2 min read  Β·  388 words

A NERC Standards Drafting Team has quietly acknowledged that utilities adopting cloud-based security tools β€” specifically Electronic Access Control or Monitoring Systems (EACMS) or Physical Access Control Systems (PACS) β€” will be forced to comply with the new CIP “100 series” standards, despite prior assurances that entities avoiding cloud infrastructure could opt out. The concession emerged during a recent meeting with NERC entity compliance staff, where a drafting team member confirmed the mandatory scope applies whenever cloud-hosted software meets the EACMS or PACS definitions, creating a compliance trap for utilities modernizing their security operations.

The revelation undermines the drafting team’s public messaging that the 100 series β€” formally known as Project 2023-09 Risk Management for Third-Party Cloud Services β€” would only burden entities choosing to place Bulk Electric System Cyber Systems in the cloud. In practice, many utilities have no realistic path to cloud-based Security Information and Event Management (SIEM), multi-factor authentication, or physical access control without triggering the full weight of the new standards. The draft requirements, posted last month, impose extensive third-party risk management, supply chain, and incident reporting obligations that were designed for cloud-hosted BES Cyber Systems but now sweep in cloud-delivered security services.

This outcome contradicts the original Standards Authorization Request, which explicitly identified cloud-based EACMS and PACS as the two most urgent problems to solve and pleaded with the drafting team to prioritize them. Instead, the team pursued a broader framework that leaves utilities facing a stark choice: forgo modern cloud security capabilities or accept a compliance burden that many consider disproportionate to the risk. For an industry under pressure to improve detection and response times, the practical effect may be to slow cloud adoption in precisely the areas β€” identity management, log aggregation, physical security β€” where cloud services offer the strongest operational advantages.

NERC and the drafting team now face pointed questions about whether the 100 series achieves its stated purpose or simply exchanges one compliance deadlock for another. Utilities evaluating cloud security investments will need to factor the full 100 series compliance cost into their business cases, and regional entities should prepare for audit scrutiny on any cloud-hosted EACMS or PACS deployments. The drafting team’s next comment period will be a critical test of whether the standards can be narrowed to their original intent or whether the “fine print” becomes the new reality.

Read the full report at Energy Central.

Written by