a glance whether an upcoming standard applies to your registration category or impact level, without opening each one to check.
In this new column, CIP standards display a Low, Medium or High impact-rating pill. O&P standards display a Cat 1 or Cat 2 registration-category pill, left blank where a standard has no GO/GOP scope, but we're adding TO/TOP in shortly.

Multi-Level Lists in Policy Editors For all you list makers, you can indent your bulleted and numbered lists across your policies, plans and procedures in the Policies feature.
Industry Update
CISA Discloses Two Hitachi Energy Vulnerabilities in One Day
On July 7, CISA published two ICS advisories for Hitachi Energy products used in grid planning and operations. Both have vendor fixes available now.
PROMOD V (CVE-2026-10763, CVSS 7.1): the generation and transmission planning tool many GOs and GOPs use for system studies transmits data over HTTP instead of HTTPS through its bundled Digipede server, letting an attacker intercept or manipulate study data in transit. Fixed in version 1.0.11, which adds HTTPS support.
e-mesh EMS (CVE-2026-42945, CVSS 8.1): Hitachi Energy's energy management system ships a version of NGINX with a heap-based buffer overflow in its rewrite module. An unauthenticated attacker can trigger it with a crafted HTTP request, crashing the worker process and, without ASLR protection, potentially executing code. Hotfixes update the bundled NGINX version.
If either runs in your environment, patch it. For CIP programs, treat the update as a baseline configuration change under CIP-010 and log it against your CIP-007 patch management process.
Supreme Court Clears a Path to Test FERC's Independence
The Supreme Court ruled 6-3 on June 29 in Trump v. Slaughter that the FTC's for-cause removal protections violate the separation of powers, overruling the 90-year-old Humphrey's Executor precedent that has shielded independent agency heads from at-will presidential removal. Chief Justice Roberts's majority opinion explicitly declined to decide "the fate of officials not before us."
FERC was not a party, but legal analysis from Akin and Vinson & Elkins both note that FERC's organizing statute carries nearly identical for-cause removal language, and that FERC exercises the same rulemaking, investigation, and enforcement powers the Court used to strip the FTC's protection. Vinson & Elkins puts it plainly: FERC commissioners "will almost certainly be subject to removal by the President at will, without cause."
FortiBleed Update: Ransomware Groups Now Linked to the Campaign
Last month's FortiBleed credential-harvesting campaign against FortiGate firewalls has grown and gained an attribution. SOCRadar's July 6 update now puts the scope at more than 430,000 targeted FortiGate devices, up from the roughly 86,600 CISA cited when it first urged hardening on June 18. SOCRadar also found an operator logged into both the INC Ransom and Lynx ransomware negotiation panels using FortiBleed-derived access, tying the credential theft to at least 12 confirmed ransomware deployments.
Compliance Resources
Large Loads: NERC Moves the Line on Who Registers NERC is revising the criteria that decide which large loads (data centers, AI compute) must register as they interconnect, and is hosting a webinar on July 13 for entities that may fall under the new thresholds. If you own, co-locate with, or interconnect large load, this session is how you find out whether the revised criteria pull you into scope. It builds on the Level 3 Alert NERC issued in May, whose seven essential actions for transmission owners and planners carry an August 3 response deadline.
PRC-029-2 Ballot Closes Monday Last week's issue flagged NERC's additional ballot and non-binding poll for draft PRC-029-2, the replacement for the not-yet-effective PRC-029-1 ride-through standard (effective October 1, 2026). That window, open since July 3, closes July 13. If your fleet includes IBRs and you have not confirmed your registered ballot body representative has voted, this is the last call.
Important Dates
July 13, 2026: PRC-029-2 additional ballot and non-binding poll close in the NERC balloting system (Project 2025-05).
July 13, 2026: NERC webinar on revised registration criteria for large loads (Project 2026-02 Computational Loads / Large Loads Action Plan).
July 16, 2026: FERC July Open Meeting.
August 3, 2026: NERC Level 3 Alert entity responses due on modeling, study, protection, and communications practices for large loads.
Join our mailing list.
Weekly industry insights, news, and product updates.
More News

Four IBR standards, four different compliance clocks
The ERO ran one-on-one IBR sessions with GOs and GOPs. PRC-028, 029, 030 and MOD-026.

Iranian actors in energy-sector PLCs + Nico knows your fleet
CISA and the FBI name Energy in their updated PLC advisory. Plus nine weeks to the ride-through wave.

FERC orders mandatory NERC standards for data centers
A July 16 FERC order gives NERC a year-end deadline to bring large loads under mandatory standards.