What SCOTUS ruling could mean for FERC

Eliminate friction. Automate compliance. Simplify NERC with Raptor Comply.

Patch PROMOD V and e-mesh EMS. The July 13 webinar on Large Loads registration changes. Plus what SCOTUS ruling could mean for FERC.

CISA published two industrial control system advisories for Hitachi Energy on July 7: PROMOD V and e-mesh EMS. Vendor fixes are available for both. Read on below.

Separately, the Supreme Court cleared a path this week to test whether FERC commissioners can be removed by the President at will.

NERC's additional ballot for draft PRC-029-2 closes Monday, July 13. If your fleet includes IBRs, confirm your registered ballot body representative has voted. Also next week, NERC sheds light on upcoming registration thresholds for large loads.

Product Update

NERC Standards Widget Gets an Applicability Column

The NERC Standards dashboard widget shows you what standards are coming and when. We just added an Applicability column. Now you can also see at a glance whether an upcoming standard applies to your registration category or impact level, without opening each one to check.

In this new column, CIP standards display a Low, Medium or High impact-rating pill. O&P standards display a Cat 1 or Cat 2 registration-category pill, left blank where a standard has no GO/GOP scope, but we're adding TO/TOP in shortly.


Screenshot 2026-07-07 at 9.34.06 AM

Multi-Level Lists in Policy Editors For all you list makers, you can indent your bulleted and numbered lists across your policies, plans and procedures in the Policies feature.

Industry Update

CISA Discloses Two Hitachi Energy Vulnerabilities in One Day

On July 7, CISA published two ICS advisories for Hitachi Energy products used in grid planning and operations. Both have vendor fixes available now.

  • PROMOD V (CVE-2026-10763, CVSS 7.1): the generation and transmission planning tool many GOs and GOPs use for system studies transmits data over HTTP instead of HTTPS through its bundled Digipede server, letting an attacker intercept or manipulate study data in transit. Fixed in version 1.0.11, which adds HTTPS support.

  • e-mesh EMS (CVE-2026-42945, CVSS 8.1): Hitachi Energy's energy management system ships a version of NGINX with a heap-based buffer overflow in its rewrite module. An unauthenticated attacker can trigger it with a crafted HTTP request, crashing the worker process and, without ASLR protection, potentially executing code. Hotfixes update the bundled NGINX version.

If either runs in your environment, patch it. For CIP programs, treat the update as a baseline configuration change under CIP-010 and log it against your CIP-007 patch management process.

Supreme Court Clears a Path to Test FERC's Independence

The Supreme Court ruled 6-3 on June 29 in Trump v. Slaughter that the FTC's for-cause removal protections violate the separation of powers, overruling the 90-year-old Humphrey's Executor precedent that has shielded independent agency heads from at-will presidential removal. Chief Justice Roberts's majority opinion explicitly declined to decide "the fate of officials not before us."

FERC was not a party, but legal analysis from Akin and Vinson & Elkins both note that FERC's organizing statute carries nearly identical for-cause removal language, and that FERC exercises the same rulemaking, investigation, and enforcement powers the Court used to strip the FTC's protection. Vinson & Elkins puts it plainly: FERC commissioners "will almost certainly be subject to removal by the President at will, without cause."

FortiBleed Update: Ransomware Groups Now Linked to the Campaign

Last month's FortiBleed credential-harvesting campaign against FortiGate firewalls has grown and gained an attribution. SOCRadar's July 6 update now puts the scope at more than 430,000 targeted FortiGate devices, up from the roughly 86,600 CISA cited when it first urged hardening on June 18. SOCRadar also found an operator logged into both the INC Ransom and Lynx ransomware negotiation panels using FortiBleed-derived access, tying the credential theft to at least 12 confirmed ransomware deployments.

Compliance Resources

Large Loads: NERC Moves the Line on Who Registers NERC is revising the criteria that decide which large loads (data centers, AI compute) must register as they interconnect, and is hosting a webinar on July 13 for entities that may fall under the new thresholds. If you own, co-locate with, or interconnect large load, this session is how you find out whether the revised criteria pull you into scope. It builds on the Level 3 Alert NERC issued in May, whose seven essential actions for transmission owners and planners carry an August 3 response deadline.

PRC-029-2 Ballot Closes Monday Last week's issue flagged NERC's additional ballot and non-binding poll for draft PRC-029-2, the replacement for the not-yet-effective PRC-029-1 ride-through standard (effective October 1, 2026). That window, open since July 3, closes July 13. If your fleet includes IBRs and you have not confirmed your registered ballot body representative has voted, this is the last call.

Important Dates

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.
Somerville, MA
02143

Company

© 2026 Raptor Maps, Inc.

444 Somerville Ave.

Somerville, MA 02143

Company