2 min read  ·  326 words

NAESB’s WEQ Cybersecurity Subcommittee and Business Practices Subcommittee will meet on August 18, 2026, to review proposed standardized contract language for a cybersecurity addendum designed to support implementation of FERC Order No. 912. The draft terms address vendor vulnerability disclosure reporting and third-party software verification — two pillars of supply chain transparency that have long lacked consistent procurement frameworks across the electric sector. This meeting marks the first public review of language that could become the baseline for how utilities and grid operators hold vendors accountable for the security of critical infrastructure components.

FERC Order No. 912, issued in 2024, directed the Electric Reliability Organization to develop supply chain risk management standards that go beyond the perimeter defenses of CIP-013. The order recognized that software supply chain compromises — whether through unpatched vulnerabilities, malicious code insertion, or opaque third-party dependencies — pose systemic risk to the bulk electric system. NAESB’s role in translating that mandate into practical contract terms reflects the reality that regulatory compliance increasingly runs through procurement offices, not just control rooms.

The proposed addendum, accessible through NAESB’s meeting materials, attempts to standardize clauses that today vary widely across individual utility contracts. By establishing common expectations for vulnerability disclosure timelines, software bill-of-materials transparency, and independent verification of third-party code, the language aims to reduce negotiation friction and close gaps that adversaries exploit. Industry stakeholders have long argued that without such standardization, smaller entities lack leverage to demand adequate assurances, while larger utilities duplicate effort crafting bespoke terms.

The August 18 session is open to all interested parties, though non-members must register and pay a participation fee. Comments and revisions from this review will feed into NAESB’s broader 2026 Annual Plan deliverables, with the goal of producing a reference addendum that FERC, NERC, and regional entities can cite in future compliance guidance. For vendors, the signal is clear: the era of voluntary transparency is ending, and contractual accountability for software integrity is becoming a condition of market access.

Read the full report at Energy Central.

Written by