CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

FERC approves NERC CIP-014-4 to strengthen physical security and risk assessments for critical transmission facilities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7462

As cited

Copy frozen at (site build).

ot ics

FERC approves NERC CIP-014-4 to strengthen physical security and risk assessments for critical transmission facilities

The Federal Energy Regulatory Commission (FERC) approved NERC Reliability Standard CIP-014-4, which strengthens physical security requirements for critical transmission facilities by establishing clearer risk assessment methodologies and a unified 36-calendar-month review cycle for identifying and evaluating vulnerabilities. The standard becomes effective October 1, 2028, and applies to approximately 344 transmission owners who must identify nearby facilities within 1,500 feet, conduct both steady-state and dynamic simulations, and assess consequences of potential losses using technically justified thresholds. This revision consolidates previous tiered assessment schedules and aligns requirements with broader planning standards to reduce assessment gaps and ensure more consistent evaluation of critical infrastructure risks.

Why it matters: Transmission owners and operators must prepare for revised compliance obligations beginning October 1, 2028, including more frequent risk assessments and stricter documentation of physical security methodologies, affecting capital planning and operational processes across the bulk electric system.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary