What Does NERC CIP-015 Require?

CIP-015-1 adds Internal Network Security Monitoring, or INSM, to the NERC CIP standards. In plain English, covered entities need network data feeds, methods to detect anomalous network activity, and a documented way to evaluate what those detections mean. They also need to retain relevant INSM data and protect it from unauthorized deletion or modification.

Go to the requirements

What does CIP-015-1 actually require?

The standard applies INSM to networks protected by Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity. The exact applicability still depends on the responsible entity's NERC CIP scope and categorization.

R1.1

Choose network data feeds

Use a documented risk based rationale to select feeds that monitor network activity, including connections, devices, and network communications.

R1.2

Detect anomalous activity

Use one or more methods to detect anomalous network activity from the feeds selected under R1.1.

R1.3

Evaluate what was detected

Use one or more methods to evaluate detected anomalous activity and determine what action should happen next.

R2

Retain relevant INSM data

Retain data tied to activity the entity determines is anomalous, at least until the R1.3 action is complete.

R3

Protect the INSM data

Protect the data supporting R1 and R2 against unauthorized deletion or modification.

EVIDENCE

Document the process

The standard's measures call for evidence showing the feeds, detection methods, evaluation process, retention, and protection controls were implemented.

CIP-015-1 doesn't require one specific monitoring product or one specific feed type. The responsible entity chooses and documents the approach that fits its network and risk.

When does CIP-015-1 take effect?

NERC lists October 1, 2028 as the U.S. effective date. The approved implementation plan then gives other applicable medium impact BES Cyber Systems with External Routable Connectivity up to 24 additional months.

Initial compliance October 1, 2028

Applicable systems at Control Centers and backup Control Centers are required to comply when CIP-015-1 becomes effective.

Phased compliance October 1, 2030

Other applicable medium impact BES Cyber Systems with External Routable Connectivity receive 24 additional calendar months under the implementation plan.

Confirm the implementation plan against your specific assets, jurisdiction, CIP-002 categorization, and current NERC or Regional Entity guidance before making compliance decisions.

What changes operationally?

The practical shift is from watching only the boundary to having a documented process for activity inside the protected network.

01

Know what traffic you can see

Map the networks in scope, choose useful collection points, and document why those feeds were selected.

02

Know what looks unusual

Use the selected data to surface activity that differs from expected or authorized behavior.

03

Know who investigates

Define how a detection is evaluated, who owns the decision, and when the event moves into another response process.

The useful workflow is more than another alert.

CIP-015 calls for detection and evaluation. An operator still needs enough evidence and context to decide what the activity means.

01Observe

Collect approved network telemetry from the parts of the environment the entity has chosen to monitor.

02Detect

Surface anomalous network activity using the methods defined for the deployment.

03Investigate

Correlate the available evidence to understand affected systems, timing, behavior, confidence, and uncertainty.

04Decide and document

Give the operator a case record and enough context to determine the appropriate next action.

Where CrunchAtlas fits

CrunchAtlas supports the monitoring and investigation workflow around CIP-015. It doesn't certify compliance or replace the responsible entity's compliance program.

AtlasCyber

  • Ingests approved network telemetry and existing security data
  • Surfaces anomalous behavior for investigation
  • Correlates network and host evidence where available
  • Creates investigated cases with confidence and supporting evidence

ClemAI

  • Supports triage and investigation of detected activity
  • Explains why activity matters and what remains uncertain
  • Recommends next steps for operator review
  • Produces decision ready investigation and incident reporting
CrunchAtlas can deploy cloud, on premises, or fully air gapped. Operators retain control of consequential actions.

CIP-015 questions, answered

Who is in scope for CIP-015-1?

The standard covers networks protected by the responsible entity's Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity, subject to the standard's applicability language and the entity's CIP-002 categorization.

Does CIP-015 require full packet capture?

No. R1.1 requires network data feeds chosen using a risk based rationale. The standard doesn't mandate one specific feed type or require full packet capture everywhere.

Does CIP-015 require a network baseline?

Not as a single prescribed method. The standard requires methods to detect anomalous network activity. A network communication baseline is listed as one example of evidence, but other detection methods can be used.

How long does anomalous INSM data need to be retained?

R2 requires relevant INSM data to be retained at least until the action supporting R1.3 is complete. Separately, the compliance section requires evidence of each requirement to be retained for three calendar years.

Does buying CrunchAtlas make an entity compliant?

No. CrunchAtlas can support network visibility, anomaly investigation, evidence, and reporting. The responsible entity remains accountable for applicability, documented processes, risk rationale, governance, retention, protection, and compliance decisions.

What's the status of CIP-015-2?

NERC adopted CIP-015-2 in June 2026 and filed it with FERC on June 18, 2026. NERC currently lists CIP-015-2 as filed and pending regulatory approval. This page treats CIP-015-1 as the approved compliance baseline unless that status changes.

Current standards status

CIP-015-1 is approved. CIP-015-2 is pending regulatory approval.

NERC submitted CIP-015-2 to FERC on June 18, 2026. Until regulatory approval changes the baseline, implementation decisions should distinguish the approved CIP-015-1 requirements from the proposed revisions in CIP-015-2.

Need to see how your current monitoring and investigation workflow lines up?

We can walk through the environment, existing telemetry, investigation process, and where CrunchAtlas fits.

Talk to CrunchAtlas