What Does NERC CIP-015 Require?
CIP-015-1 adds Internal Network Security Monitoring, or INSM, to the NERC CIP standards. In plain English, covered entities need network data feeds, methods to detect anomalous network activity, and a documented way to evaluate what those detections mean. They also need to retain relevant INSM data and protect it from unauthorized deletion or modification.
Go to the requirementsWhat does CIP-015-1 actually require?
The standard applies INSM to networks protected by Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity. The exact applicability still depends on the responsible entity's NERC CIP scope and categorization.
Choose network data feeds
Use a documented risk based rationale to select feeds that monitor network activity, including connections, devices, and network communications.
Detect anomalous activity
Use one or more methods to detect anomalous network activity from the feeds selected under R1.1.
Evaluate what was detected
Use one or more methods to evaluate detected anomalous activity and determine what action should happen next.
Retain relevant INSM data
Retain data tied to activity the entity determines is anomalous, at least until the R1.3 action is complete.
Protect the INSM data
Protect the data supporting R1 and R2 against unauthorized deletion or modification.
Document the process
The standard's measures call for evidence showing the feeds, detection methods, evaluation process, retention, and protection controls were implemented.
When does CIP-015-1 take effect?
NERC lists October 1, 2028 as the U.S. effective date. The approved implementation plan then gives other applicable medium impact BES Cyber Systems with External Routable Connectivity up to 24 additional months.
Applicable systems at Control Centers and backup Control Centers are required to comply when CIP-015-1 becomes effective.
Other applicable medium impact BES Cyber Systems with External Routable Connectivity receive 24 additional calendar months under the implementation plan.
Confirm the implementation plan against your specific assets, jurisdiction, CIP-002 categorization, and current NERC or Regional Entity guidance before making compliance decisions.
What changes operationally?
The practical shift is from watching only the boundary to having a documented process for activity inside the protected network.
Know what traffic you can see
Map the networks in scope, choose useful collection points, and document why those feeds were selected.
Know what looks unusual
Use the selected data to surface activity that differs from expected or authorized behavior.
Know who investigates
Define how a detection is evaluated, who owns the decision, and when the event moves into another response process.
The useful workflow is more than another alert.
CIP-015 calls for detection and evaluation. An operator still needs enough evidence and context to decide what the activity means.
Collect approved network telemetry from the parts of the environment the entity has chosen to monitor.
Surface anomalous network activity using the methods defined for the deployment.
Correlate the available evidence to understand affected systems, timing, behavior, confidence, and uncertainty.
Give the operator a case record and enough context to determine the appropriate next action.
Where CrunchAtlas fits
CrunchAtlas supports the monitoring and investigation workflow around CIP-015. It doesn't certify compliance or replace the responsible entity's compliance program.
AtlasCyber
- Ingests approved network telemetry and existing security data
- Surfaces anomalous behavior for investigation
- Correlates network and host evidence where available
- Creates investigated cases with confidence and supporting evidence
ClemAI
- Supports triage and investigation of detected activity
- Explains why activity matters and what remains uncertain
- Recommends next steps for operator review
- Produces decision ready investigation and incident reporting
CIP-015 questions, answered
Who is in scope for CIP-015-1?
The standard covers networks protected by the responsible entity's Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity, subject to the standard's applicability language and the entity's CIP-002 categorization.
Does CIP-015 require full packet capture?
No. R1.1 requires network data feeds chosen using a risk based rationale. The standard doesn't mandate one specific feed type or require full packet capture everywhere.
Does CIP-015 require a network baseline?
Not as a single prescribed method. The standard requires methods to detect anomalous network activity. A network communication baseline is listed as one example of evidence, but other detection methods can be used.
How long does anomalous INSM data need to be retained?
R2 requires relevant INSM data to be retained at least until the action supporting R1.3 is complete. Separately, the compliance section requires evidence of each requirement to be retained for three calendar years.
Does buying CrunchAtlas make an entity compliant?
No. CrunchAtlas can support network visibility, anomaly investigation, evidence, and reporting. The responsible entity remains accountable for applicability, documented processes, risk rationale, governance, retention, protection, and compliance decisions.
What's the status of CIP-015-2?
NERC adopted CIP-015-2 in June 2026 and filed it with FERC on June 18, 2026. NERC currently lists CIP-015-2 as filed and pending regulatory approval. This page treats CIP-015-1 as the approved compliance baseline unless that status changes.
Current standards status
NERC submitted CIP-015-2 to FERC on June 18, 2026. Until regulatory approval changes the baseline, implementation decisions should distinguish the approved CIP-015-1 requirements from the proposed revisions in CIP-015-2.
Need to see how your current monitoring and investigation workflow lines up?
We can walk through the environment, existing telemetry, investigation process, and where CrunchAtlas fits.
Talk to CrunchAtlas