ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-103

Foundations · EC-WP-103

NERC Standards: Institutional Design & Authority

The NERC Reliability Standards are not technical documents. They are federally enforceable obligations grounded in Section 215 of the Federal Power Act.

The NERC Reliability Standards are not technical documents. They are federally enforceable obligations grounded in Section 215 of the Federal Power Act. That status is what makes the framework's institutional design matter — separating who writes the standards, who approves them, who enforces them, and who reviews enforcement. Knowing the architecture tells you what each part can and cannot do. Section 215 is what turned reliability from a best practice into a federal obligation. Read it once. It explains more about NERC's authority than the standards do. Each standard follows a fixed structure. The structure is enforceability, not arbitrary formatting. Operations standards govern real-time decisions. Planning standards govern future conditions. Protection standards govern containment. Knowing which family applies tells you which audit posture to expect. VRF and VSL together set the penalty band. The matrix is public. Programs that don't self-assess penalty exposure get surprised. The framework adapts. Each standards revision traces to specific events, FERC directives, or stakeholder input. Programs that respect the architecture work with the framework. Programs that fight it work against it. Both approaches show up in enforcement records. From the Field Practitioner perspectives that frame the chapter ahead. The standards aren't just technical documents.

Contents

  1. Foreword
  2. The Legal and Institutional Foundation of the Reliability Standards
  3. The Architecture of a Reliability Standard
  4. Operations Standards and Real- Time Reliability Authority
  5. Planning and System Performance Standards
  6. Protection and Control Standards and Disturbance Containment
  7. Emergency Preparedness and System Restoration Standards
  8. Critical Infrastructure Protection Standards and Cyber Reliability
  9. Measures, Evidence, and the Logic of Demonstrated Compliance
  10. Regional Entity Oversight and the Administration of Compliance
  11. Evolution of the Reliability Standards and Institutional Adaptation
  12. Glossary
  13. About the Author
  14. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.

That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.

These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

EC-WP-103 NERC Reliability Standards: Institutional Design

Chapter 2

The Architecture of a Reliability Standard

Each Reliability Standard has to follow the structure shown above. The reason for this structure is not arbitrary. Rather, the purpose of the structure is to ensure that each standard is written in a way that is enforceable, not subject to local interpretation, and that compliance can be easily measured. Generally, a standard will be composed of a Purpose, applicable sections, a Glossary of Terms, Requirements, Measures, Violation Risk Factors and Violation Severity Levels. There may be other compliance items that are included in a standard, such as implementation plans or attachments. The purpose statement defines the reliability objective that the standard is intended to attain. Although brief, the purpose statement indicates the reliability risk that the drafting team had in mind. More commonly, an operating standard is intended to ensure the continuity of real-time system reliability, a planning standard to ensure the performance of the system to certain contingencies in the future, and a protection standard to achieve fault detection and isolation. The purpose statement is for interpretive use only and does not create obligations. The Requirements constitute the obligations of the user. An Applicability records the registered functions for which the standard is applicable. This is a threshold determination. The requirement(s) in the standard are enforceable only against those entities registered for the applicable function(s) as listed in the Applicability section. An Applicability section functions as a “filter” to jurisdiction and is derived from the functional model embodied in the NERC Entity Registration system. Thus a Requirement addressing the behavior of a Transmission Operator will address a different set of operating activities than that addressed by a Requirement applicable to a Planning Coordinator. Defined terms are more than a convenience. The NERC Glossary of Terms provides a set of standardized definitions of terms, defined and approved in the same federal rulemaking process as the standards themselves. In a Requirement, each defined term in a statement is interpreted using the definition of the term in the Glossary. Without a defined term, each Region can impose a different interpretation, reducing some of the national uniformity of the Standard. Interpretive disputes about the intent of the Requirements often are about defined terms. The Glossary definitions therefore can have a direct enforcement consequence. Objectives, Rationale, Applicability, Procedures and Definitions are all necessary components that provide context for each Standard, but it is the Requirements in each Standard that form the backbone of each Reliability Standard. These are specifically numbered and written in the imperative language. The drafting convention identifies the responsible party, the actions or conditions that must be taken achieved, and any criteria that must be met. The sub-division of

requirements into component parts (using R1.1, R1.2, etc. ) allows for the enforcement of specific actions or conditions within a requirement, in case only some of them need to be enforced for non compliance. Not all requirements are created equal. Some requirements mandate that procedures must be designed and in place while others specify action to be taken under certain conditions. Other requirements have performance characteristics associated with tolerances (i.e. ranges). The different types of requirements reflect the differences in reliability goals that are often quite different for different classes of standards. Documentation-based requirements tend to be more to do with a function related to governmental or management type activities whereas real-time requirements tend to be more to do with sustaining the continuing operation of the system and maintaining variable parameters within certain allowable tolerances. A Measure is a tool that accompanies a Requirement. The measure of compliance with a requirement is the type of evidence that serves as proof of the requirement’s being satisfied. A Measure does not create a requirement; it only clarifies how the requirements of an earlier clause may be satisfied. Measures in standards and regulations have evolved from a focus on documenting the presence of certain policies or procedures to an emphasis on providing direct evidence of their implementation. Such direct implementation or performance oriented measures are often in the form of dated entries in a log, report, etc., output of automated systems, etc. There is a trend towards an increased institutional focus on performance evidence over merely verifying policy statements. Violation Risk Factors (VRFs) establish a lower, medium or higher violation risk factor for each Requirement based on the potential impact on Bulk Electric System reliability. VRFs indicate the potential reliability consequence should a violation occur. They do not verify whether a violation occurred. VRFs may be higher for Requirements associated with real-time control of a system element or aspect of protection system performance, where they could affect grid stability or cascading risk, and lower for planning or documentation Requirements, where the immediate potential for impact to the grid reliability is not as pronounced. Violation Severity Levels are a method to determine the degree of noncompliance for violations of the requirements and rule provisions. Violation Severity Levels set a standard for distinguishing between substantial and less-than-substantial noncompliances. Enforcement using the VSLs will provide clarity as to what severity is imposed upon what degree of noncompliance based on specific criteria. Enforcement filings may be available in situations in which they are made public, and the VSLs will impact the ultimate penalties, if any, that will be imposed, as well as the extent to which reduction may be sought and is allowable. VRFs and VSLs provide a risk assessment framework within the enforcement mechanism of an FCC regulatory approach. The standards may contain the attachment(s) or technical references. Some standards are accompanied by performance tables, contingency tables or calculation methods. The attachment(s) or technical references approved together with the standard become an integral part of the standard. This may be necessary to cover sensitive reliability assessments where a small variation in a quantitative parameter can significantly affect the results. The balance sought in a Reliability Standard between clarity, enforceability and technical flexibility is reflected in its architecture. A standard structure that accommodates varying levels of detail

for different standard families, and an overall template that affords scope for differences in content among individual standards within a family address this balance. The components of the structure Purpose, Applicability, Definitions, Requirements, Measures, Vulnerabilities, Risk-Associated Factors, Vulnerability Reduction Factors and Validation and Verification Statements - serve different institutional purposes. It is important to have an understanding of the Obligation Architecture prior to examining individual standard families in detail. Without this understanding, obligations contained in a Requirement will appear more procedural than structural. The Obligation Architecture exposes the enforcement logic contained within the requirements language.

End-of-Chapter Summary

A Reliability Standard is composed in accordance with a consistent institutional template consisting of enforceable Requirements, identified in the standard with specified expectation for evidence and risk classification. Applicability, terms defined in this chapter, Measures, Violation Risk Factors, and Violation Severity Levels are incorporated into a governance instrument that is risk-based, measurable, and enforceable as provided in Section 215.

Chapter 3

Operations Standards and Real- Time Reliability Authority

The Operations Standards deal with activities affecting the BES in the real time or near real time operating horizon. They are associated with BAL, TOP and IRO standards. They are designed to protect the frequency, voltage and thermal stability standards within defined parameters. They were written with the understanding that operational decisions are made under time pressure and often with incomplete knowledge. They were written to be enforceable while providing clarity under stringent time constraints. Communication frequency in power systems is the process of adjusting amount of power supplied or used by generators or transmission lines. These adjustments are necessary to maintain the frequency within specified limits by maximizing utilization of available transmission transfer capacity using real time information. The BAL standards are oriented towards controlling the rate of interconnection so that generation and interchange can be controlled to maintain frequency within allowable limits. The primary focus is on the function of the Balancing Authority. Standards in this family usually reference Control Performance Standards, Disturbance Control Standard, and performance measurements. The reliability is in the frequency response and/or area control error, rather than the record. The measurements are usually based on performance information, disturbance reports or calculation and record of the necessary processes. TOP Standards for Transmission Operators TOP standards are rules and procedures for Transmission Operators (TOs) to operate and control their systems in order to maintain reliability. Often the TOP standards refer to System Operating Limits and how TOs should operate their systems within these limits. These standards cover the aspects of situational awareness, real time monitoring, procedures for communication and actions when System Operating Limits are being approached or breached. Sometimes they require operators to perform specific actions when breaches are notified, or to follow documented operating procedures to manage specific situations. Expected evidence includes operator logs, operator directives and time-stamped operator records. This revision imposes the IRO standards upon

the Reliability Coordinator (RC) function. The RC authority structure described herein extends beyond a single transmission system or Balancing Authority Area. The Reliability Coordinator is responsible for Reliability within its Reliability Coordinator Area, and shall coordinate with Transmission Operators and Balancing Authorities to protect Wide Area reliability. Certain requirements describe in the following text in terms of the Reliability Coordinator “monitoring” or “ordering” or “verifying” certain actions, which

describe a hierarchical authority while nevertheless preserving functional boundaries and preventing the Reliability Coordinator from having operational control of resources. System Operating Limits (SOL) and Interconnection Reliability Operating Limits (IROL) are both Operating Families. When a Requirement cites an SOL or IROL it invokes a specific technical and jurisdictional rule. Exceeding an IROL has higher reliability risk consequences, since violations of an IROL rule may have cascading affects in the power system. Requirements associated with IROL exceedances often carry a higher Violation Risk Factor because the rule drafting is intended to recognize the greater system instability risk posed by not correcting potential problems with time to prevent a potential power system disruption. Standards of operation often require an operation plan, study or procedure to be developed. These documentation are not necessarily to be performed in normal time. They are there to help management to prepare for possible crisis. During an enforcement review, it can be very difficult to distinguish between the documentation of procedures and the actual implementation of the procedures. It should be demonstrated that the procedures have been applied as required, and not only that they exist. The communication requirements under operational standards highlight the concern of utilities towards the risks of coordination failures. The requirements ask utilities to report various conditions such as outages, limit violations and planned conditions. The reliability risk is not solely technological but also has an organizational component. Failure to complete the communication requirements in a timely manner can themselves have negative effects on reliability. Examples of such Requirements records of notifications, conference calls and electronic emails. Reliability Standard development evolved in accordance with lessons learned from major disturbances. Following several major system disturbances FERC orders required various actions to determine/clarify the authority, to remove ambiguities in the synchronized real-time limit monitoring functionality and to strengthen the corrective actions. This evolution of standards illustrates the event analysis to standard development feedback process. It illustrates how standards have been changed to address lessons learned from reliability disturbances. The enforcement response to alleged non-compliance with operational standards is often influenced by the actions taken by the entity in relation to the time they occur. A number of operational standards may be related to relatively fast changing system events, where the degree of impact arising from any delay prior to corrective action is a factor in determining the overall effect and any enforcement action arising from the matter in issue. Refer Penalties - Public Notices for examples where AER consideration of short periods of non-compliance, or other matters such as procedural breaches, involves consideration of the broader systemic context and potential relative impact. Operations Standards are part of the reliability framework that provide the real-time reliability spine. They define relationships between actors such as Balancing Authorities, Transmission Operators and Reliability Coordinators, provide performance standards where appropriate and rules of conduct where necessary. Their institutional purpose is to ensure system stability under changing operating conditions.

End-of-Chapter Summary

The BAL, TOP and IRO standards establish enforceable obligations for real time and near real time operation of the Bulk Electric System, including performance requirements, authority, procedures and necessary communications and actions to protect frequency, voltage and thermal stability. These standards take into account the urgency of BES operations and enforcement in a manner commensurate with the risk identified through the Reliability Standards development process.

Chapter 4

Planning and System Performance Standards

Planning Standards deal with reliability risk affecting the long term. Unlike the Operations Standards which concern the behaviour in real time, the planning families such as TPL, FAC and MOD focus on whether the system has been dimensioned, analyzed and organized so as to be able to manage pre defined contingencies. These standards are preventive rather than curative, aiming to avoid any foreseeable reliability problem before it is revealed by the operation circumstances. Standards for Transmission Planning require that Planning Coordinators and Transmission Planners analyze the performance of the transmission system for a specified set of contingencies. The contingencies are divided into several classes depending on the level of system stress experienced (e.g., single component outages versus multiple component outages). This document was developed using this sequential approach. It requires that analyses are made using specified performance criteria, assumptions, models and remedies for determining transmission system deficiencies. Voltage and voltage drop performance tables incorporated into the TPL standards illustrate the relationship between technical specification and enforceability. voltage limits, thermal loading thresholds and stability performance criteria are specified in a manner which allows them to be measurable. Attachments within the standard are part of the Requirements and are not considered to be informational documents. Once approved, an attachment becomes part of the Requirements and is enforceable. In this category, standards for the Faciliy (FAC) reliability area are applicable to interactions among Transmission Owners, Generator Owners and Transmission Planners relating to facility ratings, interconnection studies and model adequacy. The reliability criterion for this category is to reflect the real capacity of the transmission facilities in all planning tools and operational systems. Possibly standards will also oblige Transmission Owners and Generator Owners to prepare methods to derive facility ratings, to communicate changed facility ratings, and to verify models used in interconnection studies. The institutional criterion for this category is to be with the accuracy of the inputs (data) fed to the planning and operational tools for enhancing reliability. The Modeling, Data, and Analysis (MOD) standards within the framework of smart grid standards ensure the standards for developing, validating and exchanging system models used for planning and operational grid management decisions. Out-of-date or incorrect models can lead to incorrect assumptions of grid behavior during contingency situations. MOD standards may involve standards for model verification processes and data reporting. Evidence of activities related to validating and updating models and tracking communications between entities may be required. Reliability problems often are

addressed by requiring documentation of corrective action plans. Although typically initiated when the reliability study shows that some performance criterion has been violated, there is a requirement that action be taken to correct the problem. This does not mean that there is a real-time requirement. Planning standards simply provide for a necessary step of planning corrective action which may be initiated over a period of time. Thus the requirement for corrective action recognizes that not all reliability problems can be fixed immediately. It thus introduces an element of planning flexibility into an “institution” that had heretofore required “immediate action.” Violation Risk Factors (VRFs) in the planning standards are calibrated differently than in the operational standards. While failures in planning can lead to long term risk, the short term operational impact from such failure may not always be readily apparent. The VRFs for planning standards are calibrated with this time disparity in mind. Enforcement actions to date have however highlighted that more than one failure to perform necessary studies or implement action plans has been necessary to document a significant reliability exposure. These planning standards may interact with the market and interconnection processes, but the rules still concentrate on reliability. The transmission expansion decisions, generation interconnection studies, and load forecast all enter into consideration of whether a planning standard is met, but they do not impact the commercial outcome of adequacy, reliability analysis, and mitigation plans. Past revisions to Reliability Planning Standards were primarily motivated by extreme disturbances or shifts in resource composition. The transition to an increasingly inverterbased power system with the aging of conventional generation and an increasing number of large load centers are additional motivations for potential updates to planning models and performance criteria. Rarely, public technical analyses or directives from FERC (commission) have been enough to justify changes to study assumptions or contingency ranks to keep pace with system evolution. The planning families operate as a forward looking safeguard in the Reliability Standards. The goal is to ensure that the power system can provide acceptable performance for a range of reasonably foreseeable events including disruptions, or that any deviations from acceptable performance are understood and are either addressed through documented mitigation or not a concern. The enforceability of these families serves to enforce good practices in planning studies, data, and maintenance and other recovery actions.

End-of-Chapter Summary

The TPL, FAC and MOD standards contain requirements which must be implemented in grid operations and accordingly, become regulatory. They concern forecasting of future grid performance and adequacy through assessment techniques, synchronization of the facility ratings as recommended in the FAC standard, and requirements for the reliability model to ensure an appropriate representation of the power system for performing reliability analyses. The overall institutional goal of these requirements is to achieve preventive measures to enhance reliability of the power system through adequate

contingency analysis and sufficient documentation for required corrective action during real time operation under normal and stressed conditions.

Chapter 5

Protection and Control Standards and Disturbance Containment

Standards covering Protection and Control within the PRC family provide coverage for the protection system’s ability to detect, identify, isolate and contain faults occurring on the Bulk Electric System prior to instability spreading across the system. While they do not fall within the purely operational or planning category, the Protection and Control standards are also not entirely within the other category; rather they fall within a middle area and are used to cover design, maintenance, testing and other related issues of automatic protective relays which operate in response to abnormal conditions existing in the electrical system. Protection systems should operate quickly and accurately. Non-operation when required or unwanted operation under normal conditions introduces reliability risk, as addressed in the PRC standards. Many requirements impose on Generator Owners, Transmission Owners and Distribution Providers the need to develop maintenance and testing schedules for protection systems, relay, communication systems, etc. in order to ensure that the protective systems operate as required when a fault occurs. It is common for Maintenance and Testing (M&T) intervals to be specified in the Requirements or tables. The rationale for including such intervals may be due to general experience or based on past performance of specific types of apparatus and system components. Nevertheless, it is the obligatory nature of having to test the condition of apparatus at specified time periods and making good any deficiencies that is important. Expectations for evidence can vary, but common elements include dates associated with entries in test records, maintenance logs and records of remedial work undertaken. This category of standards may cover PRC standards for Remedial Action Schemes (RAS) or Special Protection Systems (SPS). RAS/ SAPS functions detect abnormal system conditions and automatically order corrective actions to eliminate the conditions, thereby preventing cascading blackouts. Because these systems do not require operator intervention to take effect, it is crucial that their performance integrity is maintained. Design reviews, analysis of RAS performance, and coordination among interested parties may be included in

the requirements. Misoperations have long been a focus for enforcement and standardization. A misoperation is a situation where a protection system fails to operate when desired or where it operates when not desired. In recent years, several PRC grid standards address the consideration of misoperations in their analysis, root cause determination and corrective action plans. It is realized that grid protection systems need to be under constant scrutiny, not just after major events. Almost every publicly available

post event analysis of a major disturbance includes a section that describes the behavior of protection systems and typically identifies its impact on the overall stability of the system. Another area of considerable discussion has been between transmission and generation protection coordination. Bad coordination can lead to unwanted tripping out of equipment which tends to increase strain in the grid. As such, the standards often require documentation of coordination studies between and within utilities, (especially when it comes to interconnected systems). The wording is a reflection of the interconnected nature of protection relays and that no one station’s protection settings are totally independent of others. In PSA-G-2, Vol 8 some of the Violation Risk Factors (VRFs) for certain PRC Requirements have been increased due to potential cascading impact. A basic principle of protection system maintenance and design is to be able to withstand faults in other parts of the system in order to successfully protect the main system. On the other hand, some Requirements are related to administrative documentation or program development activities and therefore generally have lower VRFs as they are not directly related to the immediate stability of the system. The risk-based ranking and classification is therefore clearly visible in the Requirements of PSA-G-2, Vol 8. This part deals with the effect of the changes in the environment of protection standards and with some consequences of technological progress, particularly with respect to the performance capabilities of digital relays, wide-area monitors, and modern communication systems. The revisions of protection standards have dealt with some terminology, increased the number of items that must be recorded in protection relay records, and have more precisely defined the maintenance to be done. After each major disturbance, as a result of FERC investigations, protection performance has had to be more accurately analysed and made more readily available. These are the Protection and Control standards. They are a containment layer in the reliability architecture. The operations in real time deal with the unusual and the planning assumptions do not account for unusual contingencies, the protection works to limit the impact of an event and prevent the

propagation of disturbances. The enforceable elements of the PRC family emphasize the importance of automated fault handling in maintaining Bulk Electric System reliability.

End-of-Chapter Summary

Protection and Remedial Action for Power Systems / Standard: PRC-02 These standards set regulatory requirements for design, maintenance, testing, coordination and performance analysis of protection and remedial action systems for the purpose of disturbance containment and the prevention of cascading outages through reliable automated fault removal. The regulations enforce a risk based compliance for the systems affected by protection system failure or misoperation based on the impact to the power system.

Chapter 6

Emergency Preparedness and System Restoration Standards

The Emergency Preparedness standards, predominantly within the EOP category, deal with low probability, high-consequence events that could endanger the Bulk Electric System. The operational standards provide for normal conditions under stressed and contingency situations where the System can be brought back to normal using normal control actions. The EOP standards deal with situations where control actions are not adequate. The purpose of having institutional emergency response, coordination and restoration plans is to deal with major disruptions to the power system that result in potential threats to the health and safety of the public and the environment. The EOP standards cover a range of Requirements related to emergency operations planning, load shedding programs, event reporting and system restoration plans. These requirements acknowledge that certain types of events such as weather, fuel supply events, component failures, cyber events, or wide area instability cannot be addressed through normal corrective procedures. The draft acknowledges the need for contingency plans to be pre-defined to ensure that required actions can be implemented expeditiously, even when real time information is unavailable and/or communications are poor. Underfrequency Load Shedding and Undervoltage Load Shedding programs were the most prevalent requirements. These are programs that shed load to stop a frequency or voltage drop. All programs required establishing certain parameters, coordinating settings and periodically validating performance. The reliability objective for the evidence associated with these programs is to prevent cascading failures by stabilizing system conditions during major disturbances. The expectation of the evidence for these programs was that of program documentation, coordination records and validation tests. System restoration planning is another core responsibility for Transmission Operators, Balance Authorities and Reliability Coordinators. Blackstart resource identification, cranking path verification and neighbor region coordination are all part of this enforceable responsibility, and must be developed and validated on a scheduled basis. Restoration capabilities cannot be assumed and are required

to be demonstrated through either a practical exercise or through documentation of a computer simulation. Event reporting Reliability Event Protocol (EOP) standards afford a means of enhancing disturbance visibility. Entities are required to report events to NERC and Regional Entities under specified timing requirements to enhance visibility of situations arising in real time and to facilitate an after-the fact assessment. The timing and other thresholds for reporting events established in the EOPs were

designed to maximize situational awareness and knowledge of occurrences while complying with DOE event reporting requirements. Non-compliance with these requirements has been the basis of enforcement actions by FERC. See Emergency Operations Directive Authority for information on directive authority exercised by Reliability Coordinators in emergency operations, and for information on the importance of coordination among utilities in the event of a rapid deterioration in system conditions. These EOP standards emphasize the importance of procedures and coordination to assure adequate communication among all parties during emergency operations. This institutional design mitigates potential sources of increased uncertainty during emergencies, and reduces the risk of confusion that might arise in the absence of well-defined roles and clear procedures for emergency operations, including procedures for the escalation of authority in the event of a significant development in an emergency situation. Violation Risk Factors (VRFs) within the EOP are based on the relative impact of violation of the requirement to plant or spinning reserve levels and load shedding performance or restoration readiness. Some documentation or procedural Requirements have lower VRFs but are still mandatory to support the emergency response process. Standards for Electric Power Emergency Preparedness Revised Lessons learned from major disturbances are incorporated into the revised power emergency preparedness standards. Investigations of wide-area power outages have identified problems with the load shedding regimen, restoration order or communication procedures. The new FERC regulations and the NERC efforts to draft revised Reliability Standards to implement the new FERC Regulations reflect these findings. This process of reviewing the adequacy of existing power emergency preparedness standards after the occurrence of major disturbances is an ongoing process that affects the revision of these standards. The Emergency Preparedness standards serve as the ultimate backstop within the reliability standards framework. In the event that planned assumptions and operational controls are violated, the EP standards provide structured procedures for stabilization and restoration. The enforceable nature of these standards serves to underscore the fact that having the ability to restore reliability and participate in emergency procedures are reliability standards, not options.

End-of-Chapter Summary

The EOP standards introduce regulatory requirements for emergency response, load shedding plans, reporting of disturbances and restoration planning. The institutional goal of these standards is to achieve synchronized synchronization and restoration following severe disturbances. They thus integrate elements of resilience, stemming from the planning, testing and reporting requirements in the reliability framework.

Chapter 7

Critical Infrastructure Protection Standards and Cyber Reliability

Standards and technical documents within the Critical Infrastructure Protection (CIP) series extend the reliability framework to cyber and physical security in the context of the Bulk Electric System (BES). The CIP standards and policies do not regulate the typical company information technology (IT) environment. Rather, the CIP focus is exclusively on BES Cyber Systems and associated physical or cyber components, where a breach could potentially have consequences impacting reliable generation and transmission operations. The goal is to ensure grid reliability can be maintained despite intentional actions such as cyber attacks or physical sabotage. Each CIP standard addresses one or more of the following key areas of cybersecurity for BES: Asset Identification; Security Management Controls; Electronic and Physical Security Perimeters; System Security Management; Configuration Management; Incident Response; and Recovery Planning. The standards are written in an architecture where classification preceeds obligation. CIP-002 sets forth the method by which a utility determines whether particular portions of its BES Cyber Systems are High, Medium or Low Impact. Each of the other CIP standards then impose differing controls based on the classification made in accordance with CIP-002. The classification framework builds on a risk stratified model where the impact determinations are based on the potential reliability consequences from loss of control or loss of use of assets and systems. For example, Medium Impact BES Cyber Systems are primarily related to Scada systems associated with control centers, generation control systems or transmission facilities that if compromised may impact reliable delivery of electricity. The controls required for these systems are typically less in terms of scope and intensity when compared to the controls required for High Impact assets and systems reflecting a different risk calculus. Although controls are specified in many regulatory requirements, the CIP Requirements emphasize rules and policies and controls to varying extents. As we have come to expect, Measures require a mix of documentation and technical controls. These new Measures provide more examples of the type of technical evidence required to document that certain controls are implemented in relevant systems. The new Measure requirements are evolving in the same way that the field of cybersecurity is evolving in other ways. Electronic Security Perimeters and Physical Security Perimeters are key elements of the CIP definition of critical infrastructure. These defined boundaries serve to identify the areas in which controls must be applied. This Clause combines technical detail with enforceable language. For example, Requirements within this Clause related to access control, continuous monitoring, and authentication may be applicable to systems located within an Electronic Security Perimeter and expectations for

providing evidence may extend beyond simply being a matter of including relevant statements in policies and procedures, but may include providing documentation of actual system performance. A new set of Incident response and recovery planning Requirements recognizes that it is not possible to prevent all cyber threats with controls. Utilities must have procedures in place to identify, manage, report and recover from cybersecurity incidents impacting BES Cyber Systems, which overlays other reliability reporting requirements. The requirements focus on preparing and holding utilities accountable for managing cyber threats, as opposed to guaranteeing specific outcomes. NERC (National Electro Magnetic Research Center) audit reviews for compliance to Regional Entity (RE) CIP performed extensive examinations on a wide array of information relative to critical infrastructure physical documentation, technical parameters and implementation steps taken for measures to protect high voltage relays, transient protectors and the supply chain activities. Enforcing Bodies filing of public enforcement actions include details relative to how one could adequately document their compliance to these regulatory actions and FERC has directed and instructed NERC on several occasions to correct what they deem gaps and or ambiguous language in a standard regarding protection against threats in the supply chain and transients. So these Rules continue to evolve and the regulators at FERC have an evolving understanding of threats to the national electric power system and the key technologies protected under these standards. Violation Risk Factors (VRFs) for the CIP family of policies are based on the relative impact of critical infrastructure reliability on noncompliance with individual requirements. Requirements associated with access control, system security management, and incident response may carry higher VRFs because a cyber attack that is not mitigated in real time can have serious consequences. Requirements for which documentation is primarily responsible may carry lower VRFs, but will still be enforceable because they are part of the overall governance structure. This version of the CIP standards

incorporates cybersecurity risk into the reliability regime of FERC Standard 215. They do not establish operational standards, but instead ensure that the operational reliability standards can be properly implemented by securing the control systems upon which operational reliability relies. The institutional logic at play here is ensuring continuity of control and data integrity in the face of accidental or intentional breaches of the systems’ defenses. Cyber reliability has become a material part of operational reliability. The CIP Requirements of the CIP family are enforceable, risk-based, based on the classification of the asset and the definition of the perimeter. As electronic systems become more prevalent in the transmission, generation and control environments, they are likely to be treated even more so in the future in the standards as a material part of operational reliability.

End-of-Chapter Summary

Standards for Cybersecurity & Physical Controls (CIP) Rules bring the Reliability Standards, as they are known, from the field of traditional power system engineering into the field of cyber and physical

security of BES Cyber Systems. These Standards for CIP, which classify assets, define perimeters and impose controls and documentation requirements through a risk-based approach, are designed to ensure continuity of operation and reliable generation and transmission system operations. These CIP Rules are a recognition of the ever-growing interrelation between cybersecurity and BES reliability.

Chapter 8

Measures, Evidence, and the Logic of Demonstrated Compliance

For a Reliability Standard to be enforceable, both the clarity of the Requirements in the Standard and the measure of compliance must be clear. Measures are included with each Requirement to describe what type of documentation (as defined in section 3 of the Rules of Procedure) will be used to demonstrate compliance with that requirement. A Measure lists the institution’s expectation of proof of compliance with a particular Requirement. Other than serving as advisory commentary, measures can be Mandatory or Optional. Once a Reliability Standard measure is adopted as part of the standard, mandatory measures carry the force of law and must be followed. Measures used in Reliability Standards describe the actions that utility companies must take to meet the requirements of the standard by identifying the type of documentation, data or other record that demonstrates compliance with a Requirement. The language that describes the required evidence can differ, but most measures follow a consistent structural pattern that describes the requirement, and then describes the characteristics of the required measure (i.e., the required evidence). The required evidence is described by identifying the word(s) that demonstrate compliance with the requirement, and then listing the types of documentation, data or other records that establish that the required word(s) have been met. In earlier versions of a number of standards, the Measures in these standards referenced the presence of documented policies and procedures. As the monitoring programme developed, new versions incorporated measures that reflected the implementation of these policies. Experience showed that having documented policies and procedures did not protect reliability in the event of an audit or an enforcement action. The Measures have evolved to require more than just documentation, such as dated logbooks, time-stamped records, study reports, configuration baselines, maintenance records, etc. There is an asymmetry between Requirements and Measures. A Measure does not expand or change a Requirement, it defines what constitutes acceptable evidence that the requirement has been met. However, Measures can affect the auditors stance during an audit.

Let’s say a Requirement is “develop and implement a process”. A Measure to the requirement might be “retain dated documentation proving that the process has been carried out”. This implies that, in the absence of such documentation, that the process has not been carried out and, thus, a policy is not adequate to avoid an audit finding. NERC and Regional Entities have released Reliability Standard Audit Worksheets (RSAWs) that shed some light on the expectations of the evidence required for audits. Note

that the RSWs do not change the wording of the Reliability Standard, but they give some insight into how audit staff will apply the Requirements and Measures when auditing for compliance. In essence, an RSW is a checklist of types of evidence the audit staff may request for an audit activity, focusing on such things as documentation, interviews, etc. The RSWs have evolved to be more structured and uniform over time, to allow for more efficient and consistent auditing among audit teams within Regions. Violation Severity Levels (VSLs) tie in with the evidence structure and criteria. VSLs could be determined by whether required actions were fully taken, partially taken or not taken at all. In a performance-based standard VSLs could relate to a threshold of performance that needs to be met. In a documentation based standard, VSLs could relate to the completeness of the documentation and/or the speed with which it was completed. The VSLs in this instance relates the sufficiency of the particular item of evidence to the degree of severity with which any resulting breach of the standard is enforced. The underlying logic of proof in the standard is a balance between the institutions ensuring the compliance of the systems and the necessity to manage the complexity inherent to these systems. On the one hand, the standard must not be too simple in order to prevent mere formal compliance, while on the other hand, it must not be too prescriptive in order to manage the variability of systems and situations. If it were too prescriptive, it would quickly become outdated in the face of technological progress, and if it were too vague, it would be too open to interpretation by the auditors. A balance has to be found. This element covers the information found in public enforcement filings for Measures and VSLs. Typically the enforcement action will be due to the lack of retention of the necessary documentation or lack of documentation of certain analyses that have to be done or tests that have to be performed, failure to perform these tests in a timely manner or the lack of effective implementation of the VSL or Measure. However, the impact of enforcement proceedings on the reliability of the item in question as well as the presence of any mitigating circumstances may also be considered when imposing any penalty. The evidence and documentation and the basis for any enforcement action can vary depending on the risk based approach used for that particular item or activity. As part of the compliance monitoring system, self-reporting and self-certification are included. Based on internal audit and controls, possible non compliance could be self-declared by entities. The record of how the non-compliance was discovered, the steps taken to correct it and the measures put in place to prevent similar noncompliance from occurring in the future will be part of the monitoring body’s record. The institutional features of this system are intended to achieve early detection of possible shortcomings and to promote responsibility. Reliability Standards’ measures and evidence expectations are not merely administrative details. They are building blocks of the Reliability Standards structure. They transform generic obligations into tangible instruments. The development of these standards reflects the increasing maturity of the reliability regulatory framework, as well as the lessons learned through the implementation of enforcement practices.

End-of-Chapter Summary

Measures and evidentiary procedures comprise the rules that implement each Reliability Standard Requirement. The expectation for documentation and the integration with Violation Severity Levels (VSLs) incorporates a transparent risk based enforcement mechanism that focuses on the importance of implementation and enforcement rather than the existence of policy.

Chapter 9

Regional Entity Oversight and the Administration of Compliance

Reliability Standards are implemented under a delegated compliance monitoring regime. NERC has been designated as the Electric Reliability Organization (ERO), but the Regional Entities carry out the on-the ground compliance monitoring under the Commission-approved Delegation Agreements. This delegation reflects a number of factors that are related to geography, to the operation of the Bulk Power System, and to history in North America. It introduces an additional layer of institutional complexity in the space between the development of the Reliability Standard and its effect in the operating reliability system. NERC’s Regional Entities perform compliance audits, spot checks, self-certifications and investigations related to alleged Reliability Standard violations. The Entities review mitigation plans and the sufficiency of proposed corrective actions and make enforcement recommendations. Regional Entities operate under NERC Board and Commission oversight and within Commission-approved Terms of Reference. They are also closer to the operational reality of Registered Entities, and are thus in a position to apply considerable expertise and insight when determining how to implement individual Reliability Standard requirements in a given operational setting. The Compliance Monitoring and Enforcement Program sets out standardized procedures for identifying and handling noncompliance occurrences. The documents that are made public by the Regional Entities describe the timelines, procedures and coordinating activities, in relation to the RRE Program. The CM&E Program provides a framework that balances procedure with individual judgment. The investigation of alleged noncompliance may require a detailed technical examination of existing system information; protection device settings; operating records; and other information, including cybersecurity information. The application of a particular Requirement may involve consideration of specific system conditions and circumstances. Reliability management by both operating personnel and system planners is an ongoing dynamic process that operates under different rules than the static reliability criteria that are enforced by Regional Entities’ post-occurrence compliance investigations and analyses. The purpose of Regional Entities’ compliance investigations and analyses is to verify that established procedures have been followed, that required analyses or studies have been performed and that established limits and standards have been complied with. The Reliability standards were designed to reduce the discretion allowed for operational decisions. However, due to the complexity of some design or operational aspects, some degree of judgment may still be required. Reliability Standard Audit Worksheets (RS AWs) are interpretive tools used to help guide the auditing process. The RS AWs identify the types of evidence that may need to be gathered for each Audit

Question, the nature of the information that might be sought in an interview, and what documentation might be required to demonstrate compliance with each Requirement. While RS AWs are meant to help assure uniformity of approach among audit teams and within NERC Regions, they are not part of the text of a Reliability Standard. Any ambiguity is resolved by referring to the approved Reliability Standard and all relevant Commission orders. Ultimately, the outcome of enforcement actions may be reviewed by NERC and subject to Commission approval as necessary. In addition to notifications of Penalties, the Commission makes publicly available all settlement filings related to enforcement actions to ensure that compliance with the FERC Reliability Standards is transparent and that all relevant information regarding violations (including the associated reliability risk, the standard at issue, and the corrective actions implemented) is disclosed and available to support deterrence and enforcement and to reflect Commission interpretations. Regional Entities are involved in disturbance analysis and event reviews. In the event of significant reliability events, they may work with NERC in the development of the disturbance report to identify the cause of the event and the reliability lessons that may eventually become incorporated into NERC standards. This type of feedback loop is a recurring pattern in this institution. Variation among Regional Entities is a topic that surfaces periodically. Considerations such as geography, system configuration, and the length of time a Regional Entity has been in place all can play a role in determining focus areas for audits. The Commission and NERC both emphasize the need for consistent enforcement of Reliability Standards through the application of the Enforcement Program Rules by FERC and enforcement by the Regional Entities. Program reviews and oversight audits help to ensure that audits in each region are carried out in a consistent manner while taking into account the decentralized structure of the Regional Entities. The delegated oversight model provides accountability at the point closest to the operating activities of the systems it covers. Regional Entities will understand

the characteristics of the local grid and will do so in a context of continental wide reliability. The delegation of oversight responsibilities to the Regional Entities completes the institutional structure of Reliability Standards as it links mandatory Requirements with the monitoring of compliance.

End-of-Chapter Summary

Regional Entities perform compliance monitoring and enforcement functions with respect to the ERCOT Bulk Electric System under delegation from the Reliability Organization pursuant to section 215 of the FPA. The Entities perform audits, investigations, and disturbance analyses to carry compliance monitoring and enforcement activities associated with Reliability Standard Requirements. This function provides a link between operational activities in the BES and the general enforcement process, ensuring that applicable Reliability Standard Requirements are enforced to maintain accountability and consistency in the BES.

Chapter 10

Evolution of the Reliability Standards and Institutional Adaptation

Since the implementation of Section 215, the Reliability Standards have not stood still. New versions have been introduced in response to changing technologies, learning from disturbances, Commission decisions and developments in the compliance monitoring process. The underlying statute, FERC’s regulations and procedures have not changed but individual reliability standards have been the subject of a series of evolutionary modifications. The early Reliability Standards were more focused on procedural issues and on the documentation of policies and processes. As enforcement of the Reliability Standards began to provide a foundation for understanding how to effectively enforce reliability standards, both NERC and the Commission determined that various provisions of the Reliability Standards needed revision in order to reflect lessons learned from enforcement experience. As understanding of enforcement practices and needs for reliability standards evolved, Reliability Standard revisions began to incorporate more documentation related to how implementations were made, performance criteria that could be verified and conditions under which Reliability Standards need to be in effect and were enforced. The standards’ drafting conventions were also changed to reduce scope for varying interpretations of the standards and to make the language of the Requirements more closely aligned with the observed physical and operational characteristics of the Bulk Power System. Major disturbance events have triggered standards changes. Widespread blackouts and near-miss events have uncovered problems with protection relay coordination, real time system knowledge, vegetation management, load shedding, and restoration planning. After investigating the causes and affected systems, FERC has requested that NERC make changes to current Reliability Standards or develop new ones. These changes illustrate how practical experience of major events can lead to revisions in the reliability regulatory framework. The transition to modern technology has significantly affected the process of evolving standards. The increased penetration of inverter-based resources and sophisticated protection relay designs along with the proliferation of distributed resources and digital automation systems have all contributed to changing characteristics of a grid and require appropriate considerations within standardization activities. New modeling techniques, data exchange mechanisms, and associated cyber security requirements are examples of how standards have to be refined to address the new operational context. As threats and vulnerabilities to digital components change, so too must the control and protection standards evolve and the practices within associated supply chains. Examples of such changes can be seen with the revisions to the CIP standardization group’s documents. The process of

standard development has matured. The working procedures of the Stakeholder Drafting Teams have changed. The procedures for Standard Authorization Requests, the timeframes for the drafting process and the treatment of comments have all changed. This is set against a backdrop of increased Commission involvement in the development process. New rules for TNA purposes require more detailed technical justification and greater clarity. This will potentially prejudice the chances of passing the Commission’s review process. This issue of balance between flexibility and prescription of Requirements is a persistent theme in IEC work. More prescriptive Requirements may appear less relevant in fast moving technology. Failure to define Requirements with sufficient clarity may also result in inconsistent enforcement. Such balances have to be reviewed as Standards are revised, for example in achieving more effective and relevant Requirements by replacing requirements for method of work with requirements for performance where the former results in less reliable enforcement of the Requirement owing to the more precise signals which can be derived from measurement of performance. Risk-based compliance oversight is also changing. Our Compliance Monitoring and Enforcement Program now incorporates risk assessment to help guide the scope of audits and priority of countermeasures. Similarly, FERC and state public utility commission enforcement actions are beginning to make reference to risk assessments and associated mitigating factors when determining the level of enforcement action to be taken in response to non-compliance with regulatory Requirements. Rather than applying the same level of scrutiny to all Requirements, FERC and state commissions will focus enforcement activity on those aspects that have the potential for the greatest impact on reliability. Another important factor in regional coordination across the Interconnections is standards development. Some reliability issues appear differently in the three Interconnections because of system design and operating practices. Although continent-wide Reliability Standards have been developed, they are enforced within the context of different Interconnection systems and operating practices. This issue has been examined periodically and discussed at technical conferences. Although there are ongoing changes, the underlying structure of the Reliability Standards has not changed much. The Requirements, Measures, Violation Risk Factors, and Violation Severity Levels are still the enforceable parts of the standard. The delegation of ERO responsibility to the Reliability Organizations has not changed, nor has the underpinning of authority to regulate from Section 215 of the FPA. The evolution of standards represents a process of institutional adjustment rather than structural change. The reliability regime has incorporated certain aspects of disturbance analysis, technology change, and enforcement experiences, while still retaining its basic structure. The ability of the reliability regime to adapt and survive while continuing to be relevant to contemporary electric system developments is an important factor.

End-of-Chapter Summary

The Reliability Standards, after being adopted, amended, modified or reviewed by the Commission to address disturbances occurring on the transmission grid, changes in technology, or the Commission’s

concerns, are designed to achieve their statutory and structural goals while providing appropriate modifications on matters of implementation procedures, performance criteria, and risk-based compliance procedures. In this way, the Commission’s Order illustrates the adaptive nature of the institutional arrangements that comprise the Section 215 reliability regime.

Glossary

Glossary

The terms listed below are taken from the NERC Glossary of Terms and are reproduced here in their original form. Only terms referenced in this publication are included.

Balancing Authority (BA) - The body that coordinates all the resource plans of the generating units of its member utilities prior to real time, and ensures that generation, load interchange within the BAA are in balance. The BAs also provide major frequency support to the Interconnection in real time.

Bulk Electric System (BES) - As defined by the NERC Reliability Standards.

Electric Reliability Organization (ERO) - An Electric Reliability Organization (ERO) is a body certified by the Federal Energy Regulatory Commission (FERC) under Section 215 of the Federal Power Act.

Interconnection Reliability Operating Limit (IROL) A System Operating Limit that, if violated, could lead to instability, uncontrolled separation, or Cascading within an Interconnection.

Planning Coordinator (PC) – Entity that coordinates the planning of new transmission facilities and associated services, resource plans and protection systems.

Reliability Coordinator (RC) – The entity that has been determined by the generation and transmission providers to be the highest level of authority to ensure reliable generation and transmission to meet electricity demand, has a Wide Area view of the Bulk Electric System, has the Operating Tools, processes and procedures, including the authority to prevent or mitigate emergency operating situations in both next-day analysis and real-time operations.

Remedial Action Scheme (RAS) Conditions that could have the potential to affect system reliability and remedial actions that would be required to rectify these situations if they were to occur. An RAS is a scheme to detect the occurrence of predetermined system conditions with an automatic response to restore power reliability to the affected area.

Special Protection System (SPS) A protection system that monitors the operation of the power system and, in the event of unusual system conditions, takes a predefined action in addition to or instead of the normal removal of faulted components to maintain reliable system operation.

System Operating Limit (SOL) - The value (such as MW, MVar, Amperes, Frequency, or Volts) that satisfies the most limiting of the prescribed operating criteria for a specified system configuration to ensure operation within acceptable reliability criteria.

1. Transmission Operator (TOP) - The entity responsible for the reliability of its local transmission system, and that operates or directs the operations of the transmission facilities.

Transmission Planner (TP) - The entity that develops a long-term (usually one year or more) plan to ensure reliability of transmission systems within the portion of the Planning Coordinator Area comprised of the Transmission Planner’s transmission facilities.

The definitions above are taken verbatim from the NERC Glossary of Terms as it has been made available to the public. Readers should refer to the current official version of the NERC Glossary for the most up to-date language.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

Services Provided

Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.

Energy Compliance services include, but are not limited to:

  • NERC reliability and compliance advisory support
  • Reliability governance and program assessments
  • Registration and applicability analysis
  • Operational and engineering reliability alignment
  • Compliance program design and improvement
  • Audit and enforcement support (non-advocacy)
  • Mitigation planning and Self-Report development
  • Training and executive briefings on reliability frameworks
  • Regulator-perspective program reviews

Each engagement is scoped to the entity’s role, function, and bulk system impact.

ENERGY COMPLIANCE PROFESSIONAL REFERENCE

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US Scan to visit

E N E RGY COMPL IAN CE , IN C. · EC-WP-103 · © 2026 · AL L RIGHTS RES E RV E D

Foundations