2 min read  ·  304 words

The draft NERC CIP 100 series standards for cloud computing, released in July, may be fundamentally unenforceable because their requirements are so vaguely defined that entities cannot be proven non-compliant. The standards drafting team has published four or five of an expected 12 to 13 standards, but core definitions like “BES Cyber System or Service” rely on undefined terms such as “system” and “service,” creating a logical gap where a responsible entity could simply declare it has no applicable assets and face no viable audit challenge.

This problem echoes physicist Wolfgang Pauli’s famous dismissal of theories that are “not even wrong” — statements so ill-defined they cannot be falsified. In regulatory terms, a standard that cannot be violated is not a standard at all; it is administrative theater. The North American Electric Reliability Corporation’s critical infrastructure protection framework has historically relied on bright-line criteria and measurable evidence. The CIP 100 series, intended to modernize rules for cloud adoption, risks inverting that logic by embedding ambiguity into its foundation.

The practical stakes are significant. Electric utilities and grid operators are accelerating cloud migration for functions ranging from data analytics to operational technology management. Without auditable, falsifiable requirements, regulators cannot verify that cloud-hosted assets affecting bulk electric system reliability are properly secured. The current draft effectively permits a compliance strategy of selective definition: if the scope is undefined, the obligation disappears.

NERC’s standards drafting team has acknowledged the work is early, and several more standards remain under development. But the pattern established in the initial release suggests a structural issue, not a drafting oversight. Industry stakeholders should press for explicit, testable definitions — particularly for “system,” “service,” and the reliability impact threshold — before the series advances to ballot. Grid security in a cloud-native era demands standards that can survive an audit, not just a reading.

Read the full report at Energy Central.

Written by