What Does NERC CIP-015Actually Require?
CIP-015-1 adds Internal Network Security Monitoring, or INSM, to the NERC CIP standards. Covered entities need network data feeds, methods to detect anomalous network activity, and a documented way to evaluate what those detections mean.
Start with the approved standard.
CIP-015-1 is the approved compliance baseline. Applicability and implementation timing still depend on the responsible entity's NERC CIP scope and categorization.
CIP-015-1 is approved.
NERC lists CIP-015-1 as approved. CIP-015-2 has been filed with FERC and is pending regulatory approval.
Applicability is specific.
The standard applies to networks protected by Electronic Security Perimeters for high impact BES Cyber Systems and applicable medium impact systems with External Routable Connectivity.
October 1, 2028.
NERC lists October 1, 2028 as the U.S. effective date for the initial applicable systems under the implementation plan.
October 1, 2030.
Other applicable medium impact BES Cyber Systems with External Routable Connectivity receive 24 additional calendar months under the approved implementation plan.
Confirm the implementation plan against your specific assets, jurisdiction, CIP-002 categorization, and current NERC or Regional Entity guidance before making compliance decisions.
The requirement is more than another alert.
The short version: see internal network activity, detect what looks wrong, evaluate it, keep the relevant evidence long enough to act, and protect that evidence.
Choose network data feeds
Use a documented risk based rationale to select feeds that monitor network activity, including connections, devices, and network communications.
Detect anomalous activity
Use one or more methods to detect anomalous network activity from the feeds selected under R1.1.
Evaluate what was detected
Use one or more methods to evaluate detected anomalous activity and determine what action should happen next.
Retain relevant INSM data
Retain data tied to activity the entity determines is anomalous, at least until the R1.3 action is complete.
Protect the INSM data
Protect the data supporting R1 and R2 against unauthorized deletion or modification.
Document the process
The standard's measures call for evidence showing the feeds, detection methods, evaluation process, retention, and protection controls were implemented.
CIP-015-1 doesn't require one specific monitoring product or one specific feed type. The responsible entity chooses and documents the approach that fits its network and risk.
The workflow needs four steps.
CIP-015 calls for detection and evaluation. An operator still needs enough evidence and context to decide what the activity means.
Observe
Collect approved network telemetry from the parts of the environment the entity has chosen to monitor.
Detect
Surface anomalous network activity using the methods defined for the deployment.
Investigate
Correlate the available evidence to understand affected systems, timing, behavior, confidence, and uncertainty.
Decide and document
Give the operator a case record and enough context to determine the appropriate next action.
Where CrunchAtlas fits.
CrunchAtlas supports the monitoring and investigation workflow around CIP-015. It doesn't certify compliance or replace the responsible entity's compliance program.
Network Detection and Response
Use approved network telemetry to surface anomalous behavior and investigate activity across supported network segments.
Explore NDR → 02Alert Investigation
Work detected activity into an investigated case with supporting evidence, confidence, uncertainty, and recommended next steps for operator review.
Explore Alert Investigation →CrunchAtlas can deploy cloud, on premises, or fully air gapped. Operators retain control of consequential actions.
CIP-015 questions, answered.
Who is in scope for CIP-015-1?
The standard covers networks protected by the responsible entity's Electronic Security Perimeters for high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity, subject to the standard's applicability language and the entity's CIP-002 categorization.
Does CIP-015 require full packet capture?
No. R1.1 requires network data feeds chosen using a risk based rationale. The standard doesn't mandate one specific feed type or require full packet capture everywhere.
Does CIP-015 require a network baseline?
Not as a single prescribed method. The standard requires methods to detect anomalous network activity. A network communication baseline is listed as one example of evidence, but other detection methods can be used.
How long does anomalous INSM data need to be retained?
R2 requires relevant INSM data to be retained at least until the action supporting R1.3 is complete. Separately, the compliance section requires evidence of each requirement to be retained for three calendar years.
Does buying CrunchAtlas make an entity compliant?
No. CrunchAtlas can support network visibility, anomaly investigation, evidence, and reporting. The responsible entity remains accountable for applicability, documented processes, risk rationale, governance, retention, protection, and compliance decisions.
What's the status of CIP-015-2?
NERC adopted CIP-015-2 in June 2026 and filed it with FERC on June 18, 2026. NERC currently lists CIP-015-2 as filed and pending regulatory approval. This page treats CIP-015-1 as the approved compliance baseline unless that status changes.
Sources and standards
Implementation decisions should distinguish the approved CIP-015-1 requirements from proposed revisions in CIP-015-2.
This page is educational and does not replace NERC, FERC, Regional Entity, legal, engineering, or compliance guidance.
Know what you can see. Know how you'll evaluate what looks wrong.
We can walk through the environment, existing telemetry, investigation process, and where CrunchAtlas fits.
CrunchAtlas does not certify compliance. Operators and responsible entities retain control of consequential actions and compliance decisions.