1 min read  ·  280 words

NAESB’s cybersecurity committee has revised proposed contract language that would embed “Secure By Design” requirements into procurement agreements for critical infrastructure operators, giving asset owners contractual leverage to demand timely vulnerability disclosures and secure development practices from vendors. The addendum aligns with NIST and CISA guidance and is now open for public comment through September 1 before a September 3 subcommittee meeting finalizes the language.

The move marks a significant shift from voluntary frameworks to enforceable procurement terms. For years, federal agencies have urged manufacturers to adopt secure-by-design principles, but adoption has been uneven across the sprawling supply chain that serves electric utilities, pipelines, and other critical sectors. By codifying these expectations into standard contract addenda, NAESB creates a mechanism that operators can attach to every purchase order — turning best-practice guidance into a baseline contractual obligation.

Vendors should pay close attention. The revised language is expected to require timely notification of discovered vulnerabilities, evidence of secure development lifecycles, and commitments to patch management — provisions that will carry legal weight once incorporated into signed agreements. Smaller suppliers, in particular, may face compliance costs that reshape their product roadmaps. Asset owners, meanwhile, gain a standardized tool that reduces the negotiation burden on individual procurement teams and creates consistency across the sector.

The comment period is deliberately inclusive: any interested party, regardless of NAESB membership, can submit informal feedback to the NAESB office. This broad aperture reflects the reality that cybersecurity risk in the energy supply chain is a shared problem — one that no single operator or vendor can solve alone. The September 3 meeting will determine whether the current draft advances toward formal adoption or requires further iteration.

Read the full report at Energy Central.

Written by