TL;DR:
- In March 2026, the Federal Energy Regulatory Commission issued Order No. 919 to approve 11 modified Critical Infrastructure Protection (CIP) Reliability Standards and related glossary updates to accommodate virtualization and other new technologies in the Bulk-Power System. This marks a formal regulatory embrace of cloud, virtualization, and modern IT/OT convergence for grid security and reliability. (ferc.gov)
- The package includes CIP-002-8, CIP-003-11 and 9 other CIP standards, plus four new glossary terms and 18 revised terms. The changes enable responsible entities to deploy virtualization while maintaining security controls and traceability. (ferc.gov)
- A key design change is the replacement of strict “where technically feasible” language with “per system capability,” accompanied by criteria development and mandatory reporting to the Commission. This gives wind to more flexible, technology-forward security models while preserving oversight. (ferc.gov)
- Timing provisions set by the rule allow early adoption at 6, 12, or 18 months after the rule’s effective date, with the overall standards becoming effective after the government approval process completes. The earliest possible implementation date is the later of April 1, 2026 or the first calendar quarter 24 months after that order’s effective date. (ferc.gov)
- For engineers and PE exam candidates, these changes change how cyber security for BES operates in practice and may influence exam emphasis on regulatory compliance, risk management, virtualization concepts, and the evolving CIP framework. (ferc.gov)
Background
Order 919, issued March 19, 2026, addresses modernization of CIP standards to reflect rapid shifts in technology used within the Bulk-Power System. The Commission approves 11 revised CIP Reliability Standards and 4 new/18 revised glossary terms to support virtualization and other nascent technologies in a secure manner. The document frames virtualization as a disciplined upgrade path that preserves reliability and security while enabling more flexible deployment architectures, including virtual machines, containers, and cloud services where appropriate. (ferc.gov)
NERC, the Electric Reliability Organization, petitioned for these updates to align CIP with current technology use and security objectives. The finalized rule confirms that virtualization and related technologies can be adopted in a secure manner, with the potential to improve resilience through isolation, segmentation, and scalable security controls. The CIP changes touch multiple standards and definitions to ensure consistent, auditable implementation across the industry. (ferc.gov)
What Changed
CIP Standards touched
CIP-002-8 Cyber Security – BES Cyber System Categorization
CIP-003-11 Cyber Security – Security Management Controls
CIP-006-7.1 Cyber Security – Physical Security of BES Cyber Systems
CIP-007-7.1 Cyber Security – Systems Security Management
CIP-008-7.1 Cyber Security – Incident Reporting and Response Planning
CIP-009-7.1 Cyber Security – Recovery Plans for BES Cyber Systems
CIP-010-5 Cyber Security – Configuration Change Management and Vulnerability Assessments
CIP-011-4.1 Cyber Security – Information Protection
CIP-013-3 Cyber Security – Supply Chain Risk Management
In total, 11 CIP Reliability Standards were modified to accommodate virtualization, with 4 new definitions and 18 definitions revised in the NERC Glossary. (ferc.gov)
Virtualization focus
The package explicitly updates CIP to enable virtualization and other new technologies, with the Commission noting the shift toward virtualization and cloud-like approaches as part of evolving security posture. This reflects a deliberate policy choice to modernize cyber security requirements while staying aligned with operating realities. (ferc.gov)
Per system capability and governance
A notable policy change is the replacement of the previous “where technically feasible” phrasing with “per system capability” in multiple CIP requirements. This aims to balance security objectives with the realities of diverse technologies, but it also requires clear criteria and oversight to avoid inconsistent implementations. The Commission directs NERC to develop explicit criteria for invoking per system capability and to establish mandatory reporting to the Commission. (ferc.gov)
Implementation timeline and practical implications
Effective dates and adoption windows
The rule states that it is effective 60 days after publication in the Federal Register, with further implementation guidance and interpretations to follow. The order also directs NERC to establish criteria for per system capability and to implement mandatory reporting to the Commission. (ferc.gov)
Early adoption opportunities exist on six, 12, or 18 months after the rule’s effective date, enabling entities to begin aligning processes and controls with virtualization-oriented requirements sooner rather than later. (ferc.gov)
The fundamental dates for when the revised CIP Standards become effective hinge on the government’s approval process. The rule notes the practical implementation window as the later of April 1, 2026 or the first day of the first calendar quarter that is 24 months after the effective date of the approving order, acknowledging that exact dates depend on the formal approval timeline. (ferc.gov)
Compliance and oversight
The final rule confirms that NERC will implement the 11 virtualization-related CIP Standards and retire the currently effective versions, with explicit reporting requirements to the Commission. This ensures ongoing oversight and the ability to track adoption and performance across the BES. (ferc.gov)
Practical impact for engineers
For project design and operations teams, this rule signals a shift to accommodate virtualization in high consequence settings. Practically, this means updating cyber security architecture, risk assessments, and change management processes to reflect virtualization-enabled environments. It also implies broader use of new definitions and clearer criteria for compliance exemptions, when applicable, under per system capability. Engineering teams should begin mapping current BES configurations to the new CIP structure and identify where virtualization could yield security and resilience benefits without compromising oversight. (ferc.gov)
Implications for PE exam preparation
Regulatory and security literacy
For PE candidates, the March 2026 CIP update raises the importance of understanding NERC CIP frameworks and how virtualization intersects with critical infrastructure protection. While the exact exam coverage varies by discipline, the trend toward cyber security, risk management, and regulatory compliance in power systems is increasingly relevant for the exam and professional practice. Candidates should become familiar with CIP-002-8 and CIP-003-11 at a high level, and stay aware of NERC’s evolving glossary and definitions related to BES cyber systems and virtualization. (ferc.gov)
Study strategy
Build a study map that connects core CIP requirements to practical security controls, and note how the “per system capability” concept changes the interpretation of compliance obligations. Practice with scenarios that require selecting appropriate compensating controls or documenting per system capability justifications under the revised standard language. Review the NERC petition and FERC order discussion to understand the rationale behind virtualization readiness and the oversight framework. (ferc.gov)
Practical exam updates
PE candidates should monitor official guidance from NERC, regional entities, and state boards for any jurisdictional adoption specifics or supplemental materials that translate the CIP changes into engineer-level practice questions. The March 2026 order provides the regulatory backbone; exam prep should align with the high level of CIP-002-8 and CIP-003-11 concepts and the broader virtualization context. (ferc.gov)
What this means for engineers moving forward
Embrace virtualization with a security-first approach
The CIP modernization signals that modern BES operations will routinely incorporate virtualization, cloud-like services, and containerized components. Engineers should plan security architectures with virtualization in mind, including access controls, monitoring, configuration management, and supply chain considerations tailored to virtual environments. The rule’s emphasis on new and revised definitions ensures consistent terminology across audits and compliance processes. (ferc.gov)
Prepare for phased implementation
With early adoption windows and a formal implementation plan, engineering teams can begin the cultural and technical transition now, while maintaining strict compliance with existing CIP requirements until the new standards become fully effective. Coordination with utilities, regional entities, and NERC will be critical to ensure a smooth transition and accurate reporting. (ferc.gov)
Align with exam readiness
For PE exam candidates, the virtualization CIP updates underscore the growing importance of cyber security and regulatory frameworks in power engineering. Incorporating these topics into study plans will build readiness for questions that connect engineering design with security, governance, and reliability in modern electric grids. (ferc.gov)
Sources
- Federal Energy Regulatory Commission, Order No. 919 Final Rule, Virtualization Reliability Standards (Issued March 19, 2026). https://www.ferc.gov/news-events/news/ferc-takes-action-enhance-reliability-us-electric-grid (ferc.gov)
- Federal Energy Regulatory Commission, RM24-8-000, Final Rule, Virtualization Reliability Standards (Docket and excerpts). https://www.ferc.gov/sites/default/files/2026-03/RM24-8-000.pdf (ferc.gov)
- FERC notice and summary for NERC Petition and NOPR related to virtualization CIP standards. https://www.ferc.gov/sites/default/files/2026-03/RM24-8-000.pdf (NOPR discussion) (ferc.gov)
- Additional context on virtualization and CIP changes, including definitions and implementation considerations. https://www.ferc.gov/sites/default/files/2026-03/RM24-8-000.pdf (ferc.gov)