What Does NERC CIP-015Actually Require?

CIP-015-1 adds Internal Network Security Monitoring, or INSM, to the NERC CIP standards. Covered entities need network data feeds, methods to detect anomalous network activity, and a documented way to evaluate what those detections mean.

Start with the approved standard.

CIP-015-1 is the approved compliance baseline. Applicability and implementation timing still depend on the responsible entity's NERC CIP scope and categorization.

01

CIP-015-1 is approved.

NERC lists CIP-015-1 as approved. CIP-015-2 has been filed with FERC and is pending regulatory approval.

02

Applicability is specific.

The standard applies to networks protected by Electronic Security Perimeters for high impact BES Cyber Systems and applicable medium impact systems with External Routable Connectivity.

03

October 1, 2028.

NERC lists October 1, 2028 as the U.S. effective date for the initial applicable systems under the implementation plan.

04

October 1, 2030.

Other applicable medium impact BES Cyber Systems with External Routable Connectivity receive 24 additional calendar months under the approved implementation plan.

Confirm the implementation plan against your specific assets, jurisdiction, CIP-002 categorization, and current NERC or Regional Entity guidance before making compliance decisions.

The requirement is more than another alert.

The short version: see internal network activity, detect what looks wrong, evaluate it, keep the relevant evidence long enough to act, and protect that evidence.

R1.1

Choose network data feeds

Use a documented risk based rationale to select feeds that monitor network activity, including connections, devices, and network communications.

R1.2

Detect anomalous activity

Use one or more methods to detect anomalous network activity from the feeds selected under R1.1.

R1.3

Evaluate what was detected

Use one or more methods to evaluate detected anomalous activity and determine what action should happen next.

R2

Retain relevant INSM data

Retain data tied to activity the entity determines is anomalous, at least until the R1.3 action is complete.

R3

Protect the INSM data

Protect the data supporting R1 and R2 against unauthorized deletion or modification.

EVIDENCE

Document the process

The standard's measures call for evidence showing the feeds, detection methods, evaluation process, retention, and protection controls were implemented.

CIP-015-1 doesn't require one specific monitoring product or one specific feed type. The responsible entity chooses and documents the approach that fits its network and risk.

The workflow needs four steps.

CIP-015 calls for detection and evaluation. An operator still needs enough evidence and context to decide what the activity means.

01

Observe

Collect approved network telemetry from the parts of the environment the entity has chosen to monitor.

02

Detect

Surface anomalous network activity using the methods defined for the deployment.

03

Investigate

Correlate the available evidence to understand affected systems, timing, behavior, confidence, and uncertainty.

04

Decide and document

Give the operator a case record and enough context to determine the appropriate next action.

Where CrunchAtlas fits.

CrunchAtlas supports the monitoring and investigation workflow around CIP-015. It doesn't certify compliance or replace the responsible entity's compliance program.

CrunchAtlas can deploy cloud, on premises, or fully air gapped. Operators retain control of consequential actions.

CIP-015 questions, answered.

Who is in scope for CIP-015-1?

The standard covers networks protected by the responsible entity's Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity, subject to the standard's applicability language and the entity's CIP-002 categorization.

Does CIP-015 require full packet capture?

No. R1.1 requires network data feeds chosen using a risk based rationale. The standard doesn't mandate one specific feed type or require full packet capture everywhere.

Does CIP-015 require a network baseline?

Not as a single prescribed method. The standard requires methods to detect anomalous network activity. A network communication baseline is listed as one example of evidence, but other detection methods can be used.

How long does anomalous INSM data need to be retained?

R2 requires relevant INSM data to be retained at least until the action supporting R1.3 is complete. Separately, the compliance section requires evidence of each requirement to be retained for three calendar years.

Does buying CrunchAtlas make an entity compliant?

No. CrunchAtlas can support network visibility, anomaly investigation, evidence, and reporting. The responsible entity remains accountable for applicability, documented processes, risk rationale, governance, retention, protection, and compliance decisions.

What's the status of CIP-015-2?

NERC adopted CIP-015-2 in June 2026 and filed it with FERC on June 18, 2026. NERC currently lists CIP-015-2 as filed and pending regulatory approval. This page treats CIP-015-1 as the approved compliance baseline unless that status changes.

Sources and standards

Implementation decisions should distinguish the approved CIP-015-1 requirements from proposed revisions in CIP-015-2.

Know what you can see. Know how you'll evaluate what looks wrong.

We can walk through the environment, existing telemetry, investigation process, and where CrunchAtlas fits.

CrunchAtlas does not certify compliance. Operators and responsible entities retain control of consequential actions and compliance decisions.