NERC CIP Compliance
Program assessments and control support across governance, asset categorization, access, configuration change, incident response, recovery, and evidence.
NERC CIP + O&P compliance advisory
Practical compliance support for electric-sector organizations, data center owners, and project teams—from emerging IBR obligations to early CLO and CLOP readiness.
Next Tier helps registered entities and emerging computational-load stakeholders translate requirements into controls, ownership, and evidence that stand up to review.
Program assessments and control support across governance, asset categorization, access, configuration change, incident response, recovery, and evidence.
Applicability, readiness, and evidence support for O&P obligations, with dedicated focus on the new IBR performance standards.
Early-stage scoping and program planning for data center owners, operators, and project managers preparing for the proposed CLO and CLOP framework.
Structured reviews that identify control and evidence gaps, clarify priorities, and turn findings into an actionable remediation plan.
Requirement-to-evidence mapping, sampling support, document review, and audit-room preparation.
Practical policies, procedures, controls, calendars, and ownership models built for repeatable execution.
Root-cause review, corrective-action planning, implementation tracking, and durable evidence of completion.
Next Tier connects policy language to the systems, teams, approvals, and records that make a CIP program operational.
Discuss a CIP engagementReview registered functions, BES Cyber System categorization, ownership, delegation, and the links between policies, procedures, and technical controls.
Test whether control activities are performed consistently, supported by usable records, and aligned across compliance, operations, IT, and security teams.
Examine plan quality, role clarity, exercises, recovery evidence, and lessons-learned workflows before they are tested by an incident or audit.
Build evidence indexes, test narratives, rehearse interviews, and trace sampled records from requirement through implementation.
Support spans applicability, program design, control testing, and event-ready evidence for Operations & Planning standards.
See the IBR focusMap obligations to Generator Owner, Generator Operator, Transmission Owner, and other applicable responsibilities, with documented scoping decisions.
Translate Reliability Standard language into procedures, responsible roles, recurring tasks, source systems, and retained evidence.
Coordinate engineering, operations, compliance, OEM, and plant-level responsibilities across PRC-028, PRC-029, and PRC-030 readiness.
Validate evidence quality, test execution against documented controls, and prepare clear narratives for reviewers.
Next Tier helps data center owners, computational load operators, and project managers organize early readiness work while NERC’s CLO and CLOP framework is still developing.
Discuss CLO readinessDocument site configuration, connected load, voltage, ownership, operating responsibilities, and interconnection relationships against the latest proposed CLO and CLOP definitions.
Give project and program managers a practical workstream for studies, model data, communications, protection coordination, disturbance monitoring, owners, and decision gates.
Clarify the information, studies, technical contacts, and operating communications that may be needed across the data center, serving utility, Transmission Planner, and operating entities.
Create a living inventory of assumptions, open decisions, source records, and remediation actions so the program can adapt as draft requirements change.
The three standards create an interconnected readiness problem: capture useful disturbance data, establish ride-through performance, and turn unexpected behavior into analysis and mitigation.
Build the data foundation needed to analyze IBR behavior during Bulk Electric System disturbances.
Align facility design, settings, studies, and operating evidence with plant-level ride-through performance expectations.
Create a repeatable path from event identification through technical analysis, corrective action, and completion evidence.
Applicability, approved versions, and effective dates vary by entity, facility, and jurisdiction. Engagements begin by confirming the controlling requirements and current implementation schedule.
Work is shaped around the entity, facilities, functions, and teams that carry the obligation—not a generic template.
Applicability, registration, program buildout, evidence, and audit readiness for BES and qualifying non-BES resources.
Coordinate engineering, OEM, modeling, plant controls, and compliance work across the project lifecycle.
Practical CIP and O&P controls that fit lean teams and real control-room operations.
Clear requirement-to-control mapping, model and evidence workflows, and cross-functional ownership.
Bring emerging compliance considerations into site development, interconnection, design, commissioning, and operating-readiness plans.
Early applicability, role mapping, utility coordination, and readiness work for NERC’s proposed CLO and CLOP framework.
Focused advisory support for assessments, remediation, documentation, training, and audit preparation.
Next Tier monitors effective dates, phase-ins, and developing standards across IBRs, dynamic models, and computational loads—then translates them into decisions, owners, and evidence.
The dates below separate enforceable obligations from proposed work so teams can prioritize without treating a draft as a requirement.
Non-BES IBRs meeting the aggregate 20 MVA and common-point 60 kV test entered the new registration population.
BES IBR ride-through design obligations and unexpected-event analysis requirements begin. Qualifying non-BES IBR dates follow on 1 January 2027.
FERC directed NERC to file standards, definitions, and registry criteria. This is a filing milestone—not an approval or compliance date.
Design compliance under PRC-029-1 R1–R3 and PRC-030-1 applicability begin for qualifying non-BES IBRs.
Model-data process requirements mature under MOD-026-2; PRC-028-1 R8 reaches qualifying non-BES IBRs.
The implementation window for documented hardware-limitations submissions closes for applicable IBRs.
For covered legacy BES IBR fleets, at least half of applicable MVA must meet R1–R7 under the approved phase-in.
Core dynamic-model verification and validation requirements reach their implementation-plan milestone.
R1–R7 reach the 100% milestone for covered legacy BES fleets and qualifying non-BES IBRs.
Project 2026-02 passed its first industry ballots in September 2026. These Draft 1 standards are not yet approved or enforceable.
Proposes facility requirements, reliability-impact studies, modeling data, verification, and planning-case reporting.
Proposes planning and real-time information exchange plus defined communications among load owners/operators and reliability entities.
Proposes protection coordination and disturbance-monitoring requirements for qualifying computational-load sites.
Use these as scoping prompts. Final applicability depends on facility configuration, registration, definitions, and the controlling implementation plan.
Do you own or operate a generating BES facility? If yes, the current framework points to Category 1 GO/GOP.
Aggregate nameplate capacity of at least 20 MVA, delivered through a system designed primarily for that capacity to a common point at 60 kV or above.
Both non-BES tests point to Category 2. If neither path fits, Order 901 GO/GOP registration is not triggered by this test alone.
Category 2 registration became effective 15 May 2026. Registration does not itself complete the associated PRC and MOD obligations.
Owner/operator of generating BES facilities. The BES definition, including inclusions and exclusions, controls.
Owner/operator of qualifying non-BES IBRs meeting both the 20 MVA aggregate and 60 kV common-connection tests.
Both categories can face PRC-028/029/030 and MOD-026-2, but non-BES implementation dates are staggered.
MOD-026-2 applies to Generator Owners, Transmission Owners, Transmission Planners, and Planning Coordinators.
Test the standard’s listed IBR, synchronous generation, dynamic reactive resource, HVDC, and other applicability categories.
Do not assume every IBR owes an EMT model. R3 is triggered where the TP or PC identifies the need and specifies the model requirements.
Implementation-plan milestones: R1/R7 by 1 April 2027; R2–R6 by 1 April 2029. Legacy-fleet phase-in details require facility-specific review.
A single location primarily containing IT infrastructure for software, AI, cryptocurrency mining, or other computational activity.
Current Draft 1 uses total connected load of at least 50 MW and electrical equipment connected at 100 kV or above.
A qualifying owner may be a CLO; an operator may be a CLOP. Definitions and registry criteria remain proposed and can change.
The September 2026 initial ballots passed. The 31 December 2026 date is NERC’s filing deadline to FERC—not a compliance date.
Three focused guides turn the regulatory language into scoping questions, workstreams, evidence needs, and near-term actions for owners and project teams.
A field guide to applicability, engineering coordination, settings, documentation, and the path to an auditable ride-through program.
A practical preparation plan for data center owners, operators, and PMs while the proposed CLO and CLOP framework develops.
A field guide to monitoring capability, data quality, event retrieval, request response, and defensible evidence.
A practical path from applicability and facility design through settings, limitations, change control, and evidence.
PRC-029-1 readiness depends on facility category, commercial-operation timing, and jurisdiction. Confirm applicability and effective dates before turning this guide into a project schedule.
PRC-029-1 is intended to keep applicable inverter-based resources connected through defined frequency and voltage excursions, subject to the standard’s permitted exceptions and documented equipment limitations. The compliance challenge is not a single relay setting. It is the chain linking facility design, protection, controls, OEM capabilities, studies, operating practice, and retained evidence.
That chain often crosses owners: plant engineering may understand the design basis, an OEM may control inverter logic, a protection group may own relay settings, operations may manage outages and changes, and compliance may hold the evidence. A defensible program makes those interfaces explicit.
Document registration category, facilities and units in scope, commercial-operation dates, equipment vintages, common points of connection, and the implementation dates that apply to each population.
Map the ride-through expectations to inverter controls, plant controller logic, collector-system protection, main transformers, auxiliary systems, and other equipment that can initiate disconnection.
Compare protection and control settings across devices and owners. Record the approved basis, review authority, implementation record, and how field values are verified.
Identify claimed hardware limitations early. Assemble engineering support, OEM documentation, affected equipment, operating implications, and the submission path required by the standard.
Bring firmware, model, controller, relay, transformer, and protection changes into a single impact-review process so ride-through capability is reassessed before implementation.
Connect disturbance review to corrective action. Unexpected trips, momentary cessation, or control interactions should feed settings review, model validation, and fleet-wide lessons learned.
Confirm applicability, freeze the in-scope facility list, name accountable owners, collect current drawings and settings, and log missing source records.
Perform the coordinated engineering review, test the equipment-limitations position, map evidence, and identify settings or process gaps by risk.
Approve remediation plans, complete high-priority changes, exercise the change-control and event-review workflows, and assemble a reviewer-ready evidence index.
Next Tier can confirm applicability, lead the cross-functional readiness assessment, build the requirement-to-evidence map, facilitate settings and equipment-limitations reviews, and turn the results into an owned remediation plan.
Discuss PRC-029-1 readinessA stage-gated preparation plan for owners, operators, and project managers facing the proposed computational-load standards.
Project 2026-02 Draft 1 passed initial industry ballots in September 2026, but the standards, definitions, thresholds, and registry criteria are not yet approved or enforceable. Prepare adaptable foundations—do not label a draft obligation as final.
Site topology, utility interconnection, protection schemes, load-control behavior, communications, models, monitoring equipment, and project records are expensive to retrofit after commissioning. Early readiness work lets a data center preserve the information and decision trail likely to matter without treating the draft as settled law.
Current Draft 1 uses a 50 MW total-connected-load threshold and electrical equipment connected at 100 kV or above in its proposed computational-load framework. Those details can change. The right first step is a documented threshold watch and facility dossier, not an unsupported registration conclusion.
Maintain current one-lines, service voltage, total connected load, phased energization dates, utility feeds, on-site generation, storage, transfer schemes, and backup-power arrangements.
Document who owns the load, who directs real-time operation, who controls switching and load-management systems, and which responsibilities sit with vendors or managed-service providers.
Keep study requests, assumptions, models, utility comments, protection requirements, operating limits, and accepted changes tied to the as-built facility.
Characterize normal ramps, block changes, transfer events, power-supply behavior, protection actions, demand response, and controls that could produce rapid or simultaneous load changes.
Identify available disturbance, sequence-of-events, frequency, voltage, and power data; document time synchronization, retention, access, export formats, and responsible system owners.
Map planning and real-time contacts across the site, serving utility, Transmission Planner, Balancing Authority, Transmission Operator, and Reliability Coordinator as applicable.
Capture prospective service voltage, connected-load buildout, utility configuration, ownership model, and the current draft-threshold assessment.
Assign model, study, protection, communications, and data-delivery owners; establish a controlled assumptions and responses log.
Confirm monitoring points, time synchronization, record retention, controls visibility, secure data access, and the evidence each discipline must hand over.
Verify as-built records, test data capture and retrieval, validate contact paths, and close gaps between study assumptions and installed equipment.
Maintain the facility dossier, govern changes, rehearse disturbance-data response, monitor the standards project, and update the applicability position at defined triggers.
Next Tier can build the initial CLO/CLOP applicability file, facilitate owner-operator role mapping, add compliance gates to the project schedule, review the data and communications architecture, and maintain a change log as the draft standards evolve.
Discuss CLO readinessA field guide to monitoring coverage, data quality, event retrieval, reporting workflows, and evidence that can withstand review.
The usable compliance product is a complete chain: scoped facilities, capable devices, known data paths, synchronized records, trained responders, controlled retention, and evidence that the process works.
PRC-028-1 establishes disturbance-monitoring and reporting obligations for applicable IBR facilities. A readiness review should ask whether the organization can identify an event, retrieve the required sequence-of-events, fault-recording, and dynamic-disturbance information, validate its quality, preserve it, and deliver it through a controlled workflow.
Every link matters. A technically capable device can still fail the program if channels are misnamed, clocks are not aligned, files are inaccessible, settings drift, ownership is unclear, or a request waits in the wrong queue.
Map each in-scope facility to required monitoring functions, installed devices, monitored quantities, trigger sources, communication paths, and the implementation milestone that applies.
Control device settings, enabled channels, labels, scaling, trigger logic, record length, sampling configuration, firmware, and the approved basis for each value.
Document time sources, distribution, health monitoring, tolerances, alarms, outage response, and how timestamp quality is checked before records are released.
Define automated and manual paths from field devices to historians or repositories, including access, file formats, naming, secure transfer, and fallback steps.
Verify completeness, channel mapping, units, scaling, trigger performance, timestamp alignment, and readability through periodic tests and selected event reviews.
Set preservation rules, request intake, due-date tracking, technical review, approval, transmittal, and proof of delivery with named owners and backups.
Log the requester, event window, facilities, requested data, format, due date, and accountable response lead.
Collect source files through the controlled path, preserve originals, document retrieval gaps, and escalate missing records immediately.
Check timestamps, channels, units, scaling, trigger alignment, completeness, and whether the record actually covers the requested interval.
Apply technical and compliance review, transmit through the approved channel, and retain the package, approval, delivery evidence, and any explanation.
Track defects and corrective actions. Use each request or event to improve monitoring coverage, configuration control, training, and fleet consistency.
Next Tier can scope the fleet, map monitoring coverage, assess device and data-path controls, facilitate a request-response drill, and build the evidence index and remediation plan needed for sustained PRC-028-1 readiness.
Discuss PRC-028-1 readinessA disciplined engagement keeps the focus on decisions, evidence, and sustainable execution—not paperwork for its own sake.
Define the objective, relevant standards, stakeholders, and the evidence needed to evaluate current state.
Review controls and records, distinguish documentation issues from execution issues, and prioritize by risk.
Translate findings into clear owners, practical next actions, and a defensible record of improvement.
The best program is not simply documented. It is understood by the people who own it, supported by the right evidence, and repeatable under pressure.
What utility and energy-sector leaders say about working with our team. Client identities are withheld to respect confidentiality.
“Your team was instrumental in helping us navigate becoming a NERC-certified entity. From there, our relationship expanded into strengthening our compliance program, leadership training, and individual coaching. You've become an integral part of the process, and we highly recommend your services. You won't be disappointed.”
President and CEO · Electric Cooperative
“Your experience with electric distribution, transmission, and generation assets—and how those assets achieve maximum compliance with federal, regional, and state entities—is unrivaled. Helping us through our Transmission Operator (TOP) Certification process with hundreds of information requests, a systematic approach to training, and audit-proven document development made all the difference.”
Director of Grid Control & Compliance · Municipal Utility
“Your deep background and leadership in NERC compliance enable you to create structured programs that bring real, sustainable value to clients. Your ability to simplify regulatory complexity and equip energy sector organizations with critical knowledge helps teams navigate complex landscapes with complete confidence.”
CEO · Energy Technology Company
“Preparing for a NERC audit always feels high-stakes, but having your guidance transformed our approach. You didn't just hand us a template; you worked side-by-side with our operations and engineering teams to ensure our evidence packages were bulletproof. We cleared our audit with zero findings—an outcome we couldn't have achieved without your expertise.”
Director of Compliance · Generation Facility
“Your engineering background combined with a deep, practical understanding of NERC Operations and Planning standards is a rare find. You spoke our language, understood the realities of control room operations, and helped us build a sustainable compliance framework that doesn't get in the way of running a reliable grid.”
Manager of System Operations · Municipal Utility
Next Tier Compliance is a focused NERC compliance consultancy serving electric-sector organizations that need experienced support without unnecessary complexity.
The work is built around a simple standard: advice must be technically grounded, operationally usable, and supported by evidence that another reviewer can follow.
Share the situation, the outcome you need, and any time constraints. Your inquiry goes directly to Steven White for a focused discussion of fit and next steps.