NERC's Proposed CIP-100 Series: What Utilities Need to Know About the Future of Cloud Compliance
Key Takeaway
NERC is developing the proposed CIP-100 Series to improve cybersecurity compliance for utilities using cloud and hybrid technologies. The new framework would focus more on protecting critical services than the location of the services, while giving utilities more flexibility in how they meet security requirements. The standards are still being developed and are not currently enforceable, but utilities can start preparing by reviewing their cloud systems, vendor relationships, and compliance processes.
Why NERC is Updating Cloud Compliance
Cloud adoption is accelerating across the electric utility industry. It offers greater scalability, resiliency, and operational efficiency. However, as organizations move critical systems and services into cloud and hybrid environments, the current NERC Critical Infrastructure Protection (CIP) Reliability Standards are becoming increasingly difficult to apply.
To address this challenge, NERC is developing the proposed CIP-100 Series, a new compliance framework designed specifically for cloud-hosted and hybrid environments.
Why the CIP-100 Series Matters
Today's CIP standards were built around traditional environments where registered entities own and manage the underlying infrastructure. Cloud services introduce a different operating model, one where responsibilities are often shared between the utility and a third-party provider.
Instead of changing the current CIP standards, NERC is proposing a new approach that would provide the same level of cybersecurity and reliability while giving companies more flexibility to use cloud technology.
A key feature of the proposal is choice. Organizations could apply either the existing CIP standards or the CIP-100 framework on a system-by-system basis, allowing for a gradual transition as cloud adoption grows.
A Shift from Infrastructure to Services
One of the most significant changes in the proposed framework is the introduction of BES Cyber Services and Systems (BCSS).
Instead of concentrating primarily on where systems are located or who owns the infrastructure, the CIP-100 Series focuses on the services and functions that support reliable BES operations. This reflects the reality of modern cloud environments, where critical functions use a combination of on-premises and cloud-based technologies.
The proposal also introduces new concepts such as:
- Cyber Security Zones (CSZs)
- Conduits
- Access Control Services and Systems (ACSS)
- Security Monitoring Services and Systems (SMSS)
- Protected Cyber Services and Systems (PCSS)
- System Security Plans (SSPs)
Together, these concepts create a framework that is more adaptable to cloud and hybrid technology environments.

How Compliance Could Change
The proposed CIP-100 Series is built around objective-based requirements rather than highly strict controls.
Instead of dictating specific technologies or architectures, organizations would be required to demonstrate that security objectives are achieved. The primary compliance document would become the SSP, which would document how security controls are implemented and how responsibilities are shared between the utility and cloud service providers.
This approach is intended to provide flexibility while maintaining cybersecurity expectations comparable to existing CIP standards.
What Utility Organizations Should Do Now
It's important to note the CIP-100 Series has not been approved and is not currently enforceable. As of August 2026, the project remains in development, and utilities have no compliance obligations related to the proposed standards.
However, organizations should begin evaluating how the framework could impact future cloud initiatives by:
- Monitoring Project 2023-09 and ongoing NERC discussions
- Assessing current and planned cloud-hosted operational systems
- Reviewing governance and vendor risk management processes
- Identifying systems that could be candidates for future CIP-100 adoption
- Understanding how shared responsibility models may affect compliance programs
Looking Ahead
The CIP-100 Series represents a major evolution in NERC's approach to cybersecurity compliance. By focusing on services and functions rather than physical infrastructure, the framework is designed to support the realities of cloud and hybrid environments while maintaining the reliability and security of the Bulk Electric System.
Although the proposal is still under development, organizations that begin evaluating its potential impact now will be better positioned to adapt if the standards move forward and become enforceable in the future.
Frequently Asked Questions
Is the CIP-100 Series currently required for utilities?
No. The CIP-100 Series is still under development and has not been approved or made enforceable. Utilities do not currently have compliance obligations under the proposed framework.
How would the CIP-100 Series change cloud compliance?
The proposed framework would shift the focus from where systems are located to the services and functions they provide. This could give utilities more flexibility in how they secure cloud and hybrid environments while still meeting cybersecurity and reliability objectives.
What should utilities do to prepare for CIP-100?
Utilities can start by reviewing their current and planned cloud environments, assessing vendor and shared-responsibility arrangements, and monitoring updates to NERC Project 2023-09. This can help organizations understand how the proposed framework could affect their future compliance programs.